You must identify the appropriate IBM® Verify Directory versions
and settings that are interoperable in an LDAP environment.
IBM Verify Directory,
Version 11.0.1 can interoperate with different versions of servers but
depends on whether the support for NIST SP 800-131A is enabled or
not.
Interoperability when support for NIST SP 800-131A
transition is disabled
The following behaviors are observed,
when you use IBM Verify Directory,
Version 11.0.1 servers or clients without enabling the support for NIST
SP 800-131A.
- In a directory server environment
- A IBM Verify Directory,
Version 11.0.1 server that is configured for secure communications can
interoperate with the IBM Verify Directory,
version 6.3.0.15 or previous versions servers.
- A IBM Verify Directory,
Version 11.0.1 server that is configured for secure communications can
be used with previous versions of secure servers in the following
topologies:
- Replication
- Distributed directory
- Pass-though authentication
- A IBM Verify Directory,
Version 11.0.1 server can interoperate with the different versions of
client utilities and do not require any configuration changes.
- In a client environment
- You can use IBM Verify Directory,
Version 11.0.1 client utilities with the different versions of servers
without any configuration changes.
Support for NIST SP 800-131A transition is enabled
If IBM Verify Directory,
Version 11.0.1 servers or client environment are configured to support
transition to NIST SP 800-131A, the following responses are observed:
- In a directory server environment
- When you configure directory servers in a topology for secure
communication, the following responses are observed:
- Replication topology:
- The replication fails if the supplier server is IBM Verify Directory,
version 6.3.0.15 or earlier and the consumer server is IBM Verify Directory,
version 6.3, Fix Pack 17 or later and is configured with one of the
following settings:
- The
TLS 1.2 protocol.
- The
TLS 1.2 signature and hash algorithm restrictions.
- Suite B mode.
If supplier and consumer servers are of IBM Verify Directory,
version 6.3, Fix Pack 17 or later, the supplier server attempts to
establish secure connection with the protocol and ciphers set on the
consumer server. If the consumer server is configured with a key database
file that contains EC public keys, the supplier server must contain
a key database file with the EC public keys to establish
secure connection. Otherwise, the supplier server might fail to establish
a secure connection with the consumer server.
If TLS
1.2 signature and hash algorithm restrictions is configured
in a replication topology, both the supplier server and consumer server
must contain compatible keys, certificates, and signature and hash
algorithm restriction. Otherwise, the supplier server might fail to
establish a secure connection with the consumer server.
If Suite
B mode is configured in a replication topology, all the servers in
a replication topology must be configured with the same Suite B cryptographic
security levels. Otherwise, the replication might fail.
- Distributed directory:
- The distributed directory setup fails if the proxy server is IBM Verify Directory,
version 6.3.0.15 or earlier and the back-end server is IBM Verify Directory,
version 6.3, Fix Pack 17 or later and is configured with one of the
following settings:
- The
TLS 1.2 protocol.
- The
TLS 1.2 signature and hash algorithm restrictions.
- Suite B mode.
If the proxy server and the back-end servers are of IBM Verify Directory,
version 6.3, Fix Pack 17 or later, the proxy server attempts to establish
secure connection with the protocol and ciphers set on the back-end
server. If the back-end server is configured with a key database file
that contains EC public keys, the proxy server must
contain a key database file with the EC public keys
to establish secure connection. Otherwise, the proxy server might
fail to establish a secure connection with the back-end server.
If TLS
1.2 signature and hash algorithm restrictions is configured
in a distributed directory setup, all servers must contain compatible
keys, certificates, and signature and hash algorithm restriction.
Otherwise, the proxy server might fail to establish a secure connection
with the back-end server.
If Suite B mode is configured in a
distributed directory setup, all the servers must be configured with
the same Suite B cryptographic security levels. Otherwise, the servers
might fail to establish a secure connection.
- Pass-through authentication:
- The pass-though authentication fails if the authenticating server
is IBM Verify Directory,
version 6.3.0.15 or earlier and the pass-through server is IBM Verify Directory,
version 6.3, Fix Pack 17 or later and is configured with one of the
following settings:
- The
TLS 1.2 protocol.
- The
TLS 1.2 signature and hash algorithm restrictions.
- Suite B mode.
If the authenticating server and the pass-through server are
of IBM Verify Directory,
version 6.3, Fix Pack 17 or later, the authenticating server attempts
to establish secure connection with the protocol and ciphers set on
the pass-through server. If the pass-through server is configured
with a key database file that contains EC public
keys, the authenticating server must contain a key database file with
the EC public keys to establish secure connection.
Otherwise, the authenticating server might fail to establish a secure
connection with the pass-through server.
If TLS 1.2 signature
and hash algorithm restrictions is configured for pass-through authentication,
all servers must contain compatible keys, certificates, and signature
and hash algorithm restriction. Otherwise, the authenticating server
might fail to establish a secure connection with the pass-through
server.
If Suite B mode is configured for pass-through authentication,
all the servers must be configured with the same Suite B cryptographic
security levels. Otherwise, the servers might fail to establish a
secure connection.
- Server at IBM Verify Directory,
version 6.3, Fix Pack 17 or later and previous versions of clients:
- Secure communications between a directory server of 6.3.0.17 or
later and client utilities of version 6.3.0.15 or earlier might fail,
if you configure the server with:
- The
TLS 1.1 or TLS 1.2 protocol.
- The
TLS 1.2 signature and hash algorithm restrictions.
- Suite B mode.
- In a client environment
- Secure communications between the client utilities and IBM Verify Directory,
version 6.3.0.15 or earlier servers fail, if you configure the client
environment with:
- The
TLS 1.1 or TLS 1.2 protocol.
- The
TLS 1.2 signature and hash algorithm restrictions.
- Suite B mode.