Enabling Secure LDAP Connections


Exporting the Trusted Root

Although this procedure demonstrates how to perform the task in ConsoleOne, NetWare Administrator can accomplish the same task.

  1. In ConsoleOne, right-click the Security object at the [Root] of the tree and click New > Object.

  2. Click NDSPKI: Certificate Authority > OK, then follow the online instructions.

  3. Right-click the LDAP Server container, then click New > Object.

  4. Click NDSKPI: Key Material > OK, then follow the online instructions.

  5. Expand the LDAP Server container.

  6. Right-click the Key Material object you created for the SSL certificate, then click Refresh LDAP Server Now > Close.

  7. Export the self-assigned CA from NDS.

    1. Right click the Key Material Object.

    2. Select Properties.

    3. Select Public Key Certificates on the Certificates tab.

    4. Click Export.

  8. Install the self-assigned CA in all browsers that establish secure LDAP connections to NDS.


Importing the Trusted Root into the Browser


Importing the Trusted Root into Netscape Navigator

  1. Select File > Open Page.

  2. Select Choose File, and open the trusted root file that was previously exported.

    This launches the New Certificate Authority Wizard.

    The New Certificate Authority wizard does not launch if you do not have the correct file extension registered on your workstation. This is typically the case if you have installed Internet Explorer 5 and/or Windows NT service pack 4 or greater.

    1. To fix this problem, exit Navigator.

    2. Run the file X509.REG (located in <Install_dir>\NDS, where <Install_dir> is the directory name you selected when you installed NDS).

    3. Rename the trusted root certificate file you exported to .X509 extension.

    4. Import the certificate into Navigator.

  3. Follow the online prompts.

  4. Check Accept this Certificate Authority for Certifying Network Sites.


Importing the Trusted Root into Internet Explorer

  1. Select File > Open.

  2. To locate and select the trusted root file that was previously exported.

    This launches the New Site Certificate Wizard.

  3. Follow the online prompts.



Previous | Next