<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSS Secure LDAP loadbalancing in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/css-secure-ldap-loadbalancing/m-p/1442240#M29972</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Finally got it working.&amp;nbsp; The config on the CSS is pretty straight forward. The problem was with certificates. I was generating my own certificates using openssl and therefore were not trusted on the client pc I was testing with.&amp;nbsp; All I did to get it working is adding the root certicate that I used to sign the ldap server certificate on the client machine.&lt;/P&gt;&lt;P&gt;It just worked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Useful links that might be related to what you I was&amp;nbsp; trying to accomplish:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cs.bham.ac.uk/~smp/projects/peap/"&gt;http://www.cs.bham.ac.uk/~smp/projects/peap/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 Jun 2010 00:21:02 GMT</pubDate>
    <dc:creator>amyskitchen</dc:creator>
    <dc:date>2010-06-23T00:21:02Z</dc:date>
    <item>
      <title>CSS Secure LDAP loadbalancing</title>
      <link>https://community.cisco.com/t5/application-networking/css-secure-ldap-loadbalancing/m-p/1442238#M29970</link>
      <description>&lt;P&gt;I have succesfully configure the CSS to load balance ldap request to 3 Windows AD servers. However, when adding SSL to the front end only it fails.&lt;/P&gt;&lt;P&gt;I'm assuming it has to do with the certificate requiring extended key usages. Has anyone done this before?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I create a certificate requests on the CSS requiring those ext? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas or help would be gretely appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Eric&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2010 22:08:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-secure-ldap-loadbalancing/m-p/1442238#M29970</guid>
      <dc:creator>amyskitchen</dc:creator>
      <dc:date>2010-06-17T22:08:51Z</dc:date>
    </item>
    <item>
      <title>Re: CSS Secure LDAP loadbalancing</title>
      <link>https://community.cisco.com/t5/application-networking/css-secure-ldap-loadbalancing/m-p/1442239#M29971</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just found myself in the same boat.&amp;nbsp; I got data going the the CSS fine but when I try to setup SSL on the front end (no backend SSL) I get nothing.&amp;nbsp; I'm sure it's just something minor I'm missing but having never been inside one of these CSS11500's until this project I am not sure what to focus my attention on as a likely suspect.&amp;nbsp; Appreciate any help that can be offered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Robbie&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jun 2010 19:16:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-secure-ldap-loadbalancing/m-p/1442239#M29971</guid>
      <dc:creator>Robbie Woodley</dc:creator>
      <dc:date>2010-06-18T19:16:42Z</dc:date>
    </item>
    <item>
      <title>Re: CSS Secure LDAP loadbalancing</title>
      <link>https://community.cisco.com/t5/application-networking/css-secure-ldap-loadbalancing/m-p/1442240#M29972</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Finally got it working.&amp;nbsp; The config on the CSS is pretty straight forward. The problem was with certificates. I was generating my own certificates using openssl and therefore were not trusted on the client pc I was testing with.&amp;nbsp; All I did to get it working is adding the root certicate that I used to sign the ldap server certificate on the client machine.&lt;/P&gt;&lt;P&gt;It just worked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Useful links that might be related to what you I was&amp;nbsp; trying to accomplish:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cs.bham.ac.uk/~smp/projects/peap/"&gt;http://www.cs.bham.ac.uk/~smp/projects/peap/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jun 2010 00:21:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-secure-ldap-loadbalancing/m-p/1442240#M29972</guid>
