Configuring or Disabling LDAP Authentication
157
• Encryption
• The encryption key version and type
channel.blocksize=248
channel.defKeyIndex=0
channel.defKeyVersion=0
channel.encryption=true
Example 5.3. Default TPS-Token Channel Configuration
The
defKeyIndex
and
defKeyVersion
parameters should remain the default value, as in
Example 5.3, “Default TPS-Token Channel Configuration”
.
The
channel.encryption
configuration parameter sets whether to use an encrypted channel
between the TPS and tokens managed by the Enterprise Security Client.
channel.encryptionchannel.encryption=true
For security, the
channel.encryptionchannel.encryption
parameter should always be set to
true
, the default.
5.7.3. Configuring or Disabling LDAP Authentication
The TPS, by default, requires a user to authenticate to an LDAP directory when a smart card operation
request is received. There are three parameters for this which can be set for each separate token
operation:
op.
operation.key_type
.auth.enable=true|false
op.
operation.key_type
.auth.id=
ldap_db_config_entry
op.
operation.key_type
.loginRequest.enable=true|false
Setting these parameters determines whether LDAP authentication is required, which the LDAP
directory to use for the authentication (by referencing its entry in the TPS
CS.cfg
file), and whether to
send the login request to the smart card client program.
NOTE
The user must have an existing LDAP user entry in the LDAP server instance specified in
the TPS's
CS.cfg
file in order to complete the operation.
To configure LDAP authentication:
1. Stop the TPS subsystem.
service pki-tps stop
2. Set the authentication parameters.
op.
operation_type.token_type
.loginRequest.enable=false|true
op.
operation_type.token_type
.auth.id=
ldap_db_config_entry
op.
operation_type.token_type
.auth.enable=false|true
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...