Starting the Server with SSL Enabled
NOTE
You can further configure the server to verify the authenticity of requests by
9.
selecting the "Check hostname against name in certificate for outbound SSL
connections" option. The server does this verification by matching the
hostname against the value assigned to the common name (
subject name in the certificate being presented for authentication.
By default, this feature is disabled. If it's enabled and if the hostname does not
match the
are logged. For example, in a replicated environment, messages similar to
these are logged in the supplier server's log files if it finds that the peer
server's hostname doesn't match the name specified in its certificate:
It is recommended that you enable this option to protect Directory Server's
outbound SSL connections against a Man in the Middle (MITM) attack.
Click Save.
10.
Restart the Directory Server. You must restart from the command-line.
11.
Enabling SSL in the Directory Server, Admin
Server, and Console
Obtain server certificates and CA certs, and install them on the Directory
1.
Server.
Obtain and install server and CA certificates on the Administration Server.
2.
It is important that the Administration Server and Directory Server have their
CA certificates in common so that they trust the other s certificates.
430
Red Hat Directory Server Administrator's Guide • May 2005
If you are using certificate-based authentication with replication,
then you must configure the consumer server either to allow or to
require client authentication.
attribute of the certificate, appropriate error and audit messages
cn
[DATE] - SSL alert: ldap_sasl_bind("",LDAP_SASL_EXTERNAL) 81
(Netscape runtime error -12276 - Unable to communicate
securely with peer: requested domain name does not match the
server's certificate.)
[DATE] NSMMReplicationPlugin - agmt="cn=to ultra60 client
auth" (ultra60:1924): Replication bind with SSL client
authentication failed: LDAP error 81 (Can't contact LDAP
server)
) attribute of the
cn
Need help?
Do you have a question about the DIRECTORY SERVER 7.1 - ADMINISTRATOR and is the answer not in the manual?
Questions and answers