ldapclient and eDirectory

From: Algaeman (algaeman_at_nowhere.com)
Date: 12/23/03


Date: Tue, 23 Dec 2003 03:39:27 GMT

I've been trying to get the native ldapclient in Solaris9 to authenticate
against Novell eDirectory with TLS for some time now. I've gotten it to
work reasonably well, but still have one problem. For some reason, when
the ldap_cachemgr starts up, it tries to make an unecrypted connection to
the server to ask it for supportedSASLMechanisms. If it is unable to make
this first connection, it won't continue on and build the TLS proxy
connection to populate the cache. I also don't need it to make an attempt
to read the default profile from the directory. For security reasons, we
try to have all our LDAP servers accept only TLS encrypted sessions. Is
there any way to have the cachemgr skip the initial steps so I can get
these servers to work properly after a reboot?



Relevant Pages

  • RE: what will happen to outbound TLS connection if receivers cert has expired?
    ... Not all servers will fail if a certificate is invalid, this is dependant on their configuration. ... Turning off certificate validation would partially defeat the purpose of TLS. ... what will happen to outbound TLS connection if receiver's cert has expired? ...
    (microsoft.public.exchange2000.general)
  • Re: ldapclient and eDirectory
    ... > against Novell eDirectory with TLS for some time now. ... For some reason, when ... it tries to make an unecrypted connection to ... > try to have all our LDAP servers accept only TLS encrypted sessions. ...
    (comp.unix.solaris)
  • Re: ldapclient and eDirectory
    ... > against Novell eDirectory with TLS for some time now. ... For some reason, when ... it tries to make an unecrypted connection to ... > try to have all our LDAP servers accept only TLS encrypted sessions. ...
    (comp.sys.sun.admin)
  • Re: secure SMTP between backend Exchange servers
    ... you enable TLS on an SMTP virtual server, it will require TLS for every ... connection to it, effectively shutting off traffic from any hosts that don't ... You can enable TLS on a per-connector basis, ... servers in the same routing group don't communicate through a connector. ...
    (microsoft.public.exchange.misc)
  • Re: Should my PC be sending and receiving data onto/from the internet on its own?
    ... for this is that my anti-virus software (AVG free 7) has recently ... at my Internet connection status dialogue box, ... When you access a web page, you are not just accessing that server, but any servers that provide information to that page. ... Also, if the IP's are in the following ranges, you might have reason for concern: ...
    (comp.security.misc)