
362
Novell eDirectory 8.8 Administration Guide
n
ov
do
cx (e
n)
11
Ju
ly 20
08
Description: The Require TLS for Simple Binds with Passwords check box
5
Click
Apply
, then click
OK
.
14.6.2 Starting and Stopping TLS
The extended LDAP operation STARTTLS enables you to upgrade from a clear connection to an
encrypted connection. This upgrade was new to eDirectory 8.7.
When you use the encrypted connection, the entire packet is encrypted. Therefore, sniffers are
unable to diagnose data sent across the network.
Scenario: Using STARTTLS—
You create a clear connection (to port 389) and do some
anonymous searches. However, when you get into secure data, you prefer to start a TLS session. You
issue a STARTTLS extended operation to upgrade from a clear connection to an encrypted
connection. Your data is secure.
You stop TLS to turn an encrypted session into a clear connection. A clear connection requires less
overhead because data to and from the client is not encrypted and decrypted. Therefore, data moves
faster when you use a clear connection. At this point, the connection is downgraded to Anonymous.
When you authenticate, you use the LDAP Bind operation. Bind establishes your ID based on your
provided credentials. When you stop TLS, the LDAP service removes any authentication previously
established. Your authentication state changes to Anonymous. Therefore, if you want a state other
than Anonymous you must reauthenticate.
Scenario: Reauthenticating—
Henri runs STOPTLS. His status changes to Anonymous. To access
and use his files on the Net, Henri runs the Bind command, provides his login credentials, is
authenticated, and continues working in clear text on the Internet.
14.6.3 Configuring the Server for TLS
When a TLS session is instantiated, a handshake occurs. The server and the client exchange data.
The server determines how the handshake occurs. To establish that the server is legitimate, the
server always sends the server's certificate to the client. This handshake guarantees to the client that
the server is indeed the expected server.
To require that the client also establish legitimacy, you set a value on the server. This attribute is
ldapTLSVerifyClientCertificate.
Содержание EDIRECTORY 8.8 SP3
Страница 4: ...novdocx en 11 July 2008...
Страница 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Страница 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...