You can use Web Administration Tool to configure a directory
server with the required security protocols to meet the security requirement
of your LDAP environment.
Before you begin
Create
the key database file and certificate for secure communications.
For more information, see the Key database, Certificate, and Certificate request
chapters in the GSKit tool
GSKCapiCmd user guide GSK_CapiCmd_UserGuide.
Set
the required permissions (rwx) on the key database
file, certificate, and file path for the directory server instance
owner.
Procedure
- Log in to Web Administration Tool as
the directory server administrator.
- In the navigation area, expand and click Settings.
- On the Settings panel, specify the
connections type, authentication method, and secure communication
protocols.
- To accept connections on a secure port and an unsecure
port, click SSL and TLS.
- To set the secure communication protocols, select the
required protocols.
- To enable the server and client authentication method,
click Server and client authentication.
- Click Apply.
- On Manage security properties, click Encryption.
- Select the required ciphers for the secure communication
protocols.
- Click Apply.
- On Manage security properties, click Key database.
- On the Key database panel, specify
the key database file and password.
- In the Key database path and file name field,
type the key database file name with the absolute path name.
- In the Key password field, type
the key database password.
- In the Confirm password field,
type the key database password.
- In the Key label field, type
the label that uniquely identifies the certificate.
- Click Apply.
- Click OK.
- In the navigation area, expand , and click Restart.
- Access the computer on which your directory server instance
is present.
- Log in as the instance owner.
- Restart the administration server.
ibmdiradm -I dsrdbm01 -k
ibmdiradm -I dsrdbm01