HP UX Red Hat Direry Server Software manual Enabling TLS/SSL Only in the Directory Server

Models: UX Red Hat Direry Server Software

1 638
Download 638 pages 23.73 Kb
Page 426
Image 426

Chapter 11. Managing SSL

the key database. This is the same password used when the server certificate and key were imported into the database. Restarting the Directory Server without the password prompt is possible by using use a hardware crypto device or creating a PIN file (Section 4.3, “Creating a Password File for the Directory Server”).

NOTE

On SSL-enabled servers, be sure to check the file permissions on certificate database files, key database files, and PIN files to protect the sensitive information they contain. Because the server does not enforce read-only permissions on these files, check the file modes to protect the sensitive information contained in these files.

The files must be owned by the Directory Server user, such as the default nobody. The key and cert databases should be owned by the Directory Server user and should typically have read/write access for the owner with no access allowed to any other user (mode 0600). The PIN file should also be owned by the Directory Server user and set to read-only by this user, with no access to anyone other user (mode 0400).

4.1. Enabling TLS/SSL Only in the Directory Server

1.Obtain and install CA and server certificates.

2.Set the secure port for the server to use for TLS/SSL communications.

The encrypted port number must not be the same port number used for normal LDAP communications. By default, the standard port number is 389, and the secure port is 636.

a.Change the secure port number in the Configuration>Settings tab of the Directory Server Console.

b.Restart the Directory Server. It restarts over the regular port.

3.In the Directory Server Console, select the Configuration tab, and then select the top entry in the navigation tree in the left pane. Select the Encryption tab in the right pane.

4.Select the Enable SSL for this Server checkbox.

5.Check the Use this Cipher Family checkbox.

6.Select the certificate to use from the drop-down menu.

7.Click Cipher Settings.

The Cipher Preference dialog box opens. By default, all ciphers are selected.

406

Page 426
Image 426
HP UX Red Hat Direry Server Software manual Enabling TLS/SSL Only in the Directory Server, Click Cipher Settings