LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise
User Name
Password
Linux - Enterprise This forum is for all items relating to using Linux in the Enterprise.

Notices


Reply
  Search this Thread
Old 07-28-2011, 03:05 PM   #1
custangro
Senior Member
 
Registered: Nov 2006
Location: California
Distribution: Fedora , CentOS , RHEL
Posts: 1,979
Blog Entries: 1

Rep: Reputation: 209Reputation: 209Reputation: 209
Export Cert for LDAP Clients


Hello,

I'm using CENTOS-DS and I've installed it and it's up and running fine.

I created a cert and forced the CENTOS-DS to only run on a secure port. Now The clients can't authenticate beacuse the TLS option in "system-config-authentication" isn't ticked off because I don't have a cert for them to download.

How can I generate this file? Google only yields results on "How to make your LDAP server use SSL/TLS"...but none of these howtos show how to configure the clients.

All servers are running CentOS 5

--C
 
Old 07-28-2011, 03:37 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
well the clients just need to have tls enabled in ldap.conf ("ssl starttls" in ldap.conf). Well that and a valid CA Certificate, which is outside of the ldap side of things. If you are using a self CA then you would look to put your CA cert on each client and point to it using "tls_cacertdir /etc/ssl/certs" for example. If you are using a commerically signed cert then there should be no further action required.

Not sure why you can't find anything, there's loads out there. http://www.openldap.org/pub/ksoper/O...P_TLS.html#4.1
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Sort attributes by name for each entry in ldapsearch output (ldap database export) llattan Linux - Enterprise 1 08-03-2023 08:28 AM
3. What /etc/exports entry would export a directory named /nfs to all clients on the 1bigboy74 Linux - Newbie 3 01-22-2011 01:24 PM
Export from mysql to ldap - encrypted passwords clau_bolson Linux - Server 1 06-11-2009 01:45 PM
Publish Cert on LDAP Server PcHammer Linux - Software 1 05-05-2004 02:42 AM
Export Verisign cert Dmagill Red Hat 0 03-23-2004 01:58 PM

LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise

All times are GMT -5. The time now is 03:30 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration