Can anyone "Trust" Directory Server?

I've got a new Lion Server with a new Lion client. I've installed a signed certificate (from StartSSL) which I've validated is verifying correctly through the chain by running:
openssl s_client -connect server.example.net:636
... and getting a final response of:
Verify return code: 0 (ok)
This same certificate is properly encrypting iCal, Address Book, and Web with no special explicit trusting required.
On the client, when I use System Preferences -> Users & Groups to Join the Network Account Server, I get the following prompt:
This server provides SSL certificates. Do you want to trust the certificates from server.example.net?
You can continue without trusting certificates, which could allow unauthorized access to your computer.
WIth the choice of Don't Trust and Trust (default). If I choose Trust, it says "Getting Server Information..." and I get another dialog:
Unable to add server.
Connection failed to the directory server.
(2100)
If I choose Don't Trust, it works fine, but of course, I'm connecting over ldap 389 and not ldaps 636.
Anyone else having this problem with signed certificates? Is anyone having success with signed certificates?

Hi,
If you are going to use SSL for LDAP, you should create a dedicated cert.
You do NOT want to use your standard certificate that u use for all the other services like iCal etc etc.!
So create a dedicated sertificate wich will expire far in the future for example in 10 years or so.
Under the LDAP tab you want to Enable SSL and select your self-signed certificate.
Then go to the Policies tab. I have every single check-box CLEAR and not checked.
You can turn on Encrypt all Packets if you want, but I don’t use that because I have other services that I want to be able to use just standard LDAP and not LDAP over SSL
The reason for that is that some services don’t support LDAPS.
For sure you do not want the Enable authenticated directory binding option selected,
because that disables client-side binding to the directory.
I also keep Kerberos disabled, that gave me a lot of trouble setting it up correctly.
Once you've done all that you can continue to the client setup by manually copy the certificate from the server (You can find the certificate on your server in the /etc/certificates folder)
Hope this helps...
Martyin.

Similar Messages

  • Can't start Directory Server instance

    I just installed DSEE 6.2 and DSCC on a SPARC based Solaris 10 server. After following the Sun installation guide and accessing the DSCC panel, I tried to start a directory server instance. After entering all of the parameters, I cannot get the server instance started due to the following error.
    Could not contact the DSCC agent on ldap. Use the command cacaoadm to check that the DSCC agent is installed and running on port 11162.
    After this I verified the that cacaoadm was in fact running and operating on port 11162. I then tried changing the port numbers, and received the same error (although on a different port number). Can anyone advise me on a course of action to get this directory server up and running?
    Thanks

    Here is the dir listing:
    -rw------- 1 nobody nobody 0 Oct 28 20:37 import
    -rw------- 1 nobody nobody 16384 Oct 28 20:37 NetscapeRoot_uniquemember.db3
    -rw------- 1 nobody nobody 41 Oct 28 20:37 DBVERSION
    -rw------- 1 nobody nobody 16384 Oct 28 22:21 NetscapeRoot_uid.db3
    -rw------- 1 nobody nobody 16384 Oct 28 22:21 NetscapeRoot_sn.db3
    -rw------- 1 nobody nobody 16384 Oct 28 22:21 NetscapeRoot_givenName.db3
    -rw------- 1 nobody nobody 16384 Oct 31 09:55 NetscapeRoot_parentid.db3
    -rw------- 1 nobody nobody 16384 Oct 31 09:55 NetscapeRoot_objectclass.db3
    -rw------- 1 nobody nobody 16384 Oct 31 09:55 NetscapeRoot_numsubordinates.db3
    -rw------- 1 nobody nobody 90112 Oct 31 09:55 NetscapeRoot_nsuniqueid.db3
    -rw------- 1 nobody nobody 204800 Oct 31 09:55 NetscapeRoot_entrydn.db3
    -rw------- 1 nobody nobody 81920 Oct 31 09:55 NetscapeRoot_cn.db3
    -rw------- 1 nobody nobody 40960 Oct 31 09:55 NetscapeRoot_ancestorid.db3
    -rw------- 1 nobody nobody 16384 Oct 31 09:55 NetscapeRoot_aci.db3
    -rw------- 1 nobody nobody 942080 Oct 31 10:14 NetscapeRoot_id2entry.db3

