
624
Novell eDirectory 8.8 Administration Guide
n
ov
do
cx (e
n)
11
Ju
ly 20
08
E.1.3 Adding Kerberos LDAP Extensions
Kerberos LDAP Extensions provide the functionality to manage Kerberos keys.
To use the Kerberos LDAP extensions, you must install the LDAP libraries for C. For more
information, refer to
LDAP Libraries for C
(http://developer.novell.com/ndk/cldap.htm)
.
To add or remove the Kerberos LDAP extensions, use the krbldapconfig utility, which can be found
in the following locations:
Linux:
extracted_folder
/Linux/nmas/NmasMethods/Novell/GSSAPI/
Kerberos_ldap_extensions/Linux/krbldapconfig
For example:
/misc/eDir88/Linux/nmas/NmasMethods/Novell/GSSAPI/
Kerberos_ldap_extensions/Linux/krbldapconfig
To add the Kerberos LDAP extensions, use the following syntax:
krbldapconfig {-i | -u} -D
bind_DN
[-w
bind_DN_password
] [-h
ldap_host
] [-p
ldap_port
] [-e
trusted_root_cert
]
The following table explains the krbldapconfig utility parameters:
NOTE:
If you do not specify the -h option, the name of the local host that krbldapconfig is invoked
from is used as the default.
If you do not specify the LDAP server port and the trusted root certificate, the default port 389 is
used.
If you do not specify the LDAP server port but specify the trusted root certificate, the default port
636 is used.
Parameter
Description
-i
Adds the Kerberos LDAP extensions to eDirectory.
-u
Removes the Kerberos LDAP extensions from eDirectory.
-D
bind_fdn
Specifies the FDN of the administrator or the user with administrator-
equivalent rights.
This must be in the format cn=admin,o=org.
-w
bind_fdn_password
Specifies the password of the bind FDN (bind_fdn).
-h
ldap_server
Specifies the hostname or IP address of the LDAP server where
Kerberos LDAP extensions must be installed.
-p
port
Specifies the port where the LDAP server is running.
-e
trusted_root_file
Specifies the trusted root certificate filename for the SSL bind.
If you are using an SSL port, specify the -e option.
For more information, refer to
Section E.1.4, “Exporting the Trusted
Root Certificate,” on page 625
.
Summary of Contents for EDIRECTORY 8.8 SP3
Page 4: ...novdocx en 11 July 2008...
Page 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Page 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...