Interoperability with different versions of directory servers

You must identify the appropriate IBM® Verify Directory versions and settings that are interoperable in an LDAP environment.

IBM Verify Directory, Version 11.0.1 can interoperate with different versions of servers but depends on whether the support for NIST SP 800-131A is enabled or not.

Interoperability when support for NIST SP 800-131A transition is disabled

The following behaviors are observed, when you use IBM Verify Directory, Version 11.0.1 servers or clients without enabling the support for NIST SP 800-131A.

In a directory server environment
A IBM Verify Directory, Version 11.0.1 server that is configured for secure communications can interoperate with the IBM Verify Directory, version 6.3.0.15 or previous versions servers.
A IBM Verify Directory, Version 11.0.1 server that is configured for secure communications can be used with previous versions of secure servers in the following topologies:
  • Replication
  • Distributed directory
  • Pass-though authentication
A IBM Verify Directory, Version 11.0.1 server can interoperate with the different versions of client utilities and do not require any configuration changes.
In a client environment
You can use IBM Verify Directory, Version 11.0.1 client utilities with the different versions of servers without any configuration changes.

Support for NIST SP 800-131A transition is enabled

If IBM Verify Directory, Version 11.0.1 servers or client environment are configured to support transition to NIST SP 800-131A, the following responses are observed:

In a directory server environment
When you configure directory servers in a topology for secure communication, the following responses are observed:
Replication topology:
The replication fails if the supplier server is IBM Verify Directory, version 6.3.0.15 or earlier and the consumer server is IBM Verify Directory, version 6.3, Fix Pack 17 or later and is configured with one of the following settings:
  • The TLS 1.2 protocol.
  • The TLS 1.2 signature and hash algorithm restrictions.
  • Suite B mode.

If supplier and consumer servers are of IBM Verify Directory, version 6.3, Fix Pack 17 or later, the supplier server attempts to establish secure connection with the protocol and ciphers set on the consumer server. If the consumer server is configured with a key database file that contains EC public keys, the supplier server must contain a key database file with the EC public keys to establish secure connection. Otherwise, the supplier server might fail to establish a secure connection with the consumer server.

If TLS 1.2 signature and hash algorithm restrictions is configured in a replication topology, both the supplier server and consumer server must contain compatible keys, certificates, and signature and hash algorithm restriction. Otherwise, the supplier server might fail to establish a secure connection with the consumer server.

If Suite B mode is configured in a replication topology, all the servers in a replication topology must be configured with the same Suite B cryptographic security levels. Otherwise, the replication might fail.

Distributed directory:
The distributed directory setup fails if the proxy server is IBM Verify Directory, version 6.3.0.15 or earlier and the back-end server is IBM Verify Directory, version 6.3, Fix Pack 17 or later and is configured with one of the following settings:
  • The TLS 1.2 protocol.
  • The TLS 1.2 signature and hash algorithm restrictions.
  • Suite B mode.

If the proxy server and the back-end servers are of IBM Verify Directory, version 6.3, Fix Pack 17 or later, the proxy server attempts to establish secure connection with the protocol and ciphers set on the back-end server. If the back-end server is configured with a key database file that contains EC public keys, the proxy server must contain a key database file with the EC public keys to establish secure connection. Otherwise, the proxy server might fail to establish a secure connection with the back-end server.

If TLS 1.2 signature and hash algorithm restrictions is configured in a distributed directory setup, all servers must contain compatible keys, certificates, and signature and hash algorithm restriction. Otherwise, the proxy server might fail to establish a secure connection with the back-end server.

If Suite B mode is configured in a distributed directory setup, all the servers must be configured with the same Suite B cryptographic security levels. Otherwise, the servers might fail to establish a secure connection.

Pass-through authentication:
The pass-though authentication fails if the authenticating server is IBM Verify Directory, version 6.3.0.15 or earlier and the pass-through server is IBM Verify Directory, version 6.3, Fix Pack 17 or later and is configured with one of the following settings:
  • The TLS 1.2 protocol.
  • The TLS 1.2 signature and hash algorithm restrictions.
  • Suite B mode.

If the authenticating server and the pass-through server are of IBM Verify Directory, version 6.3, Fix Pack 17 or later, the authenticating server attempts to establish secure connection with the protocol and ciphers set on the pass-through server. If the pass-through server is configured with a key database file that contains EC public keys, the authenticating server must contain a key database file with the EC public keys to establish secure connection. Otherwise, the authenticating server might fail to establish a secure connection with the pass-through server.

If TLS 1.2 signature and hash algorithm restrictions is configured for pass-through authentication, all servers must contain compatible keys, certificates, and signature and hash algorithm restriction. Otherwise, the authenticating server might fail to establish a secure connection with the pass-through server.

If Suite B mode is configured for pass-through authentication, all the servers must be configured with the same Suite B cryptographic security levels. Otherwise, the servers might fail to establish a secure connection.

Server at IBM Verify Directory, version 6.3, Fix Pack 17 or later and previous versions of clients:
Secure communications between a directory server of 6.3.0.17 or later and client utilities of version 6.3.0.15 or earlier might fail, if you configure the server with:
  • The TLS 1.1 or TLS 1.2 protocol.
  • The TLS 1.2 signature and hash algorithm restrictions.
  • Suite B mode.
In a client environment
Secure communications between the client utilities and IBM Verify Directory, version 6.3.0.15 or earlier servers fail, if you configure the client environment with:
  • The TLS 1.1 or TLS 1.2 protocol.
  • The TLS 1.2 signature and hash algorithm restrictions.
  • Suite B mode.