      <dc:creator>amyskitchen</dc:creator>
      <dc:date>2010-06-23T00:21:02Z</dc:date>
    </item>
    <item>
      <title>Re: CSS Secure LDAP loadbalancing</title>
      <link>https://community.cisco.com/t5/application-networking/css-secure-ldap-loadbalancing/m-p/1442241#M29973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Would you mind sharing your config with me?&amp;nbsp; Of course the confidential stuff removed.&amp;nbsp; You can contact me off-board.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jun 2010 16:36:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-secure-ldap-loadbalancing/m-p/1442241#M29973</guid>
      <dc:creator>Robbie Woodley</dc:creator>
      <dc:date>2010-06-28T16:36:29Z</dc:date>
    </item>
    <item>
      <title>Re: CSS Secure LDAP loadbalancing</title>
      <link>https://community.cisco.com/t5/application-networking/css-secure-ldap-loadbalancing/m-p/1442242#M29974</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Robbie,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Sorry for the delayed response. Here is the relevant config info. No backend SSL service yet, backend is still unencrypted, but at this point everything is on our data center not crossing any WAN or networks.&amp;nbsp; One thing to note is that my CSS is one armed, doing NAT as well so the load-balancing is considered full-proxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssl-proxy-list ssl_list1 &lt;BR /&gt;&amp;nbsp; ssl-server 2 &lt;BR /&gt;&amp;nbsp; ssl-server 2 dhparam mydhparam1 &lt;BR /&gt;&amp;nbsp; ssl-server 2 vip address 10.1.6.12 &lt;BR /&gt;&amp;nbsp; ssl-server 2 cipher dhe-rsa-with-3des-ede-cbc-sha 10.1.6.12 389 &lt;BR /&gt;&amp;nbsp; ssl-server 2 cipher dhe-rsa-with-des-cbc-sha 10.1.6.12 389 &lt;BR /&gt;&amp;nbsp; ssl-server 2 cipher rsa-with-3des-ede-cbc-sha 10.1.6.12 389 &lt;BR /&gt;&amp;nbsp; ssl-server 2 cipher rsa-with-des-cbc-sha 10.1.6.12 389 &lt;BR /&gt;&amp;nbsp; ssl-server 2 cipher rsa-with-rc4-128-sha 10.1.6.12 389 &lt;BR /&gt;&amp;nbsp; ssl-server 2 cipher rsa-with-rc4-128-md5 10.1.6.12 389 &lt;BR /&gt;&amp;nbsp; ssl-server 2 port 636 &lt;BR /&gt;&amp;nbsp; ssl-server 2 rsakey myrsakey1 &lt;BR /&gt;&amp;nbsp; ssl-server 2 rsacert ldapxCert &lt;BR /&gt;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;service LDAP1 &lt;BR /&gt;&amp;nbsp; ip address 10.1.1.4 &lt;BR /&gt;&amp;nbsp; keepalive port 389 &lt;BR /&gt;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp; keepalive type tcp &lt;BR /&gt;&amp;nbsp; port 389 &lt;BR /&gt;&amp;nbsp; active&lt;BR /&gt; &lt;BR /&gt;service LDAP2 &lt;BR /&gt;&amp;nbsp; ip address 10.10.6.5 &lt;BR /&gt;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp; keepalive type tcp &lt;BR /&gt;&amp;nbsp; port 389 &lt;BR /&gt;&amp;nbsp; keepalive port 389 &lt;BR /&gt;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service ssl_module1 &lt;BR /&gt;&amp;nbsp; type ssl-accel &lt;BR /&gt;&amp;nbsp; add ssl-proxy-list ssl_list1 &lt;BR /&gt;&amp;nbsp; slot 2 &lt;BR /&gt;&amp;nbsp; keepalive type none &lt;BR /&gt;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; content LDAPSSLTest &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; vip address 10.1.6.12 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; add service ssl_module1 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; port 636 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;group LDAPGroup &lt;BR /&gt;&amp;nbsp; vip address 10.1.6.12 &lt;BR /&gt;&amp;nbsp; add destination service LDAP1 &lt;BR /&gt;&amp;nbsp; add destination service LDAP2 &lt;BR /&gt;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Eric&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jul 2010 19:25:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-secure-ldap-loadbalancing/m-p/1442242#M29974</guid>
      <dc:creator>amyskitchen</dc:creator>
      <dc:date>2010-07-06T19:25:03Z</dc:date>
    </item>
  </channel>
</rss>

