During installation of the Administration Server, SUSE Linux Enterprise Point of
Service automatically installs a CA and generates self-signed certificates to secure
communication between
Administration
and Branch Servers. The public key
for the CA is distributed to the Branch Servers only if you enable LDAP SSL during
installation. For more information on setting up LDAP SSL, see Section 4.2, “Ini-
tializing the LDAP Directory” (page 38).
/etc/SLEPOS/keys/ca/
This file contains the CA certificate and keys.
/etc/SLEPOS/keys/ca/ca.crt
This file contains the public key for the CA that signed the server certificate. This
is copied over to the
rsync
directory only if you enable LDAP SSL during instal-
lation of the Administration Server. the public key for the CA allows the Branch
Servers to trust the Administration Server.
/etc/SLEPOS/keys/ca/ca.db.certs
This filecontains a database that tracks the server certificates the CA has signed.
/etc/SLEPOS/keys/ca/ca.key
This files contains the CA’s private key.
/etc/SLEPOS/keys/certs/
This file contains the Administration Server certificate and keys.
/etc/SLEPOS/keys/certs/server.crt
This file contains the Administration Server certificate public key. This certificate
is used to secure LDAP communication between
Administration
and Branch
Server.
/etc/SLEPOS/keys/certs/server.csr
This file contains the Administration Server’s Certificate Signing Request (CSR).
This form is submitted to the CA. The CA signs the CSR to create the server cer-
tificate.
/etc/SLEPOS/keys/certs/server.key
This file contains the private key for the server certificate.
220
SUSE Linux Enterprise Point of Service Guide