Enabling Tls/Ssl In The Directory Server, Administration Server, And Console - Red Hat DIRECTORY SERVER 8.0 - ADMINISTRATION Administration Manual

Hide thumbs Also See for DIRECTORY SERVER 8.0 - ADMINISTRATION:
Table of Contents

Advertisement

11.4.2. Enabling TLS/SSL in the Directory Server, Administration
Server, and Console
1. Obtain server certificates and CA certs, and install them on the Directory Server. This is described
Section 11.2, "Obtaining and Installing Server
in
2. Obtain and install server and CA certificates on the Administration Server. This is a similar process
as for the Directory Server.
NOTE
It is important that the Administration Server and Directory Server have a CA
certificate in common so that they can trust the other's certificates.
3. If the default port number of 636 is not used, change the secure port setting.
a. Change the secure port number in the Configuration>Settings tab of the Directory Server
Console, and save.
b. Restart the Directory Server. It restarts over the regular port.
service dirsrv restart instance
4. In the Configuration tab of the Directory Server Console, highlight the server name at the top of
the table, and select the Encryption tab.
5. Select the Enable SSL checkbox.
6. Check the Use this Cipher Family checkbox.
7. Select the certificate to use from the drop-down menu.
8. Click Cipher Settings.
The Cipher Preference dialog box opens. By default, all ciphers are selected.
9. Set the preferences for client authentication.
• Do not allow client authentication. With this option, the server ignores the client's certificate. This
does not mean that the bind will fail.
• Allow client authentication. This is the default setting. With this option, authentication is
performed on the client's request. For more information about certificate-based authentication,
Section 11.6, "Using Certificate-Based
see
• Require client authentication. With this option, the server requests authentication from the client.
NOTE
To use certificate-based authentication with replication, then configure the consumer
server either to allow or to require client authentication.

Enabling TLS/SSL in the Directory Server, Administration Server, and Console

Certificates".
2
Authentication".
355

Advertisement

Table of Contents
loading

Table of Contents