Oracle Internet Directory Administrator's Guide Release 2.0.6 A77230-01 |
|
If you use Secure Sockets Layer (SSL), you may also configure strong authentication, data integrity, and data privacy. This section discusses these topics in the following sections:
A cipher suite is a set of authentication, encryption, and data integrity algorithms used for exchanging messages between network nodes. During an SSL handshake, the two nodes negotiate to see which cipher suite they will use when transmitting messages back and forth.
The Oracle Internet Directory supports the following SSL cipher suites:
Oracle Internet Directory clients can use SSL 2.0 or SSL 3.0. A client over SSL can connect to a server either anonymously or by using simple authentication.
When both a client and server authenticate themselves to each other, SSL derives the identity information it requires from the certificate.
During start-up of a directory server instance, the directory reads a set of configuration parameters, including the parameters for the SSL profile. If you are going to run the directory with SSL enabled, you need to examine--and possibly reconfigure--the SSL parameters in the configuration set entry.
To run a server instance in secure mode, modify the configuration settings to run with the secure port 636 as the default port.
See Also:
|
You can create and modify multiple sets of configuration parameters with differing values, using a different configuration set entry for each instance of Oracle Internet Directory. This is a useful way to accommodate clients with different security needs.
Oracle Corporation recommends that you create separate configuration sets and modify their SSL values, rather than modify SSL values in the default configuration set. This is because the default configuration set is the model from which all other configuration sets are drafted.
You can examine and modify the values for the SSL configuration parameters in each configuration set entry that you have created and in each server instance that is currently running.
To view and modify SSL configuration parameters:
You can change the parameters in this tab page and save them. The fields in this tab page are described in Table 5-2.
See Also:
"Managing Server Configuration Set Entries by Using Oracle Directory Manager" for information on changing parameters in a configuration set entry |
In this release, the replication server cannot communicate with SSL-enabled servers.
If you intend to support both SSL and non-SSL clients on the same host, you need to configure two distinct server instances.
|
![]() Copyright © 1999 Oracle Corporation. All Rights Reserved. |
|