Google Mail Calendar Documents Reader Web more »
Recently Visited Groups | Help | Sign in
Google Groups Home
Message from discussion ADAM with ssl
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Follow-up To:
Add Cc | Add Follow-up to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers that you hear
 
Lee Flight  
View profile   Translate to Translated (View Original)
 More options 4 Oct 2004, 18:07
Newsgroups: microsoft.public.windows.server.active_directory
From: "Lee Flight" <l...@le.ac.uk-nospam>
Date: Mon, 4 Oct 2004 18:07:17 +0100
Local: Mon 4 Oct 2004 18:07
Subject: Re: ADAM with ssl
Here are some notes that might help, if not post back
what problem you are having.

Using a certificate with an ADAM instance

(1) on the ADAM server look in:

c:\documents and settings\All
Users\ApplicationData\Microsoft\Crypto\RSA\MachineKeys

and note what keys are there

(2) on the ADAM server request and install a server certificate
 for use by ADAM in the Computer Personal certificate store or
 the ADAM Instance personal certificate store (preferred)
 Use the MMC Certificates snap-in to install the certificate.

 The cert needs to be issued to the FQDN of the machine, and it
 should be issued for Server Authentication.

(3) on the ADAM server look in:

c:\documents and settings\All
Users\ApplicationData\Microsoft\Crypto\RSA\MachineKeys

and see what new key is there as a result of (2) and grant READ
permission on that key for the ADAM service account.

NOTE you need to set the permission on the key, the keys
in that folder do not inherit permissions

(4) install or restart an ADAM instance on the server

(5) On the ADAM server, run ldp.exe and Connect.

In the server field: put the name of the ADAM server as it appears
in the Issued To column of the Certificate MMC when you added the
certificate

In the Port Box put the port number for the ADAM instance
SSL and check the SSL box.

You should see an ldap_sslint connection initiate and
hopefully connect.

When you attempt to connect from a client other than
the ADAM server itself (localhost) the client should
specify the FQDN of the server that the server was
issued to and the client must trust the Certificate
Authority that issued the certificate.

If the connection fails check the event log for the ADAM instance,
the presence of Event Id: 1220

Description:
LDAP over Secure Sockets Layer (SSL) will be unavailable
at this time because the server was unable to obtain a certificate.

Indicates that the ADAM instance has not found a usable
certicifcate, this is often due to permissions not being set [see
step(3) above]

Lee Flight

"himanshu Khona" <himanshukh...@hotmail.com> wrote in message

news:2d2501c4aa31$8a5a0010$a301280a@phx.gbl...
> Anybody have any ideas how to configure ADAM with SSL?
> I found a small note in FAQ but that didn't help much.
> Himanshu


    Forward  
You must Sign in before you can post messages.
To post a message, you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2010 Google