Replication over SSL
354
Red Hat Directory Server Administrator’s Guide • May 2005
If you want the update operation to occur over an SSL connection, you must
modify the
ldapmodify
command in the script with the appropriate parameters
and values. For more information on the
ldapmodify
command, refer to
“Managing Entries from the Command-Line,” on page 55, and
Red Hat Directory
Server Configuration, Command, and File Reference
.
Replication over SSL
You can configure Directory Servers involved in replication so that all replication
operations occur over an SSL connection.
To use replication over SSL, you must first do the following:
• Configure both your supplier and consumer servers to use SSL.
• Configure your consumer server to recognize your supplier server’s
certificate as the supplier DN. You do this only if you want to use SSL client
authentication rather than simple authentication.
These procedures are described in chapter 11, “Managing SSL and SASL.”
When your servers are configured to use SSL, you can ensure replication
operations occur over SSL connections by using the Replication Agreement
Wizard, which enables you to set up a replication agreement between two
Directory Servers. Keep in mind that once you create a replication agreement, you
cannot change the connection type (SSL or nonSSL) defined in the agreement; this
is because LDAP and LDAPS connections use different ports. To change the
connection type, you must re-create the replication agreement.
NOTE
Replication configured over SSL with certificate-based
authentication will fail in the following cases:
• If the supplier’s certificate is a self-signed certificate.
• If the supplier’s certificate is only capable of behaving as an SSL
server certificate, meaning it is unable to play the role of the
client during an SSL handshake.
NOTE
If you have enabled attribute encryption, you must use a secure
connection for replication.
Summary of Contents for DIRECTORY SERVER 7.1
Page 1: ...Administrator s Guide Red Hat Directory Server Version7 1 May 2005 Updated February 2009 ...
Page 20: ...20 Red Hat Directory Server Administrator s Guide May 2005 Glossary 619 Index 635 ...
Page 22: ...22 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 26: ...26 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 78: ...Maintaining Referential Integrity 78 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 200: ...Assigning Class of Service 200 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 488: ...488 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 528: ...PTA Plug in Syntax Examples 528 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 572: ...572 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 612: ...Examples of LDAP URLs 612 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 634: ...634 Red Hat Directory Server Administrator s Guide May 2005 ...