Starting the Server with SSL Enabled
428
Red Hat Directory Server Administrator’s Guide • May 2005
9.
Use
pk12util
to export other server certificates and keys created with
certutil
so that they can be used on a remote server.
pk12util -d . -o ldap1.p12 -n Server-Cert1 -w /tmp/pwdfile -k
/tmp/pwdfile -P slapd-
instance_name
-
The
-w
argument is the password used to encrypt the
.p12
file for transport.
The
-k
argument specifies the password for the key database containing the
server certificate being exported to
.p12
.
10.
If the Directory Server will run with TLS/SSL enabled, then create a password
file (
pin.txt
) for the server to use so it will not prompt you for a password
every time it restarts. Creating the password file is described in “Creating a
Password File,” on page 433.
The certificates created by
certutil
are automatically available in the Encryption
tab of the Console; there is not need to import them.
Starting the Server with SSL Enabled
Most of the time, you want your server to run with SSL enabled. If you
temporarily disable SSL, make sure you re-enable it before processing
transactions that require confidentiality, authentication, or data integrity.
There are two ways to use SSL:
• Enabling SSL communications to the Directory Server only
• Requiring SSL among the Directory Server, Admin Server, Console, and other
client applications
For routine use, you only need to enable SSL to the Directory Server.
Before you can activate SSL, you must create a certificate database, obtain and
install a server certificate, and trust the CA’s certificate, as described in
“Obtaining and Installing Server Certificates,” on page 420.
NOTE
On SSL-enabled servers, be sure to check the file permissions on
certificate-database files, key-databases files, and PIN files to
protect the sensitive information they contain. Because the server
does not enforce read-only permissions on these files, check the file
modes to protect the sensitive information contained in these files.
Содержание DIRECTORY SERVER 7.1
Страница 1: ...Administrator s Guide Red Hat Directory Server Version7 1 May 2005 Updated February 2009 ...
Страница 20: ...20 Red Hat Directory Server Administrator s Guide May 2005 Glossary 619 Index 635 ...
Страница 22: ...22 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 26: ...26 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 78: ...Maintaining Referential Integrity 78 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 200: ...Assigning Class of Service 200 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 278: ...Compatibility with Earlier Releases 278 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 374: ...Troubleshooting Replication Related Problems 374 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 478: ...Using the Management Information Base 478 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 488: ...488 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 528: ...PTA Plug in Syntax Examples 528 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 545: ...About Windows Sync Chapter 18 Windows Sync 545 Figure 18 1 Active Directory Directory Server Synchronization Process ...
Страница 572: ...572 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 586: ...Storing Information in Multiple Languages 586 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 606: ...Searching an Internationalized Directory 606 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 612: ...Examples of LDAP URLs 612 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 634: ...634 Red Hat Directory Server Administrator s Guide May 2005 ...