Ssl Options - Netscape DIRECTORY SERVER 6.1 Configuration Manual

Configuration, command, and file reference
Hide thumbs Also See for NETSCAPE DIRECTORY SERVER 6.1:
Table of Contents

Advertisement

ldapsearch

SSL Options

You can use the following command-line options to specify that
LDAPS when communicating with your SSL-enabled Directory Server. You also
use these options if you want to use certificate-based authentication. These options
are valid only when LDAPS has been turned on and configured for your Directory
Server. For information on certificate-based authentication and creating a
certificate database for use with LDAP clients see Chapter 11, "Managing SSL" in
the Netscape Directory Server Administrator's Guide.
In addition to the standard
using SSL, you must specify the following:
-p
-Z
-P
-N
-K
-W
Option
-K
-m
-N
222
Netscape Directory Server Configuration, Command, and File Reference • August 2002
ldapsearch
to specify Directory Server's encrypted port
to specify SSL
to specify your certificate database's filename and path
to specify your certificate name
to specify your private key database's filename and path
to specify the password for your private key database
Description
Specifies the filename and path of the private key database of the client.
In previous releases of Directory Server, except for when doing
certificate-based authentication, it wasn't necessary to specify the path to the
key database (using the -K option). In this release of Directory Server,
irrespective of the type of authentication being performed, you must specify
the -K option when the key database has a different name than key3.db or
when the key database is not under the same directory as the certificate
database, the cert7.db file (the path for which is specified with the -P
option).
Specifies the path to the security module database. For example,
/usr/netscape/servers/admin-serv/config/secmodule.db. You
only need to specify this option if the security module database is in a different
directory from the certificate database itself.
Specifies the certificate name to use for certificate-based client authentication.
For example, -N "Server-Cert". If this option is specified, then the -Z, -P,
and -W options are required. Also, if this option is specified, then the -D and
-w options must not be specified, or certificate-based authentication will not
occur and the bind operation will use the authentication credentials specified
on -D and -w.
options, to run an
ldapsearch
use
ldapsearch
command

Advertisement

Table of Contents
loading

Table of Contents