Starting the Server with SSL Enabled
430
Red Hat Directory Server Administrator’s Guide • May 2005
9.
You can further configure the server to verify the authenticity of requests by
selecting the “Check hostname against name in certificate for outbound SSL
connections” option. The server does this verification by matching the
hostname against the value assigned to the common name (
cn
) attribute of the
subject name in the certificate being presented for authentication.
By default, this feature is disabled. If it’s enabled and if the hostname does not
match the
cn
attribute of the certificate, appropriate error and audit messages
are logged. For example, in a replicated environment, messages similar to
these are logged in the supplier server’s log files if it finds that the peer
server’s hostname doesn’t match the name specified in its certificate:
[DATE] - SSL alert: ldap_sasl_bind("",LDAP_SASL_EXTERNAL) 81
(Netscape runtime error -12276 - Unable to communicate
securely with peer: requested domain name does not match the
server's certificate.)
[DATE] NSMMReplicationPlugin - agmt="cn=to ultra60 client
auth" (ultra60:1924): Replication bind with SSL client
authentication failed: LDAP error 81 (Can’t contact LDAP
server)
It is recommended that you enable this option to protect Directory Server’s
outbound SSL connections against a Man in the Middle (MITM) attack.
10.
Click Save.
11.
Restart the Directory Server. You must restart from the command-line.
Enabling SSL in the Directory Server, Admin
Server, and Console
1.
Obtain server certificates and CA certs, and install them on the Directory
Server.
2.
Obtain and install server and CA certificates on the Administration Server.
It is important that the Administration Server and Directory Server have their
CA certificates in common so that they trust the other's certificates.
NOTE
If you are using certificate-based authentication with replication,
then you must configure the consumer server either to allow or to
require client authentication.
Summary of Contents for DIRECTORY SERVER 7.1
Page 1: ...Administrator s Guide Red Hat Directory Server Version7 1 May 2005 Updated February 2009 ...
Page 20: ...20 Red Hat Directory Server Administrator s Guide May 2005 Glossary 619 Index 635 ...
Page 22: ...22 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 26: ...26 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 78: ...Maintaining Referential Integrity 78 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 200: ...Assigning Class of Service 200 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 488: ...488 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 528: ...PTA Plug in Syntax Examples 528 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 572: ...572 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 612: ...Examples of LDAP URLs 612 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 634: ...634 Red Hat Directory Server Administrator s Guide May 2005 ...