If You Don't Want To Use Edirectory Certificates - Novell OPEN ENTERPRISE SERVER - PLANNING AND IMPLEMENTATION GUIDE 12-2010 Implementation Manual

Planning and implementation guide
Hide thumbs Also See for OPEN ENTERPRISE SERVER - PLANNING AND IMPLEMENTATION GUIDE 12-2010:
Table of Contents

Advertisement

6 Browse to the certificate file you downloaded in
on page 231
7 Select Trust this CA to identify Web sites, then click OK > OK > OK.
Firefox now trusts certificates from the servers in the tree.
Importing the CA Certificate into Internet Explorer 6 and 7 on Windows
1 Launch Internet Explorer.
2 Click Tools > Internet Options.
3 Select the Content tab.
4 Click Certificates.
5 Click Import.
The Certificate Import Wizard launches.
6 Click Next.
7 Click Browse,
8 In the Files of Type drop-down list, select All Files(*.*), browse to the file you downloaded in
"Exporting the CA's Self-Signed Certificate" on page
9 Click Next.
10 Click Next.
Choose the default, Automatically select the certificate store based on the type of certificate.
11 Click Finish > Yes > OK.
Internet Explorer now trusts certificates from the servers in the tree.
22.3 If You Don't Want to Use eDirectory
Certificates
For most organizations, the eDirectory certificate solution in OES 2 is an ideal way to eliminate the
security vulnerabilities mentioned at the beginning of this chapter. However, some administrators,
such as those who have third-party keys installed on their servers, probably want to keep their
installed certificates in place.
You can prevent the use of eDirectory certificates for HTTPS services by making sure that the
option to use them is not selected on the first eDirectory configuration page. This might or might not
require that you change the eDirectory installation option, depending on your scenario.
Table 22-2
Table 22-2
Scenario
New install
232 OES 2 SP3: Planning and Implementation Guide
and click Open.
outlines the default setting for each scenario.
Default eDirectory Certificate for HTTPS Settings
Certificate Option
Default Result
Setting
Selected
All HTTPS services on the
server are configured to use
eDirectory certificates.
"Exporting the CA's Self-Signed Certificate"
231, then click Open.
If you Change the Default Setting
All HTTPS services on the server
are configured to use the YaST-
generated temporary certificates.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Open enterprise server 2 sp3

Table of Contents