
Configuring LDAP Services for Novell eDirectory
363
n
ov
do
cx (e
n)
11
Ju
ly 20
08
Before the server can support TLS, you must provide the server with an X.509 certificate that the
server can use to establish its legitimacy.
This certificate is automatically provided during the eDirectory installation. During installation, Key
Material objects are created as part of Public Key Infrastructure (PKI) and Novell Modular
Authentication Services (NMAS
TM
). The following figure illustrates these objects in iManager:
Description: SSL objects
The installation automatically associates one of those certificates with the LDAP server. In Novell
iManager, the Connections tab for the LDAP Server object displays a DN. This DN represents the
X.509 certificate. The Server Certificate field in the following figure illustrates this DN.
Description: Server Certificate field
In Novell iManager, you can browse to the Key Material object (KMO) certificates. Using the drop-
down list, you can change to a different certificate. Either the DNS or the IP certificate will work.
As part of the validation, the server should validate the name (the hard IP address or the DN) that is
in the certificate.
Value
Description
0
Off. During a handshake, the server provides a certificate to the client. The server
never requires the client to send a certificate. The client can use or ignore the
certificate. A secure session is established.
1
During the handshake, the server provides a certificate to the client and requests a
certificate from the client. The client can choose to send its certificate back. The
client's certificate is validated. If the server cannot validate the client's certificate, the
connection is terminated.
If the client doesn't send a certificate, the server maintains the connection.
2
During the handshake, the server requests and requires a certificate from the client. If
the client does not provide a certificate, or if the certificate can't be validated, the
connection is terminated.
Summary of Contents for EDIRECTORY 8.8 SP3
Page 4: ...novdocx en 11 July 2008...
Page 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Page 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...