348
Novell eDirectory 8.8 Administration Guide
no
vd
ocx (
E
NU)
01
F
ebr
ua
ry
200
6
The installation automatically associates one of those certificates with the LDAP server. In Novell
iManager, the Connections tab for the LDAP Server object displays a DN. This DN represents the
X.509 certificate. The Server Certificate field in the following figure illustrates this DN.
In Novell iManager, you can browse to the Key Material object (KMO) certificates. Using the drop-
down list, you can change to a different certificate. Either the DNS or the IP certificate will work.
As part of the validation, the server should validate the name (the hard IP address or the DN) that is
in the certificate.
To establish a TLS connection, ensure the following:
• The LDAP server must know the server's KMO
• You connect to the secure port or start TLS after connecting to the clear port
After you reconfigure the LDAP server, refresh the server. See
Section 13.5, “Refreshing the LDAP
Server,” on page 344
. ConsoleOne and Novell iManager automatically refresh the server.
13.6.4 Configuring the Client for TLS
An LDAP client is an application (for example, Netscape Communicator, Internet Explorer, or ICE).
The client must understand the certificate authority that LDAP server uses.
When a server is added into an eDirectory tree, by default the installation creates
• A certificate authority for the tree (the tree CA).
• A KMO from the tree CA.
The LDAP server uses this certificate provider.
The client needs to import a certificate that the client will trust so that the client can validate the tree
CA that the LDAP server claims to be using. The client must import a certificate from the server so
that whenever the server sends its certificate, the client can validate it and verify that the server is
who it claims to be.
So that the client can get a secure connection, the client must be configured before the connection.
The way that the client imports the certificate differs, based on the kind of application being used.
Each application must have a method to import a certificate. Netscape browser has one way, IE has
another way, and ICE has a third way. These are three different LDAP clients. Each client has its
method for locating the certificates that it trusts.
Содержание EDIRECTORY 8.8 - GUIDE
Страница 4: ...novdocx ENU 01 February 2006...
Страница 16: ...16 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 68: ...68 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 90: ...90 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 184: ...184 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 249: ...250 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 307: ...308 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 333: ...334 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 371: ...372 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 439: ...440 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 519: ...520 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 529: ...530 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 555: ...556 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...