LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 09-20-2013, 11:00 AM   #1
coldbeer
Member
 
Registered: May 2006
Location: Orion–Cygnus Arm, MWG
Distribution: Slackware, Ubuntu
Posts: 249

Rep: Reputation: 130Reputation: 130
HTTP with LDAP - encryption


I've got my web server set up with LDAP protection on a web server directory. It all works but its all unencrypted. The LDAP is on another server by itself. Now I want to encrypt the connections.

Question: To encrypt credentials on a protected apache web server directory, I need to use both https and ldaps - is that correct?



[browser]---https:---->[apache server]---ldaps:--->[ldap server]


Using just httpS & ldap OR http & ldapS would transmit a plain password part of the way, right? Or is there something else I don't understand?

Thanks. I'm on a fast learning curve and trying to sort out my confusion.
 
Old 09-21-2013, 10:04 AM   #2
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,673
Blog Entries: 4

Rep: Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945
Usually, in practice, I see LDAP servers being accessed through (often, hardware) VPN tunnels . . .
 
Old 09-23-2013, 06:33 PM   #3
twantrd
Senior Member
 
Registered: Nov 2002
Location: CA
Distribution: redhat 7.3
Posts: 1,440

Rep: Reputation: 52
That is correct, Coldbeer.... https->ldaps.
 
Old 09-24-2013, 01:49 PM   #4
coldbeer
Member
 
Registered: May 2006
Location: Orion–Cygnus Arm, MWG
Distribution: Slackware, Ubuntu
Posts: 249

Original Poster
Rep: Reputation: 130Reputation: 130
Smile

I've got it working now. I have https to the client (browser) via a self-signed certificate. Then on the LDAP side I have the normal ldap:// connection (not ldaps://) with a STARTTLS command appended to AuthLDAPURL statement in httpd.conf. Also LDAPVerifyServerCert off at the root level of httpd.conf.

I've been using wireshark to verify the connections and it all looks good now.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LDAP (nss_ldap) conf file - bindpw encryption question codeape Linux - Security 1 05-01-2013 02:25 AM
[SOLVED] Adding package sources fails saying "http://http not found skykooler Ubuntu 2 07-02-2010 09:32 AM
Linux password encryption and data encryption Tux-Slack Programming 4 06-20-2007 06:46 AM
IBM Http server with ldap authentication Rinish Linux - Networking 1 06-16-2005 08:11 AM
Mandrake 9.0 Wireless Works without encryption.. does not with encryption topcat Linux - Wireless Networking 3 05-04-2003 08:47 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 01:02 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration