18.8 Using Clear Text or SSL Connections to the User LDAP Server

If you want to use LDAP without SSL encryption or if your LDAP server does not support SSL, select non-secure port.Non-secure is also a good choice if iFolder and LDAP are running on the same server. Because no communication or data is being transferred across network connections, no encryption is necessary. The default non-secure port is 389.

IMPORTANT:If you select non-secure port, the LDAP Group object must be marked to allow clear text passwords, using your LDAP server management tool.

Select secure port if you want to use SSL, which provides your network with encryption and security when data is transferred across network connections. SSL requires a Root Certificate.

If you select secure port, make sure you have previously copied the LDAP trusted root certificate (rootcert.der file) from your LDAP server to a directory on your iFolder server. For example, in NetWare, copy the file from LDAP server's sys:\public directory to an iFolder server’s sys:\public directory. If you use secure port, you must enter the path to the directory on your iFolder server where you copied the rootcert.der file. The default secure port is 636.

When you add a secure LDAP server to your iFolder system, the root certificate is copied into an attribute of the iFolderSettings class on the Global Settings LDAP.