
364
Novell eDirectory 8.8 Administration Guide
n
ov
do
cx (e
n)
11
Ju
ly 20
08
To establish a TLS connection, ensure the following:
The LDAP server must know the server's KMO
You connect to the secure port or start TLS after connecting to the clear port
After you reconfigure the LDAP server, refresh the server. See
Section 14.5, “Refreshing the LDAP
Server,” on page 360
. ConsoleOne and Novell iManager automatically refresh the server.
14.6.4 Configuring the Client for TLS
An LDAP client is an application (for example, Netscape Communicator, Internet Explorer, or ICE).
The client must understand the certificate authority that LDAP server uses.
When a server is added into an eDirectory tree, by default the installation creates
A certificate authority for the tree (the tree CA).
A KMO from the tree CA.
The LDAP server uses this certificate provider.
The client needs to import a certificate that the client will trust so that the client can validate the tree
CA that the LDAP server claims to be using. The client must import a certificate from the server so
that whenever the server sends its certificate, the client can validate it and verify that the server is
who it claims to be.
So that the client can get a secure connection, the client must be configured before the connection.
The way that the client imports the certificate differs, based on the kind of application being used.
Each application must have a method to import a certificate. Netscape browser has one way, IE has
another way, and ICE has a third way. These are three different LDAP clients. Each client has its
method for locating the certificates that it trusts.
14.6.5 Exporting the Trusted Root
You can automatically export the trusted root while accepting the certificate server.
To manually export the trusted root, see
Exporting a Trusted Root or Public Key Certificate (http://
www.novell.com/documentation/lg/crt27/crtadmin/data/a2ebopb.html#a2ebopd)
.
The Export functionality will create the specified file. Although you can modify the filename, it's a
good idea to leave “DNS” or “IP” in the filename, so that you can recognize the type of material
object. Also leave the servername.
Install the self-assigned CA in all browsers that establish secure LDAP connections to eDirectory.
If you are using the certificate with Microsoft products (for example, Internet Explorer), leave the
.der extension.
If applications or SDKs require the certificate, import it into a certificate database.
Internet Explorer 5 exports root certificates automatically with a registry update. The traditional
.X509 extension used by Microsoft is required.
Содержание EDIRECTORY 8.8 SP3
Страница 4: ...novdocx en 11 July 2008...
Страница 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Страница 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...