1
0

configtab_rootnode3.htm 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368
  1. <html>
  2. <!--This html file is XHTML complaint, as set forth in the
  3. w3c recommendations except for the following:
  4. Lists work as they do in older versions on HTML and not as
  5. directed in XHTML.
  6. The <a name=" "> tags have targets that use spaces. -->
  7. <head>
  8. <meta name="keywords" content="e-commerce, ecommerce, Internet software, e-commerce applications, electronic commerce, ebusiness, e-business, enterprise software, net economy, software, ecommerce solutions, e-commerce services, netscape, marketplace, digital marketplace, Red Hat, Fedora" />
  9. <meta http-equiv="content-type" content="text/html; charset=ISO-8859-1" />
  10. <meta name="templatebase" content="Authored in FrameMaker. Converted to HTML in WebWorks Publisher. manual wdt 1.6" />
  11. <meta name="LASTUPDATED" content="04/29/03 15:35:31" />
  12. <title>Directory Server Help: Encryption Tab</title>
  13. <!--The following is a javascript which determines whether the client
  14. is on a Windows machine, or is on another type of operating system. Once
  15. the operating system is determined, either a windows or other operating
  16. system cascading style sheet is used. -->
  17. <script type="text/JavaScript" src="/manual/en/slapd/help/sniffer.js">
  18. </script>
  19. </head>
  20. <body text="#000000" link="#006666" vlink="#006666" alink="#333366" bgcolor="#FFFFFF">
  21. <!--maincontent defines everything between the body tags -->
  22. <!--start maincontent-->
  23. <!--navigationcontent defines the top row of links and the banner -->
  24. <!--start navigationcontent-->
  25. <table border="0" cellspacing="0" cellpadding="0" width="100%">
  26. <tr>
  27. <td><table border="0" cellspacing="0" cellpadding="0">
  28. <tr>
  29. <td valign="bottom" width="67">
  30. </td>
  31. <td valign="middle">
  32. <span class="product">Directory Server</span>
  33. <span class="booktitle">Console Help</span>
  34. </td>
  35. </tr>
  36. </table>
  37. </td>
  38. </tr>
  39. <tr>
  40. <td>
  41. <hr size="1" noshade="noshade" />
  42. <span class="navigation">
  43. <!-- BEGIN DOC CONTROLLER --
  44. <a style="text-decoration: none; color:#006666" href="/manual/en/slapd/index.htm">
  45. DocHome
  46. </a>
  47. -- END DOC CONTROLLER -->
  48. </span>
  49. &nbsp;&nbsp;&nbsp;&nbsp;
  50. </td>
  51. </tr>
  52. </table>
  53. <!--end navigationcontent-->
  54. <!--bookcontent defines the actual content of the file, sans headers and footers -->
  55. <!--start bookcontent-->
  56. <blockquote>
  57. <br />
  58. <p class="h1">
  59. <a name="25232"> </a>
  60. <a name="Encryption Tab"> </a>
  61. Encryption Tab
  62. </p>
  63. <p class="text">
  64. <a name="25233"> </a>
  65. Use this tab to configure SSL for your directory.
  66. </p>
  67. <p class="text">
  68. <a name="25234"> </a>
  69. <b>Enable SSL for this server.</b> Select this checkbox to enable SSL communications for the directory. Clear the checkbox to disable SSL.
  70. </p>
  71. <p class="text">
  72. <a name="25235"> </a>
  73. <b>Use this cipher family. </b>Select the checkbox next to the cipher family or families you want the server to use for SSL communications.
  74. </p>
  75. <p class="text">
  76. <a name="25236"> </a>
  77. <b>Security Device.</b> Select the device you want the server to use.
  78. </p>
  79. <p class="text">
  80. <a name="25237"> </a>
  81. <b>Certificate.</b> Select the certificate you want the server to use. You must have a certificate set up on your system to use SSL.
