German

Testimonial

I was asked about Tools4ever for a reference the other day from a fellow school district technology coordinator. I had to stop and think about the program, it is called Automation. Our user account processing is totally automated. ‘Set it and forget it’, which apparently I did. I have used it for 5 years with no complaints. We moved from one Student Information System to a different one this year...

Michael Pruitt

Union County Kentucky

Kontakt

Rufen Sie uns an
+49 2202 2859-0

Stellen Sie Ihre Frage Termin für eine Online-Präsentation
Ihr Name: Ihre Frage:

Firmenname:
E-mail Adresse:
Telefonnummer:

Testimonial

UMRA has been such an asset within my environment. We are plagued daily with password reset requests within the classroom. Since the implementation of UMRA, we have been able to put the power of password resets in the hands of teachers, leaving the Network Department with more time to focus on more important administrative tasks.

Hayden Nurse

Bishop Anstey High School East Read more...

Previous Topic

Next Topic

Book Contents

Secure LDAP Active Directory environment

By default, the Microsoft LDAP implementation does not support secure LDAP. To setup secure LDAP using SSL, certificates must be installed on both sides, the LDAP Server and LDAP Client. In this case, the LDAP Server is the domain controller running Active Directory. The LDAP Client is the UMRA software, either the UMRA Console application or the UMRA Service.

  1. The certificates required to run secure LDAP using SSL can be configured in many ways. The concept is always the same:
  2. The Active Directory domain controller uses a special certificate that is issued by a trusted certification authority.
  3. The UMRA software (computer) trusts the certification authority that issues the certificate to the Active Directory domain controller.

Creating the certificate listed in step 1 requires a special procedure, as described in article Q321051. In this document, the same steps are used and described. Also, the procedure to setup a Certification Authority is described.

First, a certificate request is created. Next, a Certification Authority (CA) is setup and the certificate is signed, e.g. issued by the certification authority. Finally, the root certificate of the certification authority is exported and then imported by the computer that runs the UMRA software.

In this procedure the environment used runs Active Directory on Windows 2003 Standard Edition. For Windows 2000, a similar procedure can be used. The Certification Authority is installed on a Windows 2003 domain controller. For other versions, the procedure might be different.

In This Section

Creating an Active Directory domain controller certificate request

Creating a Certification Authority

Sign the certificate request by the Certification Authority

Exporting the root certificate Certification Authority

Importing the root certificate Certification Authority

Importing the LDAP Server certificate

Setting up the UMRA (LDAP Client) computer

Verifying secure LDAPS using SSL

See Also

Microsoft Active Directory

Introduction

Creating user accounts in Microsoft Active Directory using LDAP

Searching accounts and resetting passwords in Microsoft Active Directory using LDAP

Updating group memberships in Microsoft Active Directory using LDAP