  • Can anyone recommend some server monitoring software

    I am looking for some sort of software tool that will allow us to monitor the processor load similar to Activity Monitor but remotely. Server Monitor does not provided that particular function. Can anyone recommend one?
    Thanks
    X Serve   Mac OS X (10.4.2)  

    paul Rubino-
    Try this: http://www.apple.com/support/downloads/serveradmintools1
    Luck-
    -DaddyPaycheck

  • Where can I download Directory Server 5.1 service pack 1

    I found docs at: http://docs.iplanet.com/docs/manuals/directory/51sp1/relnotes_ds51sp1.html
    indicating that it is availible. I cannot find the page to download it.

    http://wwws.sun.com/software/download/download/5279.html
    -sanjay

  • How can I achieve high available solution for directory server

     

    You can start with deploying multi master replication which will give you 2 servers available for writes (and as many read-only consumers as you want).
    You can also install Directory Server in a Cluster (using Sun Cluster) which will provide more failover capabilities.
    If you combine both, you should be able to have almost no downtime.
    You can also use the Directory Proxy Server (aka iDAR) to provide transparent failover for client applications.
    I hope this help.
    Regards,
    Ludovic.

  • Integrating Sun Java Directory Server with Sun Java Application Server 7

    Hi,
    My basic goal is to implement Single Sign On within the network i,e if the user is inside the company's network and tries to access any application, then he should not be required for Username/password again becuase he is in the network.
    My question is Is this possible with Sun Java System DIrectory server. If yes how can we integrate Directory Server with Sun Java System Application Server 7 2004Q2.
    Please help.
    Thanks

    Directory Server in itself doesn't provide any kind of SSO functions. Basically it is a high performing data repository accessible via LDAP and DSML. It is, however, a key component used by SSO applications like Access Manager. If your applications are web applications then take a look at Access Manager for your SSO needs.
    Regards,
    Scott

  • Directory Server (partially installed) on ips60

    Hi I have followed the instruction "Configuring an Existing Remote Sun ONE Directory Server for Use With Sun ONE Portal Server" from "Sun ONE Portal Server Release Notes � March 2003" to install an exteral ids.
    I have done the patch by copying the cos-plugin.so to the appropriate directory from INSTALL_HOME/portal/ds_patch/113177-01/SUNWamds/root/var/opt/SU
    NWps/tmp/113177-01/.
    After restaring the directory server, I run the ./pssetup during the installation a message appearing as:
    Detected components:
    Directory Server (partially installed)
    Problems may result if partially installed components are used!
    Remove options:
    1) Remove Directory Server only
    2) Continue with install
    3) Exit
    Choice? [3]
    Is it supposed to show like this? And we ignore the problem and continue with Choice No.2?
    I am currently testing Portal to sit on iAS7 and also installed an external ids51p1. All on the same machine.
    Please advice

    Roger,
    I have confirmed that they have been combined into one package.
    The question now is how can I trick Directory Server 5.2 into thinking they have been installed?
    Thanks!
    Joshua Preston.
    Have you checked the Solaris 10 companion CDs? I
    looked at my JES2005Q1 distro and you're right, those
    packages are there for Sol 8 and 9, but not for 10.
    I checked a couple of our Sol10 machines and neither
    r had them.
    If they're not on the companion CDs, I'd open a case
    with tech support. This is a pretty serious
    oversight.
    HTH,
    Roger S.

  • Can anyone answer why in logic pro X I keep getting a window popping up that says Directory not found, result code= -120, followed by another window saying, Fade update failed, (error -120)?

    Can anyone answer, why in Logic Pro X I keep on getting a window popping up saying, Directory not found, result code = -120. Followed by another window saying, Fade update failed, (error -120)?
    I am running the latest version 10.0.5 through a Macbook Pro that has just been upgraded to 16GB Ram and a 960GB SSD which has made it as fast as ****. I upgraded because I was experiencing problems before and it was suggested that I didn't have enough Ram?
    I am using a Focusrite scarlett 2i4 and an Alesis Q61 midi controller. Weirdly, just trying to put a bass line down on a track using the Alesis, the bass sound goes out of tune with the track during recording only. This is very frustrating! I surely can't be the only one experiencing this?
    Many thanks
    Rob.

