Re: enable LDAP-SSL without a root-CA

From: Joe Richards [MVP] (humorexpress@hotmail.com)
Date: 08/11/02


From: "Joe Richards [MVP]" <humorexpress@hotmail.com>
Date: Sun, 11 Aug 2002 17:33:30 -0400


Not sure dude, I wasn't overly involved with it. They wanted certs on the
DC's for secure SSL password changes from UNIX sources and we don't use MS
CA. They started looked looking long and hard for something and came up with
something from verisign. They came to me with and said it would be $1000+
per DC (we have almost 400 DC's) and would require ridiculously painful
installation instructions including sitting on the phone with verisign for
each one. I said we wouldn't do it, if they needed Certs for the DC's they
needed to set up an MS CA and and make everything automagic or don't bother,
I have enough headaches keeping the 250k users running normally let alone
bog the DC's down with a bunch of SSL traffic.

--
Joe Richards
www.joeware.net
---
"David Cross [MS]" <vaq130@hotmail.com> wrote in message
news:eS30gTMQCHA.2652@tkmsftngp10...
> That sounds ridiculous.  You need a cert that chains to a trusted root on
> both the server and the client.  The net-net is you need a root CA to
start
> the hierarchy, anything less would not be secure.
>
> --
>
>
> David B. Cross [MS]
>
> --
> This posting is provided "AS IS" with no warranties, and confers no
rights.
>
> http://support.microsoft.com
>
> "Joe Richards [MVP]" <humorexpress@hotmail.com> wrote in message
> news:evPZEsHQCHA.2664@tkmsftngp10...
> > Some folks in our security group started talking to verisign about this
> and
> > I believe they found a way but it was very costly because verisign had
to
> do
> > some very strange things to make this work.
> >
> > --
> > Joe Richards
> > www.joeware.net
> > ---
> >
> > "Igor Ybema" <i.ybema@civ.utwente.nl> wrote in message
> > news:airfdt$19e$1@netlx020.civ.utwente.nl...
> > > Is it possible to enable SSL over LDAP in windows 2000 without
> installing
> > a
> > > enterprise root-CA?
> > >
> > > According to MS-article Q247078 you need to install an Enterprise CA
and
> > > allow all domain controllers to receive a certificate automatically.
In
> > our
> > > test-environment this works. After that we can use LDAPS in this
> > > test-enviroment to update passwords, make accounts etc. Now we need to
> use
> > > LDAPS in our production environment but we still have to decide how
our
> > > CA-hierachy will look like. So we cant install a enterprise-CA yet and
> we
> > > can not wait for this. Is it somehow possible to use temporary self
> signed
> > > certificates to enable SSL over LDAP on one server?
> > >
> > > regards,
> > >
> > > Igor Ybema, University of Twente, Enschede, the Netherlands
> > >
> > >
> > >
> > >
> > >
> >
> >
>
>


Relevant Pages

  • Re: LDAP authentication security ?
    ... I'm actually a big fan of external SSL certs for DCs simply because they are ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... Actually we don't have any PKI so we will buy a commercial SSL ... Simple bind is the authentication mechanism in the LDAP V3 spec and is ...
    (microsoft.public.windows.server.security)
  • Re: [opensuse] Help with Certs for Cyrus IMAP and TLS
    ... Ok, I changed the certs permissions to read/write by root only, no others can read. ... I re-made the certs again using a different how-to, making sure they did not require a pass phrase, but that did not fix the problem either. ... One, I had to start cyrus in runlevel editor and second, my IMAP SSL was and is now broken. ...
    (SuSE)
  • ADAM & SSL (w/ 3rd Party)
    ... Has anyone been able to get ADAM working with SSL using a certificates ... issued from a 3rd party CA such as Verisign? ... Verisign tells us the created .CSR file does not contain required ... LDAP over SSL? ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD SSL, what impact?
    ... We use external certs with our DCs and it isn't that big of a deal. ... running with SSL LDAP using a self-signed cert we generated with selfssl.exe ... SSL LDAP traffic will naturally be a little slower than unencrypted traffic, ... If your app uses Microsoft's LDAP APIs, then you ...
    (microsoft.public.windows.server.active_directory)
  • Re: Muliple Websites on Mutliple IP address with certicles [SSL]
    ... As opposed to different domains altogether ... IE6 caching SSL information in the past, but only when using a different ... whichever connection was made first eg. SSL on port 443 running IIS, ... compared to my current setup of 3 certs for completely different hostnames. ...
    (microsoft.public.inetserver.iis.security)