Configuring GSSAPI with eDirectory
603
n
ov
do
cx (e
n)
22
Ju
n
e 20
09
Or to remove, enter the following:
krbldapconfig -u -D cn=admin,o=org -w password -h ldapserver -p 389
IMPORTANT:
You must manually refresh the LDAP server for the installation changes to take
effect. For more information, refer to
Section 15.5, “Refreshing the LDAP Server,” on page 361
.
E.1.4 Exporting the Trusted Root Certificate
1
In iManager, click
eDirectory Administration
>
Modify Object
to open the Modify Object page.
2
Click
Single Object
, then select the Server Certificate object of the server.
3
Click
OK
.
4
Click the
Certificates
tab, then select
Trusted Root Certificate
and view the details of the
certificate.
5
Click
Export
to launch the
Certificate Export Wizard
.
6
Specify whether you want to export the private key or not, then click
Next
.
7
Select
File in Binary DER Format
, then click
Next
.
8
Click
Save the Exported Certificate to a File
.
9
Click
Close
.
E.2 Configuring the SASL-GSSAPI Method
1
The iManager plug-in for SASL-GSSAPI will not work if iManager is not configured to use
SSL/TLS connection to eDirectory. A secure connection is mandated to protect the realm's
master key and principal keys.
By default, iManager is usually configured for SSL/TLS connection to eDirectory. You need to
add the SSL trusted root certificates of the LDAP server that you use for Kerberos
administration to iManager.
For information on configuring iManager with SSL/TLS connection to eDirectory, refer to the
iManager 2.7.2 Administration Guide
(http://www.novell.com/documentation/imanager27/
imanager_admin_272/index.html?page=/documentation/imanager27/imanager_admin_272/
data/b7eyu8t.html)
.
2
Complete the following procedures in the order given:
2a
Extend the Kerberos Schema
.
2b
Create a Realm Container
.
2c
Create the LDAP Service Principal
.
2d
Extract a Service Principal Key or Shared Key from KDC
.
2e
Creating a Service Principal Object in eDirectory.
2f
Associate a Kerberos Principal Name with the User Object
.
Summary of Contents for EDIRECTORY 8.8 SP5
Page 4: ...4 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 118: ...118 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 130: ...130 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 188: ...188 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 222: ...222 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 240: ...240 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 264: ...264 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 290: ...290 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 322: ...322 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 540: ...540 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 548: ...548 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 616: ...616 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...