  82. </p>
  83. <p class="text">
  84. <a name="25238"> </a>
  85. <b>Cipher settings. </b>Opens the Encryption Preferences dialog box, where you can select which ciphers you want the server to use from the cipher families you have already selected. By default, Directory Server comes with the following SSL ciphers:
  86. </p>
  87. <br />
  88. <br/>
  89. <table width="90%" border="1" cellspacing="0" cellpadding="4">
  90. <tr>
  91. <td valign="top">
  92. <p class="tablehead">
  93. <a name="28449"> </a>
  94. SSL Cipher
  95. </p></td>
  96. <td valign="top">
  97. <p class="tablehead">
  98. <a name="28451"> </a>
  99. Description
  100. </p></td>
  101. </tr>
  102. <tr>
  103. <td valign="top">
  104. <p class="tabletext">
  105. <a name="27774"> </a>
  106. None
  107. </p></td>
  108. <td valign="top">
  109. <p class="tabletext">
  110. <a name="27776"> </a>
  111. No encryption, only MD5 message authentication (rsa_null_md5).
  112. </p></td>
  113. </tr>
  114. <tr>
  115. <td valign="top">
  116. <p class="tabletext">
  117. <a name="27778"> </a>
  118. RC4
  119. </p></td>
  120. <td valign="top">
  121. <p class="tabletext">
  122. <a name="27780"> </a>
  123. RC4 cipher with 128-bit encryption and MD5 message authentication (rsa_rc4_128_md5).
  124. </p></td>
  125. </tr>
  126. <tr>
  127. <td valign="top">
  128. <p class="tabletext">
  129. <a name="27782"> </a>
  130. RC4 (Export)
  131. </p></td>
  132. <td valign="top">
  133. <p class="tabletext">
  134. <a name="27784"> </a>
  135. RC4 cipher with 40-bit encryption and MD5 message authentication (rsa_rc4_40_md5).
  136. </p></td>
  137. </tr>
  138. <tr>
  139. <td valign="top">
  140. <p class="tabletext">
  141. <a name="27786"> </a>
  142. RC2 (Export)
  143. </p></td>
  144. <td valign="top">
  145. <p class="tabletext">
  146. <a name="27788"> </a>
  147. RC2 cipher with 40-bit encryption and MD5 message authentication (rsa_rc2_40_md5).
  148. </p></td>
  149. </tr>
  150. <tr>
  151. <td valign="top">
  152. <p class="tabletext">
  153. <a name="27790"> </a>
  154. DES
  155. </p></td>
  156. <td valign="top">
  157. <p class="tabletext">
  158. <a name="27792"> </a>
  159. DES with 56-bit encryption and SHA message authentication (rsa_des_sha).
  160. </p></td>
  161. </tr>
  162. <tr>
  163. <td valign="top">
  164. <p class="tabletext">
  165. <a name="27794"> </a>
  166. DES (FIPS)
  167. </p></td>
  168. <td valign="top">
  169. <p class="tabletext">
  170. <a name="27796"> </a>
  171. FIPS DES with 56-bit encryption and SHA message authentication. This cipher meets the FIPS 140-1 U.S. government standard for implementations of cryptographic modules (rsa_fips_des_sha).
  172. </p></td>
  173. </tr>
  174. <tr>
  175. <td valign="top">
  176. <p class="tabletext">
  177. <a name="27798"> </a>
  178. Triple-DES
  179. </p></td>
  180. <td valign="top">
  181. <p class="tabletext">
  182. <a name="27800"> </a>
  183. Triple DES with 168-bit encryption and SHA message authentication (rsa_3des_sha).
  184. </p></td>
  185. </tr>
  186. <tr>
  187. <td valign="top">
  188. <p class="tabletext">
  189. <a name="27802"> </a>
  190. Triple-DES (FIPS)
  191. </p></td>
  192. <td valign="top">
  193. <p class="tabletext">
  194. <a name="27804"> </a>
  195. FIPS Triple DES with 168-bit encryption and SHA message authentication. This cipher meets the FIPS 140-1 U.S. government standard for implementations of cryptographic modules. (rsa_fips_3des_sha)
  196. </p></td>
  197. </tr>
  198. </table>
  199. <br />
  200. <br />
  201. <p class="text">
  202. <a name="25239"> </a>
  203. <b>Do not allow client authentication.</b> Select this option if you want client applications to connect to the server using only simple authentication.
  204. </p>
  205. <p class="text">
  206. <a name="25240"> </a>
  207. <b>Allow client authentication.</b> Select this option if you want client applications to be able to connect to the server using either simple authentication or client authentication.
  208. </p>
  209. <p class="text">
  210. <a name="25241"> </a>
  211. If you are using certificate-based authentication with replication, then you must select either "Allow client authentication" or "Require client authentication" on the consumer server.
