![Netscape NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR Administrator'S Manual Download Page 382](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-1-administrator/netscape-directory-server-6-1-administrator_administrators-manual_1674675382.webp)
Introduction to SSL in the Directory Server
382
Netscape Directory Server Administrator’s Guide • August 2002
Using SSL with simple authentication ensures confidentiality and data integrity.
The benefits of using a certificate to authenticate to the Directory Server, instead of
a bind DN and password, include:
•
Improved efficiency—When you are using applications that prompt you once
for your certificate database password, and then use that certificate for all
subsequent bind or authentication operations, it is more efficient than
continuously providing a bind DN and password.
•
Improved security—The use of certificate-based authentication is more secure
than non-certificate bind operations. This is because certificate-based
authentication uses public-key cryptography. As a result, bind credentials
cannot be intercepted across the network.
The Directory Server is capable of simultaneous SSL and non-SSL communications.
This means that you do not have to choose between SSL or non-SSL
communications for your Directory Server; you can use both at the same time.
Enabling SSL: Summary of Steps
To configure your Directory Server to use LDAPS, follow these steps:
1.
Obtain and install a certificate for your Directory Server, and configure the
Directory Server to trust the certification authority’s (CA’s) certificate.
For information, see “Obtaining and Installing Server Certificates,” on
page 383.
2.
Turn on SSL in your directory.
For information, see “Activating SSL,” on page 387.
3.
Configure the Administration Server to connect to an SSL-enabled Directory
Server.
For information, see Managing Servers with Netscape Console.
4.
Optionally, ensure that each user of the Directory Server obtains and installs a
personal certificate for all clients that will authenticate with SSL.
For information, see “Configuring LDAP Clients to Use SSL,” on page 393.
NOTE
If you are running Directory Server on a UNIX platform, enabling
SSL will also enable support the the StartTLS extended operation.
The StartTLS extended operation provides security on a regular
LDAP connection.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR
Page 1: ...Administrator s Guide Netscape Directory Server Version6 1 August 2002...
Page 20: ...20 Netscape Directory Server Administrator s Guide August 2002...
Page 24: ...24 Netscape Directory Server Administrator s Guide August 2002...
Page 142: ...Using Referrals 142 Netscape Directory Server Administrator s Guide August 2002...
Page 440: ...Miscellaneous Tuning Tips 440 Netscape Directory Server Administrator s Guide August 2002...
Page 442: ...442 Netscape Directory Server Administrator s Guide August 2002...
Page 478: ...PTA Plug In Syntax Examples 478 Netscape Directory Server Administrator s Guide August 2002...
Page 498: ...498 Netscape Directory Server Administrator s Guide August 2002...
Page 538: ...Examples of LDAP URLs 538 Netscape Directory Server Administrator s Guide August 2002...