13.07.2015 Views

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Setting Up TLS SecurityNote – The security database files must be readable by everyone. Do not include anyprivate keys in the key3.db.If using TLS, the necessary security databases must be installed. In particular, thecertificate <strong>and</strong> key database files are needed. For example, if you adopt an olderdatabase format from Netscape Communicator, two files, cert7.db <strong>and</strong> key3.db,are required. Or if you use a new database format from Mozilla, three files, cert8.db,key3.db <strong>and</strong> secmod.db are needed. The cert7.db or cert8.db file containstrusted certificates. The key3.db file contains the client’s keys. Even if the <strong>LDAP</strong>naming service client does not use client keys, this file must be present. Thesecmod.db file contains the security modules such as PKCS#11 module. This file isnot required if the older format is used.Note – Before running ldapclient, you should set up <strong>and</strong> install the needed securitydatabase files described in this section.See the section about configuring <strong>LDAP</strong> clients to use SSL in the “Managing SSL”chapter of the Administrator’s Guide for the version of Sun Java System <strong>Directory</strong>Server you are using. For information on how to create <strong>and</strong> manage these files. Onceconfigured, these files must be stored in the location expected by the <strong>LDAP</strong> namingservices client. The attribute certificatePath is used to determine this location.This is by default /var/ldap.For example, after setting up the necessary cert7.db <strong>and</strong> key3.db files usingNetscape Communicator, copy the files to the default location.# cp $HOME/.netscape/cert7.db /var/ldap# cp $HOME/.netscape/key3.db /var/ldapNext, give everyone read access.# chmod 444 /var/ldap/cert7.db# chmod 444 /var/ldap/key3.dbNote – While Netscape manages the cert7.db <strong>and</strong> key3.db files in the$HOME/.netscape directory, Mozilla has its cert8.db, key3.db <strong>and</strong> secmod.dbfiles managed in a sub-direcotry under $HOME/.mozilla. Copies of these securitydatabases must be stored on a local file system if you are using them for an <strong>LDAP</strong>naming services client.Chapter 12 • Setting Up <strong>LDAP</strong> Clients (Tasks) 183

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!