
368
Novell eDirectory 8.8 Administration Guide
n
ov
do
cx (e
n)
11
Ju
ly 20
08
EXTERNAL
The EXTERNAL mechanism informs the LDAP server that the user DN and credentials have
already been supplied to the server. Therefore, the DN and credentials do not need to come across in
the bind request.
The LDAP bind request uses the SASL EXTERNAL mechanism to instruct the server to do the
following:
Ask an EXTERNAL layer what the credentials were
Authenticate the user with those credentials and user
After this is done, a secure handshake occurs. The LDAP server requests credentials from the client
and the client passes them to the server, then the server receives the certificate that was passed from
the client, passes the certificate to the NMAS module, and authenticates the user as whatever DN
was supplied in the certificate
Having a certificate with a usable DN requires some setup on the client. For information about
setting up the certificate, see the
NMAS online documentation
(http://www.novell.com/
documentation/nmas30/index.html)
.
Even if the client sends an EXTERNAL mechanism, the LDAP server could fail the request.The
following could be possible reasons for failure:
The connection is not secure.
Although the connection is secure, the client did not provide the required certificate during the
handshake.
The SASL module is unavailable.
NMAS_LOGIN
Novell Modular Authentication Service (NMAS) is a development framework that allows you to
write applications that authenticate to the network using various login and authentication methods.
The NMAS framework allows you to design a flexible and expandable login and authentication
system using modular plug-in methods that leverage Novell International Cryptographic
Infrastructure (NICI) and Novell Directory Services (eDirectory®).
The NMAS_LOGIN mechanism provides the LDAP server with the biometrics capability of
NMAS. For more information, see the
Novell NDK
(http://developer.novell.com/documentation/
nmas/index.html?page=/documentation/nmas/nmas_enu/data/bktitle.html)
.
GSSAPI
The GSSAPI mechanism enables a Kerberos user to authenticate to an eDirectory server using a
ticket, without needing to enter a separate LDAP user password. This functionality is targeted at
LDAP application users in environments that already have the Kerberos infrastructure in place. Such
users must be able to use the Kerberos server-issued tickets to authenticate to the LDAP server
without providing a separate LDAP user password.
For information on configuring GSSAPI, refer to
Appendix E, “Configuring GSSAPI with
eDirectory,” on page 621
.
Summary of Contents for EDIRECTORY 8.8 SP3
Page 4: ...novdocx en 11 July 2008...
Page 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Page 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...