
346
Novell eDirectory 8.8 Administration Guide
no
vd
ocx (
E
NU)
01
F
ebr
ua
ry
200
6
•
“Configuring the Server for TLS” on page 347
•
“Configuring the Client for TLS” on page 348
•
“Exporting the Trusted Root” on page 349
•
“Authenticating with a Client Certificate” on page 349
•
“Using Certificate Authorities from Third-Party Providers” on page 349
•
“Using SASL” on page 351
13.6.1 Requiring TLS for Simple Binds with Passwords
Secure Socket Layer (SSL) 3.1 was released through Netscape. IETF took ownership for that
standard by implementing Transport Layer Security (TLS) 1.0.
TLS allows for connections to be encrypted in the Session layer. The encrypted port doesn't have to
be used to get a TLS connection. There's another way: port 636 is the implied TLS port and the
LDAP server automatically starts a TLS session when a client connects to the secure port.
A client can also connect to the clear-text port and later use TLS to upgrade the connection to an
encrypted connection.
To require TLS for simple binds with passwords:
1
In Novell iManager, click the
Roles and Tasks
button
.
2
Click
LDAP
>
LDAP Overview
>
View LDAP Groups
.
3
Click the LDAP Group object, then click
Information
on the
General
tab.
4
Check the
Require TLS for Simple Binds with Passwords
check box.
5
Click
Apply
, then click
OK
.
13.6.2 Starting and Stopping TLS
The extended LDAP operation STARTTLS enables you to upgrade from a clear connection to an
encrypted connection. This upgrade was new to eDirectory 8.7.
When you use the encrypted connection, the entire packet is encrypted. Therefore, sniffers are
unable to diagnose data sent across the network.
Содержание EDIRECTORY 8.8 - GUIDE
Страница 4: ...novdocx ENU 01 February 2006...
Страница 16: ...16 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 68: ...68 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 90: ...90 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 184: ...184 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 249: ...250 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 307: ...308 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 333: ...334 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 371: ...372 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 439: ...440 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 519: ...520 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 529: ...530 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 555: ...556 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...