Nsslapd-Ssl-Check-Hostname (Verify Hostname For Outbound Connections); Nsslapd-Threadnumber (Thread Number) - Netscape DIRECTORY SERVER 7.0 Configuration Manual

Configuration, command, and file reference
Hide thumbs Also See for NETSCAPE DIRECTORY SERVER 7.0:
Table of Contents

Advertisement

nsslapd-ssl-check-hostname (Verify Hostname for Outbound
Connections)
Specifies whether an SSL-enabled Directory Server (with certificate based client
authentication turned on) should verify authenticity of a request by matching the
hostname against the value assigned to the common name (
subject name in the certificate being presented. By default, the attribute is set to
. If it is on and if the hostname does not match the
off
appropriate error and audit messages are logged. For example, in a replicated
environment, messages similar to these are logged in the supplier server's log files
if it finds that the peer server's hostname doesn't match the name specified in its
certificate:
[DATE] - SSL alert: ldap_sasl_bind("",LDAP_SASL_EXTERNAL) 81
(Netscape runtime error -12276 - Unable to communicate securely
with peer: requested domain name does not match the server's
certificate.)
[DATE] NSMMReplicationPlugin - agmt="cn=to ultra60 client auth"
(ultra60:1924): Replication bind with SSL client authentication
failed: LDAP error 81 (Can't contact LDAP server)
It is recommended that you turn this attribute on to protect Directory Server's
outbound SSL connections against a Man In The Middle (MITN) attack.
Entry DN:
cn=config
Valid Values:
on | off
Default Value:
off
Syntax:
DirectoryString
Example:
nsslapd-ssl-check-hostname: on

nsslapd-threadnumber (Thread Number)

Defines the number of operation threads that the Directory Server will create
during startup. The
nsslapd-threadnumber
many directory clients performing time-consuming operations such as add or
modify, as this ensures that there are other threads available for servicing
short-lived operations such as simple searches. This attribute is not available from
the server console.
Entry DN:
cn=config
Core Server Configuration Attributes Reference
) attribute of the
cn
attribute of the certificate,
cn
value should be increased if you have
Chapter 2
Core Server Configuration Reference
83

Advertisement

Table of Contents
loading

Table of Contents