Security Best Practices For Novell Ifolder; Using Ssl For Server - Ldap Server Communications - Novell IFOLDER 3.X - SECURITY ADMINISTRATOR GUIDE 08-15-2006 Administrator's Manual

Table of Contents

Advertisement

Security Best Practices for Novell
2
iFolder 3.x
This section provides specific instructions on how to install, configure, and maintain Novell
®
iFolder
3.x in the most secure way possible.
Section 2.1, "Using SSL for Server - LDAP Server Communications," on page 11
Section 2.2, "Using SSL for Enterprise Server - iManager Communications," on page 12
Section 2.3, "Using SSL for Enterprise Server - Client Communications," on page 12
Section 2.4, "Using SSL for Enterprise Server - Web Access Server Communications," on
page 12
Section 2.5, "Using SSL for Web Access Server - Users' Web Browser Communications," on
page 12
Section 2.6, "Disabling SSL 2.0 Protocol," on page 13
Section 2.7, "Configuring a Cipher Suite to Use for SSL/TLS," on page 13
Section 2.8, "Installing Trusted Roots and Certifications on the iFolder server," on page 13
Section 2.9, "Installing Server Certificates from a Known Certificate Authority," on page 13
Section 2.10, "Using a Shared Certificate in iFolder Clusters," on page 14
Section 2.11, "Ensuring Privilege Separation for the iFolder Proxy User," on page 14
Section 2.12, "Securing the iFolder Proxy User Password," on page 14
Section 2.13, "Using Synchronize Now to Remove Users Effective Immediately," on page 15
Section 2.14, "Controlling Access to the iFolder Data Store," on page 15
Section 2.15, "Controlling Access to the iFolder Server Configuration Files," on page 15
Section 2.16, "Controlling Access to and Backing Up the iFolder Audit Logs," on page 15
Section 2.17, "Storing iFolder 3.x Data Nonencrypted on the Server," on page 16
Section 2.18, "Preventing the Propagation of Viruses," on page 16
Section 2.19, "Backing Up the iFolder Server," on page 16
2.1 Using SSL for Server - LDAP Server
Communications
By default, the iFolder enterprise server and Web Access server are configured to communicate with
the LDAP server via SSL. For most deployments, this setting should not be changed. If the LDAP
server co-exists on the same machine as the iFolder enterprise server, an administrator can
reconfigure to disable SSL, which increases the performance of LDAP authentications.
For information, see
"Configuring the Enterprise Server for SSL Communications with the LDAP
Server" in the
Novell iFolder 3.x Administration
Guide.
Security Best Practices for Novell iFolder 3.x
2
®
11

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ifolder 3.x

Table of Contents