Chapter 11. Managing SSL
362
11.6.2. Allowing/Requiring Client Authentication
If Red Hat Console is configured to connect to the Directory Server using TLS/SSL
and
the Directory
Server
requires
client authentication, the Red Hat Console cannot be used to manage server
applications. You must use the appropriate command-line utilities instead.
However, to change the directory configuration to no longer
require
but
allow
client authentication in
order to use the Red Hat Console, do the following:
1. Stop the Directory Server.
2
service dirsrv stop
instance
2. Modify the
cn=encryption,cn=config
entry by changing the value of the
nsSSLClientAuth
attribute from
required
to
allowed
.
For information on modifying entries from the command-line, see
Section 2.2.4, “Adding and
Modifying Entries Using ldapmodify”
.
3. Start the Directory Server.
service dirsrv start
instance
Now start Red Hat Console.
11.7. Configuring LDAP Clients to Use SSL
For all the users of the Directory Server to use TLS/SSL or certificate-based authentication when they
connect using LDAP client applications, they
must
perform the following tasks:
• Create a certificate database.
• Trust the certificate authority (CA) that issues the server certificate.
These operations are sufficient if to ensure that LDAP clients recognize the server's certificate.
However, to require the LDAP clients to use their own certificate to authenticate to the directory, make
sure that all the directory users obtain and install a personal certificate.
NOTE
Some client applications do not verify that the server has a trusted certificate.
1. On the client system, obtain a client certificate from the CA.
2. Install the client certificate on the client system.
Regardless of how the certificate is sent (either in email or on a web page), there should be a link
to click to install the certificate.
Record the certificate information that is sent from the CA, especially the subject DN of the
certificate because the server must be configured to map it to an entry in the directory. The client
certificate resembles the following:
Содержание DIRECTORY SERVER 8.0
Страница 18: ...xviii ...
Страница 29: ...Configuring the Directory Manager 11 6 Enter the new password and confirm it 7 Click Save ...
Страница 30: ...12 ...
Страница 112: ...94 ...
Страница 128: ...110 ...
Страница 190: ...Chapter 6 Managing Access Control 172 4 Click New to open the Access Control Editor ...
Страница 224: ...206 ...
Страница 324: ...306 ...
Страница 334: ...316 ...
Страница 358: ...340 ...
Страница 410: ...392 ...
Страница 420: ...402 ...
Страница 444: ...426 ...
Страница 454: ...436 ...
Страница 464: ...446 ...
Страница 484: ...466 ...
Страница 512: ...494 ...
Страница 522: ...504 ...