Step 4: Trust the Certificate Authority
349
After installing the server certificate, configure the Directory Server to trust the CA which issued the
server's certificate.
11.2.4. Step 4: Trust the Certificate Authority
Configuring the Directory Server to trust the certificate authority consists of obtaining the CA's
certificate and installing it into the server's certificate database. This process differs depending on
the certificate authority. Some commercial CAs provide a web site that allow users to automatically
download the certificate. Others will email it back to users.
After receiving the CA certificate, use the
Certificate Install Wizard
to configure the Directory Server
to trust the certificate authority.
1. In the Directory Server Console, select the
Tasks
tab, and click
Manage Certificates
.
2. Go to the
CA Certs
tab, and click
Install
.
3. If the CA's certificate is saved to a file, enter the path in the field provided. Alternatively, copy and
paste the certificate, including the headers, into the text box. Click
Next
.
4. Check that the certificate information that opens is correct, and click
Next
.
5. Name the certificate, and click
Next
.
6. Select the purpose of trusting this certificate authority; it is possible to select both options:
•
Accepting connections from clients (Client Authentication).
The server checks that the client's
certificate has been issued by a trusted certificate authority.
•
Accepting connections to other servers (Server Authentication).
This server checks that
the directory to which it is making a connection (for replication updates, for example) has a
certificate that has been issued by a trusted certificate authority.
7. Click
Done
.
Once both the server and CA certificates are installed, it is possible to configure the Directory Server
to run in TLS/SSL. However, Red Hat recommends verify ingthat the certificates have been installed
correctly.
11.2.5. Step 5: Confirm That The New Certificates Are Installed
1. In the Directory Server Console, select the
Tasks
tab, and click
Manage Certificates
.
2. Select the
Server Certs
tab.
A list of all the installed certificates for the server opens.
3. Scroll through the list. The certificates installed previously should be listed.
It is now possible to set up the Directory Server to run in TLS/SSL.
Содержание DIRECTORY SERVER 8.0
Страница 18: ...xviii ...
Страница 29: ...Configuring the Directory Manager 11 6 Enter the new password and confirm it 7 Click Save ...
Страница 30: ...12 ...
Страница 112: ...94 ...
Страница 128: ...110 ...
Страница 190: ...Chapter 6 Managing Access Control 172 4 Click New to open the Access Control Editor ...
Страница 224: ...206 ...
Страница 324: ...306 ...
Страница 334: ...316 ...
Страница 358: ...340 ...
Страница 410: ...392 ...
Страница 420: ...402 ...
Страница 444: ...426 ...
Страница 454: ...436 ...
Страница 464: ...446 ...
Страница 484: ...466 ...
Страница 512: ...494 ...
Страница 522: ...504 ...