Chapter 8:
Authentication
180
2.
Enter the
Server Address
(IP or host name) of the remote Authentication server.
Multiple remote
servers may be specified in a comma separated list. Each server is tried in succession.
3.
Check the
Server Protocol
box
to select if SSL is to be used and/or enforced for communications
with the LDAP server. Console servers offer three options for LDAPS (LDAP over SSL):
o
LDAP over SSL preferred
will attempt to use SSL for authentication, but if it fails it will fall
back to LDAP without SSL. As an example LDAP over SSL may fail due to certificate
errors or the LDAP server not be contactable on the LDAPS port etc
o
LDAP over SSL only
: this setting configures the Opengear device to only accept LDAP
over SSL. If LDAP over SSL fails, only the root account will be able to log in to the console
server
o
LDAP (no SSL) only
: this setting will configure the Opengear device to only accept LDAP
without SSL. If LDAP without SSL fails, only the root account will be able to log in to the
console server
4.
The
Ignore SSL Certificate Error
checkbox enables you to ignore SSL certificate errors - allowing
LDAP over SSL to work regardless of these errors. This allows you to use any certificate, self-
signed or otherwise, on the LDAP server without having to install any certificates on the console
server. If this setting is not checked, you must install the CA (certificate authority) certificate with
which the LDAP server's certificate was signed, onto the console server. For example, the LDAP
server is serving with a certificate singed using the certificate myCA.crt