
624
Novell eDirectory 8.8 Administration Guide
n
ov
do
cx (e
n)
11
Ju
ly 20
08
E.1.3 Adding Kerberos LDAP Extensions
Kerberos LDAP Extensions provide the functionality to manage Kerberos keys.
To use the Kerberos LDAP extensions, you must install the LDAP libraries for C. For more
information, refer to
LDAP Libraries for C
(http://developer.novell.com/ndk/cldap.htm)
.
To add or remove the Kerberos LDAP extensions, use the krbldapconfig utility, which can be found
in the following locations:
Linux:
extracted_folder
/Linux/nmas/NmasMethods/Novell/GSSAPI/
Kerberos_ldap_extensions/Linux/krbldapconfig
For example:
/misc/eDir88/Linux/nmas/NmasMethods/Novell/GSSAPI/
Kerberos_ldap_extensions/Linux/krbldapconfig
To add the Kerberos LDAP extensions, use the following syntax:
krbldapconfig {-i | -u} -D
bind_DN
[-w
bind_DN_password
] [-h
ldap_host
] [-p
ldap_port
] [-e
trusted_root_cert
]
The following table explains the krbldapconfig utility parameters:
NOTE:
If you do not specify the -h option, the name of the local host that krbldapconfig is invoked
from is used as the default.
If you do not specify the LDAP server port and the trusted root certificate, the default port 389 is
used.
If you do not specify the LDAP server port but specify the trusted root certificate, the default port
636 is used.
Parameter
Description
-i
Adds the Kerberos LDAP extensions to eDirectory.
-u
Removes the Kerberos LDAP extensions from eDirectory.
-D
bind_fdn
Specifies the FDN of the administrator or the user with administrator-
equivalent rights.
This must be in the format cn=admin,o=org.
-w
bind_fdn_password
Specifies the password of the bind FDN (bind_fdn).
-h
ldap_server
Specifies the hostname or IP address of the LDAP server where
Kerberos LDAP extensions must be installed.
-p
port
Specifies the port where the LDAP server is running.
-e
trusted_root_file
Specifies the trusted root certificate filename for the SSL bind.
If you are using an SSL port, specify the -e option.
For more information, refer to
Section E.1.4, “Exporting the Trusted
Root Certificate,” on page 625
.
Содержание EDIRECTORY 8.8 SP3
Страница 4: ...novdocx en 11 July 2008...
Страница 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Страница 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...