Configuring LDAP Services for Novell eDirectory
369
n
ov
do
cx (e
n)
22
Ju
n
e 20
09
DIGEST-MD5
LDAP supports the DIGEST-MD5 mechanism through the bind request. Instead of requesting an
LDAP simple bind (DN and clear-text password), you request an LDAP SASL bind by providing
the DN and the MD5 credentianls. The DIGEST-MD5 mechanism does not require TLS. The LDAP
server supports DIGEST-MD5 over clear and secure connections.
MD5 provides an encrypted hash of passwords. Passwords are encrypted even on clear connections.
Therefore, the LDAP server accepts passwords that use MD5 on either the clear-text or encrypted
port. If someone tries to sniff this connection, the password cannot be detected. However, the entire
connection can be spoofed or hijacked.
This mechanism is an LDAP SASL bind (not a simple bind). Therefore, the LDAP server accepts
these requests, even if you selected the
Require TLS for Simple Binds with Passwords
check box
during installation.
EXTERNAL
The EXTERNAL mechanism informs the LDAP server that the user DN and credentials have
already been supplied to the server. Therefore, the DN and credentials do not need to come across in
the bind request.
The LDAP bind request uses the SASL EXTERNAL mechanism to instruct the server to do the
following:
Ask an EXTERNAL layer what the credentials were
Authenticate the user with those credentials and user
After this is done, a secure handshake occurs. The LDAP server requests credentials from the client
and the client passes them to the server, then the server receives the certificate that was passed from
the client, passes the certificate to the NMAS module, and authenticates the user as whatever DN
was supplied in the certificate
Having a certificate with a usable DN requires some setup on the client. For information about
setting up the certificate, see the
NMAS online documentation
(http://www.novell.com/
documentation/nmas30/index.html)
.
Even if the client sends an EXTERNAL mechanism, the LDAP server could fail the request.The
following could be possible reasons for failure:
The connection is not secure.
Although the connection is secure, the client did not provide the required certificate during the
handshake.
The SASL module is unavailable.
NMAS_LOGIN
Novell Modular Authentication Service (NMAS) is a development framework that allows you to
write applications that authenticate to the network using various login and authentication methods.
The NMAS framework allows you to design a flexible and expandable login and authentication
system using modular plug-in methods that leverage Novell International Cryptographic
Infrastructure (NICI) and Novell Directory Services (eDirectory®).
Summary of Contents for EDIRECTORY 8.8 SP5
Page 4: ...4 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 118: ...118 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 130: ...130 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 188: ...188 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 222: ...222 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 240: ...240 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 264: ...264 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 290: ...290 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 322: ...322 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 540: ...540 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 548: ...548 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 616: ...616 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...