![Netscape NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR Скачать руководство пользователя страница 382](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-1-administrator/netscape-directory-server-6-1-administrator_administrators-manual_1674675382.webp)
Introduction to SSL in the Directory Server
382
Netscape Directory Server Administrator’s Guide • August 2002
Using SSL with simple authentication ensures confidentiality and data integrity.
The benefits of using a certificate to authenticate to the Directory Server, instead of
a bind DN and password, include:
•
Improved efficiency—When you are using applications that prompt you once
for your certificate database password, and then use that certificate for all
subsequent bind or authentication operations, it is more efficient than
continuously providing a bind DN and password.
•
Improved security—The use of certificate-based authentication is more secure
than non-certificate bind operations. This is because certificate-based
authentication uses public-key cryptography. As a result, bind credentials
cannot be intercepted across the network.
The Directory Server is capable of simultaneous SSL and non-SSL communications.
This means that you do not have to choose between SSL or non-SSL
communications for your Directory Server; you can use both at the same time.
Enabling SSL: Summary of Steps
To configure your Directory Server to use LDAPS, follow these steps:
1.
Obtain and install a certificate for your Directory Server, and configure the
Directory Server to trust the certification authority’s (CA’s) certificate.
For information, see “Obtaining and Installing Server Certificates,” on
page 383.
2.
Turn on SSL in your directory.
For information, see “Activating SSL,” on page 387.
3.
Configure the Administration Server to connect to an SSL-enabled Directory
Server.
For information, see Managing Servers with Netscape Console.
4.
Optionally, ensure that each user of the Directory Server obtains and installs a
personal certificate for all clients that will authenticate with SSL.
For information, see “Configuring LDAP Clients to Use SSL,” on page 393.
NOTE
If you are running Directory Server on a UNIX platform, enabling
SSL will also enable support the the StartTLS extended operation.
The StartTLS extended operation provides security on a regular
LDAP connection.
Содержание NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR
Страница 1: ...Administrator s Guide Netscape Directory Server Version6 1 August 2002...
Страница 20: ...20 Netscape Directory Server Administrator s Guide August 2002...
Страница 24: ...24 Netscape Directory Server Administrator s Guide August 2002...
Страница 44: ...Starting the Server in Referral Mode 44 Netscape Directory Server Administrator s Guide August 2002...
Страница 78: ...Maintaining Referential Integrity 78 Netscape Directory Server Administrator s Guide August 2002...
Страница 142: ...Using Referrals 142 Netscape Directory Server Administrator s Guide August 2002...
Страница 162: ...Enabling and Disabling Read Only Mode 162 Netscape Directory Server Administrator s Guide August 2002...
Страница 278: ...Setting Resource Limits Based on the Bind DN 278 Netscape Directory Server Administrator s Guide August 2002...
Страница 336: ...Troubleshooting Replication Related Problems 336 Netscape Directory Server Administrator s Guide August 2002...
Страница 396: ...Configuring LDAP Clients to Use SSL 396 Netscape Directory Server Administrator s Guide August 2002...
Страница 418: ...Monitoring Database Link Activity 418 Netscape Directory Server Administrator s Guide August 2002...
Страница 440: ...Miscellaneous Tuning Tips 440 Netscape Directory Server Administrator s Guide August 2002...
Страница 442: ...442 Netscape Directory Server Administrator s Guide August 2002...
Страница 478: ...PTA Plug In Syntax Examples 478 Netscape Directory Server Administrator s Guide August 2002...
Страница 498: ...498 Netscape Directory Server Administrator s Guide August 2002...
Страница 512: ...Storing Information in Multiple Languages 512 Netscape Directory Server Administrator s Guide August 2002...
Страница 532: ...Searching an Internationalized Directory 532 Netscape Directory Server Administrator s Guide August 2002...
Страница 538: ...Examples of LDAP URLs 538 Netscape Directory Server Administrator s Guide August 2002...