08-15-2022 08:28 PM
Hi all,
i have been tasked with converting our LDAP to LDAPs on our UCS'.
They are currently running 4.0(4l)
ive tried finding information online, but nothing concrete.
Am i right in thinking that in order to convert LDAP to LDAPs i will have to get an SSL cert created and do trusted points etc?
Currently we use the default keyring, regenerated every year.
Are they the same thing? or will i have to actually get the UCS using proper SSL certs in order to get LDAPs working?
any help is appreciated, and if you need anymore information then i will be happy to supply!
Thank you
08-16-2022 05:36 AM
See the docs:
Search for:
Enable SSL check box
That doc should get you what you're asking.
My understanding is Trusted Points are for intermediate and/or root certificates for the HTTPS certificate on UCSM.
The default keyring is for the HTTPS certificate on UCSM.
So these are both for TLS/HTTPS server on UCSM which is completely different then UCSM reaching out to a TLS'd/startTLS service on the external LDAP.
08-21-2022 07:12 PM
Hi Steven,
thanks for your reply, ive done a lot of reading, and it seems that if i check the enable SSL then i could get locked out. Won't it be looking for a certificate from the UCS to our LDAPs?
When i go to make a new provider i don't get asked for any certs or anything, is that normal? if i tick SSL on the existing providers, will i get locked out and have to use a local account to get in and disable SSL?
08-24-2022 05:23 PM
i have decided to do a proper SSL cert for the UCSM and go from there, does this have any affect on the KVM certificates?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide