
Using Certificate-Based Authentication
436
Red Hat Directory Server Administrator’s Guide • May 2005
Setting up Certificate-Based Authentication
To set up certificate-based authentication, you must:
1.
Create a certificate database for the client and the server or for both servers
involved in replication.
In the Directory Server, the certificate database creation automatically takes
place when you install a certificate. For information on creating a certificate
database for a client, see “Configuring LDAP Clients to Use SSL,” on
page 437.
2.
Obtain and install a certificate on both the client and the server or on both
servers involved in replication.
3.
Enable SSL on the server or on both servers involved in replication.
For information on enabling SSL, refer to “Starting the Server with SSL
Enabled,” on page 428.
NOTE
When specifying the key and certificate database filenames, you
may use absolute or relative paths. If using relative paths, ensure
that they are relative to the server root (for example,
alias/slapd-phonebook-cert8.db
and
alias/slapd-phonebook-key3.db
).
The name of the certificate database has been changed from
cert7.db
to
cert8.db
. Directory Server automatically converts the
cert7.db
to
cert8.db
and uses the new file. However, the
dse.ldif
file may not show the new database name. For example,
you may still see this entry:
nsCertfile: alias/slapd-testDir-cert7.db
If you want the database filename change reflected in the
dse.ldif
file, manually edit the filename in the
dse.ldif
file.
NOTE
If Red Hat Console connects to Directory Server over SSL, selecting
“Require client authentication” disables communication. This is
because, although Red Hat Console supports SSL, it does not have a
certificate to use for client authentication.
Содержание DIRECTORY SERVER 7.1
Страница 1: ...Administrator s Guide Red Hat Directory Server Version7 1 May 2005 Updated February 2009 ...
Страница 20: ...20 Red Hat Directory Server Administrator s Guide May 2005 Glossary 619 Index 635 ...
Страница 22: ...22 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 26: ...26 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 78: ...Maintaining Referential Integrity 78 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 200: ...Assigning Class of Service 200 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 278: ...Compatibility with Earlier Releases 278 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 374: ...Troubleshooting Replication Related Problems 374 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 478: ...Using the Management Information Base 478 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 488: ...488 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 528: ...PTA Plug in Syntax Examples 528 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 545: ...About Windows Sync Chapter 18 Windows Sync 545 Figure 18 1 Active Directory Directory Server Synchronization Process ...
Страница 572: ...572 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 586: ...Storing Information in Multiple Languages 586 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 606: ...Searching an Internationalized Directory 606 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 612: ...Examples of LDAP URLs 612 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 634: ...634 Red Hat Directory Server Administrator s Guide May 2005 ...