
Advanced topics
503
Managing LDAP security
When you consider how to implement LDAP security, you must consider server security and
application security.
Server security
The
cfldap
tag supports secure socket layer (SSL) v2 security. This security provides certificate-
based validation of the LDAP server. It also encrypts data transferred between the ColdFusion
server and the LDAP server, including the user password, and ensures the integrity of data passed
between the servers. To specify SSL v2 security, set the
cfladap
tag
secure="cfssl_basic"
attribute.
About LDAP Server Security
ColdFusion MX uses Java Native Directory Interface (JNDI), the LDAP provider, and an SSL
package to create the client side of an SSL communication. The LDAP server provides the server
side. The LDAP server that the
cfldap
tag connects to using SSL holds an SSL server certificate,
a certificate that is securely “signed” by a trusted authority and identifies (authenticates) the
sender. During the initial SSL connection, the LDAP server presents its server certificate to the
client. If the client trusts this certificate, the SSL connection is established and secure LDAP
communication can begin.
ColdFusion determines whether to trust the server by comparing the server’s certificate with the
information in the jre/lib/security/cacerts keystore of the JRE used by ColdFusion MX. The
ColdFusion MX default cacerts file contains information about many certificate granting
authorities. If you must update the file with additional information, you can use the keytool
utility in the ColdFusion jre/bin directory to import certificates that are in X.509 format. For
example, enter the following:
keytool -import -keystore cacerts -alias ldap -file ldap.crt -keypass bl19mq
The keytool utility initial keypass password is "change it". For more infomration on using the
keytool utility, see the Sun JDK documentation.
Once ColdFusion establishes secure communication with the server, it must provide the server
with login credentials. You specify the login credentials in the
cfldap
tag
username
and
password
attributes. When the server determines that the login credentials are valid, ColdFusion
can access the directory.
Using LDAP security
To use security, first ensure that the LDAP server supports SSL v2 security.
Specify the
cfldap
tag
secure
attribute as follows:
secure = "cfssl_basic"
For example:
<cfldap action="modify"
modifyType="add"
atributes="cn=Lizzie"
dn="uid=lborden, ou=People, o=Airius.com"
server=#myServer#
username=#myUserName#
password=#myPassword#
secure="cfssl_basic"
port=636>
Summary of Contents for ColdFusion MX
Page 1: ...Developing ColdFusion MX Applications...
Page 22: ...22 Contents...
Page 38: ......
Page 52: ...52 Chapter 2 Elements of CFML...
Page 162: ......
Page 218: ...218 Chapter 10 Writing and Calling User Defined Functions...
Page 250: ...250 Chapter 11 Building and Using ColdFusion Components...
Page 264: ...264 Chapter 12 Building Custom CFXAPI Tags...
Page 266: ......
Page 314: ...314 Chapter 14 Handling Errors...
Page 344: ...344 Chapter 15 Using Persistent Data and Locking...
Page 349: ...About user security 349...
Page 357: ...Security scenarios 357...
Page 370: ...370 Chapter 16 Securing Applications...
Page 388: ...388 Chapter 17 Developing Globalized Applications...
Page 408: ...408 Chapter 18 Debugging and Troubleshooting Applications...
Page 410: ......
Page 426: ...426 Chapter 19 Introduction to Databases and SQL...
Page 476: ...476 Chapter 22 Using Query of Queries...
Page 534: ...534 Chapter 24 Building a Search Interface...
Page 556: ...556 Chapter 25 Using Verity Search Expressions...
Page 558: ......
Page 582: ...582 Chapter 26 Retrieving and Formatting Data...
Page 668: ......
Page 734: ...734 Chapter 32 Using Web Services...
Page 760: ...760 Chapter 33 Integrating J2EE and Java Elements in CFML Applications...
Page 786: ...786 Chapter 34 Integrating COM and CORBA Objects in CFML Applications...
Page 788: ......