Creating a Password File for the Directory Server
357
the certificate. Click
OK
to accept the certificate (either only for that current session or
permanently).
11.4.3. Creating a Password File for the Directory Server
It is possible to store the certificate password in a password file. By placing the certificate database
password in a file, the server can be started from the Directory Server Console and also restarted
automatically when running unattended.
WARNING
This password is stored in clear text within the password file, so its usage represents a
significant security risk. Do not use a password file if the server is running in an unsecured
environment.
The password file must be in the same directory where the other key and certificate databases
for Directory Server are stored. This is usually the main configuration directory,
/etc/dirsrv/
slapd-
instance_name
. The file should be named
pin.txt
.
Include the token name and password in the file, such as
token:password
. For example:
Internal (Software) Token:secret
For the NSS software crypto module, the token is always called
internal
.
The PIN file should be owned by the Directory Server user and set to read-only by the Directory
Server user, with no access to anyone other user (mode
0400
).
11.4.4. Creating a Password File for the Administration Server
Like the Directory Server, the Administration Server can use a password file during login when TLS/
SSL is enabled.
WARNING
This password is stored in clear text within the password file, so its usage represents a
significant security risk. Do not use a password file if the server is running in an unsecured
environment.
1. Open the Administration Server configuration directory,
/etc/dirsrv/admin-serv
.
2. Create a password file named
password.conf
. The file should include a line with the token
name and password, in the form
token:password
. For example:
internal:secret
For the NSS software crypto module (the default software database), the token is always called
internal
.
The password file should be owned by the Administration Server user and set to read-only by the
Administration Server user, with no access to any other user (mode
0400
).
Содержание DIRECTORY SERVER 8.0
Страница 18: ...xviii ...
Страница 29: ...Configuring the Directory Manager 11 6 Enter the new password and confirm it 7 Click Save ...
Страница 30: ...12 ...
Страница 112: ...94 ...
Страница 128: ...110 ...
Страница 190: ...Chapter 6 Managing Access Control 172 4 Click New to open the Access Control Editor ...
Страница 224: ...206 ...
Страница 324: ...306 ...
Страница 334: ...316 ...
Страница 358: ...340 ...
Страница 410: ...392 ...
Страница 420: ...402 ...
Страница 444: ...426 ...
Страница 454: ...436 ...
Страница 464: ...446 ...
Страница 484: ...466 ...
Страница 512: ...494 ...
Страница 522: ...504 ...