
Configuring GSSAPI with eDirectory
567
no
vd
ocx (
E
NU)
01
F
ebr
ua
ry
200
6
NOTE:
If you do not specify the -h option, the name of the local host that krbldapconfig is invoked
from is used as the default.
If you do not specify the LDAP server port and the trusted root certificate, the default port 389 is
used.
If you do not specify the LDAP server port but specify the trusted root certificate, the default port
636 is used.
For example, enter the following to add the extensions:
krbldapconfig -i -D cn=admin,o=org -w password -h ldapserver -p 389
Or to remove, enter the following:
krbldapconfig -u -D cn=admin,o=org -w password -h ldapserver -p 389
IMPORTANT:
You must manually refresh the LDAP server for the installation changes to take
effect. For more information, refer to
Section 13.5, “Refreshing the LDAP Server,” on page 344
.
E.1.4 Exporting the Trusted Root Certificate
1
In iManager, click
eDirectory Administration
>
Modify Object
to open the Modify Object page.
2
Click
Single Object
, then select the Server Certificate object of the server.
3
Click
OK
.
4
Click the
Certificates
tab, then select
Trusted Root Certificate
and view the details of the
certificate.
5
Click
Export
to launch the
Certificate Export Wizard
.
6
Specify whether you want to export the private key or not, then click
Next
.
7
Select
File in Binary DER Format
, then click
Next
.
8
Click
Save the Exported Certificate to a File
.
9
Click
Close
.
E.2 Configuring the SASL-GSSAPI Method
1
The iManager plug-in for SASL-GSSAPI will not work if iManager is not configured to use
SSL/TLS connection to eDirectory. A secure connection is mandated to protect the realm's
master key and principal keys.
By default, iManager is usually configured for SSL/TLS connection to eDirectory. You need to
add the SSL trusted root certificates of the LDAP server that you use for Kerberos
administration to iManager.
For information on configuring iManager with SSL/TLS connection to eDirectory, refer to the
iManager 2.0 Administration Guide
(http://www.novell.com/documentation/lg/imanager20/
index.html?page=/documentation/lg/imanager20/imanager20/data/am4ajce.html#bow4dv4)
.
2
Complete the following procedures in the order given:
2a
Extend the Kerberos Schema
.
Содержание EDIRECTORY 8.8 - GUIDE
Страница 4: ...novdocx ENU 01 February 2006...
Страница 16: ...16 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 68: ...68 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 90: ...90 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 184: ...184 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 249: ...250 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 307: ...308 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 333: ...334 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 371: ...372 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 439: ...440 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 519: ...520 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 529: ...530 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 555: ...556 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...