Configuring a directory server with protocols and ciphers by using Web Administration Tool

You can use Web Administration Tool to configure a directory server with the required security protocols to meet the security requirement of your LDAP environment.

Before you begin

Create the key database file and certificate for secure communications.

For more information, see the Key database, Certificate, and Certificate request chapters in the GSKit tool GSKCapiCmd user guide GSK_CapiCmd_UserGuide.

Set the required permissions (rwx) on the key database file, certificate, and file path for the directory server instance owner.

Procedure

  1. Log in to Web Administration Tool as the directory server administrator.
  2. In the navigation area, expand Server administration > Manage security properties and click Settings.
  3. On the Settings panel, specify the connections type, authentication method, and secure communication protocols.
    1. To accept connections on a secure port and an unsecure port, click SSL and TLS.
    2. To set the secure communication protocols, select the required protocols.
    3. To enable the server and client authentication method, click Server and client authentication.
    4. Click Apply.
  4. On Manage security properties, click Encryption.
    1. Select the required ciphers for the secure communication protocols.
    2. Click Apply.
  5. On Manage security properties, click Key database.
  6. On the Key database panel, specify the key database file and password.
    1. In the Key database path and file name field, type the key database file name with the absolute path name.
    2. In the Key password field, type the key database password.
    3. In the Confirm password field, type the key database password.
    4. In the Key label field, type the label that uniquely identifies the certificate.
    5. Click Apply.
  7. Click OK.
  8. In the navigation area, expand Server administration > Start/stop/restart server, and click Restart.
  9. Access the computer on which your directory server instance is present.
  10. Log in as the instance owner.
  11. Restart the administration server.
    ibmdiradm -I dsrdbm01 -k
    ibmdiradm -I dsrdbm01