
Security Considerations
F
633
n
ov
do
cx (e
n)
11
Ju
ly 20
08
F
Security Considerations
This appendix contains the following topics:
Section F.1, “LDAP Binds,” on page 633
Section F.2, “Nessus Scan Results,” on page 634
F.1 LDAP Binds
The LDAP binds should take place over a secure connection. We recommend that you always use a
SSL/TLS connection; else:
The key transmitted over the wire can be sniffed out. So you need to physically secure the
corporate network against eaves-dropping or “packet sniffing”.
You need to keep the servers in a physically secure location with access by authorized
personnel only.
When the product is used by users outside of the corporate firewall, a VPN should be
employed.
If a server is accessible from outside the corporate network, a firewall should be configured to
prevent direct access to the server.
Audit logs should be checked periodically.
Different administrative duties should be given to separate people. Delegation of
administration provides granular control over the directory objects.
We recommend that you identify a particular LDAP server as the right server for Kerberos
management. You can specify the server name in iManager.
IMPORTANT:
The user needs to access the LDAP server using the DNS name instead of the IP
address of the server. This is because the conversion of the IP address to the DNS name is not
secure.
Summary of Contents for EDIRECTORY 8.8 SP3
Page 4: ...novdocx en 11 July 2008...
Page 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Page 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...