![Netscape NETSCAPE DIRECTORY SERVER 6.02 Скачать руководство пользователя страница 376](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-02/netscape-directory-server-6-02_administrators-manual_1674673376.webp)
Introduction to SSL in the Directory Server
376
Netscape Directory Server Administrator’s Guide • May 2002
Using SSL with simple authentication ensures confidentiality and data integrity.
The benefits of using a certificate to authenticate to the Directory Server, instead of
a bind DN and password, include:
•
Improved efficiency—When you are using applications that prompt you once
for your certificate database password, and then use that certificate for all
subsequent bind or authentication operations, it is more efficient than
continuously providing a bind DN and password.
•
Improved security—The use of certificate-based authentication is more secure
than non-certificate bind operations. This is because certificate-based
authentication uses public-key cryptography. As a result, bind credentials
cannot be intercepted across the network.
The Directory Server is capable of simultaneous SSL and non-SSL communications.
This means that you do not have to choose between SSL or non-SSL
communications for your Directory Server; you can use both at the same time.
Enabling SSL: Summary of Steps
To configure your Directory Server to use LDAPS, follow these steps:
1.
Obtain and install a certificate for your Directory Server, and configure the
Directory Server to trust the certification authority’s (CA’s) certificate.
For information, see “Obtaining and Installing Server Certificates,” on
page 377.
2.
Turn on SSL in your directory.
For information, see “Activating SSL,” on page 381.
3.
Configure the Administration Server to connect to an SSL-enabled Directory
Server.
For information, see Managing Servers with Netscape Console.
4.
Optionally, ensure that each user of the Directory Server obtains and installs a
personal certificate for all clients that will authenticate with SSL.
For information, see “Configuring LDAP Clients to Use SSL,” on page 386.
NOTE
If you are running Directory Server on a UNIX platform, enabling
SSL will also enable support the the StartTLS extended operation.
The StartTLS extended operation provides security on a regular
LDAP connection.
Содержание NETSCAPE DIRECTORY SERVER 6.02
Страница 1: ...Administrator s Guide Netscape Directory Server Version6 02 May 2002 ...
Страница 16: ...16 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 20: ...20 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 40: ...Starting the Server in Referral Mode 40 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 74: ...Maintaining Referential Integrity 74 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 138: ...Using Referrals 138 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 258: ...Compatibility with Earlier Releases 258 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 274: ...Setting Resource Limits Based on the Bind DN 274 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 330: ...Solving Common Replication Conflicts 330 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 374: ...Attribute Name Quick Reference Table 374 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 390: ...Configuring LDAP Clients to Use SSL 390 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 412: ...Monitoring Database Link Activity 412 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 432: ...Miscellaneous Tuning Tips 432 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 434: ...434 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 468: ...PTA Plug In Syntax Examples 468 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 488: ...488 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 502: ...Storing Information in Multiple Languages 502 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 522: ...Searching an Internationalized Directory 522 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 528: ...Examples of LDAP URLs 528 Netscape Directory Server Administrator s Guide May 2002 ...