Enable Ssl Client Authentication With The Internal Database - Netscape MANAGEMENT SYSTEM 6.2 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

The Internal Database
By default, the host name of the Directory Server instance being used as the
internal database is shown as
example,
the internal database from being visible outside the system—that is, a server on
localhost
configuration minimizes the risk of someone connecting to this Directory
Server instance from outside the local machine.
You can configure the host name to something other than
know what you are doing and you think you can limit the visibility of the
internal database to a local subnet. For example, if you installed CMS and
Directory Server on separate machines for load balancing, you will have to
specify the host name of the machine in which Directory Server is installed.
Port number. Type a TCP/IP port number; CMS uses this port for non-SSL
communications with the Directory Server instance that is functioning as the
internal database. Make sure that the port you specify is unique on the host
system.
Directory manager DN. Type the distinguished name (DN) of an entry in your
LDAP directory that has directory manager access. CMS will use this DN when
it accesses the directory tree to communicate with the directory.
To save your changes, click Save.
4.
The CMS configuration is modified. If the changes you made require you to
restart the server, you will be prompted accordingly. In that case, restart the
server.
Enable SSL Client Authentication with the
Internal Database
Stop CMS
1.
Go to the directory
2.
Open the file
3.
Edit the following lines to the indicated values:
4.
internaldb.ldapauth.authtype=SslClientAuth
internaldb.ldapauth.bindDN=CN=Directory Manager
internaldb.ldapauth.bindPWPrompt=Internal LDAP Database
internaldb.ldapconn.host=<ldap_hostname>
290
Netscape Certificate Management System Administrator's Guide • June 2003
localhost
certificates.example.com
can only be accessed from the local machine. Thus, the default
<server-root>/cert-<id>/config
in a text editor.
CMS.cfg
instead of the actual host name (for
). This is done on purpose to insulate
localhost
.
if you

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.2

Table of Contents