
Configuring LDAP Clients to Use SSL
Chapter 11
Managing SSL and SASL
437
4.
Map the certificate’s distinguished name to a distinguished name known by
your directory.
This allows you to set access control for the client when it binds using this
certificate. This mapping process is described in
Managing Servers with Red Hat
Console
.
Allowing/Requiring Client Authentication
If you have configured Red Hat Console to connect to your Directory Server using
SSL
and
your Directory Server
requires
client authentication, you can no longer use
Red Hat Console to manage server applications. You will have to use the
appropriate command-line utilities instead.
However, if at a later date you wish to change your directory configuration to no
longer
require
but
allow
client authentication, so that you can use Red Hat Console,
you must follow these steps:
1.
Stop Directory Server.
For information on stopping and starting the server from the command-line,
see “Starting and Stopping the Server from the Command-Line,” on page 38.
2.
Modify the
cn=encryption,cn=config
entry by changing the value of the
nsSSLClientAuth
attribute from
required
to
allowed
.
For information on modifying entries from the command-line, see chapter 2,
“Creating Directory Entries.”
3.
Start Directory Server.
You can now start Red Hat Console.
Configuring LDAP Clients to Use SSL
If you want all the users of your Directory Server to use SSL or certificate-based
authentication when they connect using LDAP client applications, you must make
sure they perform the following tasks:
• Create a certificate database.
• Trust the Certificate Authority (CA) that issues the server certificate.
Содержание DIRECTORY SERVER 7.1
Страница 1: ...Administrator s Guide Red Hat Directory Server Version7 1 May 2005 Updated February 2009 ...
Страница 20: ...20 Red Hat Directory Server Administrator s Guide May 2005 Glossary 619 Index 635 ...
Страница 22: ...22 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 26: ...26 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 78: ...Maintaining Referential Integrity 78 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 200: ...Assigning Class of Service 200 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 278: ...Compatibility with Earlier Releases 278 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 374: ...Troubleshooting Replication Related Problems 374 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 478: ...Using the Management Information Base 478 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 488: ...488 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 528: ...PTA Plug in Syntax Examples 528 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 545: ...About Windows Sync Chapter 18 Windows Sync 545 Figure 18 1 Active Directory Directory Server Synchronization Process ...
Страница 572: ...572 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 586: ...Storing Information in Multiple Languages 586 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 606: ...Searching an Internationalized Directory 606 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 612: ...Examples of LDAP URLs 612 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 634: ...634 Red Hat Directory Server Administrator s Guide May 2005 ...