  212. </p>
  213. <p class="text">
  214. <a name="25242"> </a>
  215. <b>Require client authentication. </b>Select this option if you want client applications to connect to the server using client authentication only. If you select this option, simple authentication is not allowed.
  216. </p>
  217. <p class="text">
  218. <a name="14859"> </a>
  219. <b>Use SSL in Management Console.</b> Select this checkbox if you want the communication between the Management Console and the directory to be secured using SSL.
  220. </p>
  221. <p class="text">
  222. <a name="14866"> </a>
  223. If you use this option with client authentication, communication between the Management Console and the server will take place over a secure channel, but without client authentication.
  224. </p>
  225. <p class="text">
  226. <a name="28333"> </a>
  227. <b>Check hostname against name in certificate for outbound SSL connections. </b>Select this check box if you want an SSL-enabled Directory Server (with certificate based client authentication turned on) to verify authenticity of a request by matching the hostname against the value assigned to the Common Name (CN) attribute of the subject name in the certificate being presented.
  228. </p>
  229. <p class="text">
  230. <a name="28412"> </a>
  231. By default, this feature is disabled. If you enable it and if the hostname does not match the CN attribute of the certificate, appropriate error and audit messages are logged. For example, in a replicated environment, messages similar to these are logged in the supplier server's log files if it finds that the peer server's hostname doesn't match the name specified in its certificate:
  232. </p>
  233. <p class="text">
  234. <a name="28356"> </a>
  235. <code>[DATE] - SSL alert: ldap_sasl_bind("",LDAP_SASL_EXTERNAL) 81 (runtime error -12276 - Unable to communicate securely with peer: requested domain name does not match the server's certificate.)</code>
  236. </p>
  237. <p class="text">
  238. <a name="28357"> </a>
  239. <code>[DATE] NSMMReplicationPlugin - agmt="cn=to ultra60 client auth" (ultra60:1924): Replication bind with SSL client authentication failed: LDAP error 81 (Can't contact LDAP server)</code>
  240. </p>
  241. <p class="text">
  242. <a name="28361"> </a>
  243. It is recommended that you turn this attribute on to protect Directory Server's outbound SSL connections against a Man In The Middle (MITN) attack.
  244. </p>
  245. <!-- BEGIN DOC CONTROLLER --
  246. <p class="h2">
  247. <a name="20476"> </a>
  248. <a name="See also"> </a>
  249. See also
  250. </p>
  251. <p class="text">
  252. <a name="20477"> </a>
  253. <a href="../en/slapd/ag/ssl.htm">Managing SSL</a>
  254. -- END DOC CONTROLLER -->
  255. </p>
  256. </blockquote>
  257. <!--end bookcontent-->
  258. <!--footercontent defines the bottom navigation and the copyright. It also includes
  259. the revision date-->
  260. <!--start footercontent-->
  261. <br />
  262. <br />
  263. <span class="navigation">
  264. <!-- BEGIN DOC CONTROLLER --
  265. <a style="text-decoration: none; color:#006666" href="/manual/en/slapd/index.htm">
  266. DocHome
  267. </a>
  268. -- END DOC CONTROLLER -->
  269. </span>
  270. &nbsp;&nbsp;&nbsp;&nbsp;
  271. <hr noshade="noshade" size="1" />
  272. <!-- BEGIN COPYRIGHT BLOCK -->
  273. <p class="copy">
  274. Copyright (C) Sun Microsystems, Inc. Used by permission.<br>
  275. Copyright (C) 2005 Red Hat, Inc. All rights reserved.
  276. </p>
  277. <br>
  278. <p class="copy">
  279. This material may be distributed only subject to the terms and conditions set
  280. forth in the Open Publication License, V1.0 or later (the latest version is
  281. presently available at http://www.opencontent.org/openpub/).
  282. </p>
  283. <br>
  284. <p class="copy">
  285. Distribution of substantively modified versions of this document is prohibited
  286. without the explicit permission of the copyright holder.
  287. </p>
  288. <br>
  289. <p class="copy">
  290. Distribution of the work or derivative of the work in any standard (paper)
  291. book form for commercial purposes is prohibited unless prior permission
  292. is obtained from the copyright holder.
  293. </p>
  294. <!-- END COPYRIGHT BLOCK -->
  295. <br />
  296. <p class="update">Last Updated <b>March 31, 2005</b></p>
  297. <!--end footercontent-->
  298. <!--end maincontent-->
  299. </body>
  300. </html>