    Hi
    Time lost could be a problem, but.....
    Sadly, I don't think that there are any Apple docs relating to networked storgae issues with Logic. Other than a 'school' or 'business' setup, NAS/OD/AD setups are not usual circumstances for audio.
    If the issue is one of data backup & security, it may be enough to automatically backup the students local work folders to the NAS.
    If the issue is one of the Users being able to work from any Mac and pick up their files from the server, you are not likely to resolve this problem, without copying the files to the Local Mac.
    CCT

  • Can't start NT service for Directory Server using other acc. than LocalSys.

    Hi!
    I'm using Directory Server 5.1 on a Windows 2000 machine.
    I wrote a Plug-In for DS that needs Administrator Access to the NT Domain. So I tried to run the DS-Service as Administrator but the service can not start. I just keeps in status "starting...".
    I don't get any error message and the errorlog doesn't contain anything.
    Has anyone an idea?
    Thanks!
    Florian

    I forgot to tell one thing: I use SSL, without SSL I do not have this problem. Perhaps it's only the popup I get when starting DS, where I have to enter the certificate password?

  • Can't synchronize with Directory Server

    I am using IdM 8.0.0.1 and Sun Directory Server EE 6.3.
    I have created a server instance and suffix in DS and enabled Retro Changelog plug-in.
    In IdM I have created a LDAP resource for the DS. The synchronization policy uses the same base context as the suffix and the changenumber attribute.
    My problem is that when starting synchronization, IdM looks for changenumbers larger than the the last changenumber in the changelog suffix.
    If I create a user in IdM and assigns the DS resource, the user is created in DS. Changes to e.g. the name in DS is shown in IdM but a sync results in an error in the sync log: java.util.ArrayList cannot be cast to java.lang.String.
    I hope all this makes some sort of sense and even more, I hope someone can help me make this work.
    Thank you in advance.
    Stefan

    I don't see any references in the error, and I only changed the name attribute so I don't think that is the problem.
    I tried something else: I used Load from Resource to do the first import of users from DS to IdM. This worked as expected so now I have some users to play with. But when I create a new user in DS and starts a Sync, nothing happens. I would expect the new user to be sync'ed into IdM?
    And IdM still uses the last changenumber+1 as start point - This explains why nothing is sync'ed, but I don't understand why IdM behaves like that or where the start point comes from?
    If anyone can point me to a few tutorials on synchronization, I would appreciate it very much.
    Stefan

  • Lion Server: How can I enable directory listing for the Web Server?

    The functionality was part of the Server App in Lion Server but was not included in Lion.  Can anyone shed some light on how to enable Directory Listing.  Any help is appreciated!

    Go to /etc/apache2 and edit the file 000_any_80_.conf
    using sudo nano command and replace  "-Indexes" with "+Indexes".
    Restart Apache with "sudo apachecrl restart"
    Good luck,
    Ricky
    from Costa Rica

  • I don't know much about computers can anyone walk me through this ? How Do I Change The Software Update Server Address On A Client  ? what do I open and how do i put it in the right spot?

    I don't know much about computers can anyone walk me through this ? How Do I Change The Software Update Server Address On A Client  ? what do I open and how do i put it in the right spot?

    The simplest method is to run a defaults command on the client Macs (easily pushed via Apple Remote Desktop):
    defaults write com.apple.SoftwareUpdate CatalogURL 'HTTP_URL_FOR_CATALOG'
    for a user. If you run it via sudo it will set it for whenever you use softwareupdate as root.
    The HTTP_URL_FOR_CATALOG has been changed with Mac OS X 10.6.  If you use MCX it will automatically pick the new catalog – however if  doing it manually the following URLs need to be used for whichever  client version is in question:
    Mac OS X 10.4: http://mysus.example.com:8088/index.sucatalog
    Mac OS X 10.5: http://mysus.example.com:8088/index-leopard.merged-1.sucatalog.sucatalog
    Mac OS X 10.6: http://mysus.example.com:8088/index-leopard-snowleopard.merged-1.sucatalog
    Mac OS X 10.7: http://mysus.example.com:8088/index-lion-snowleopard-leopard.merged-1.sucatalog
    Mac OS X 10.8: index-mountainlion-lion-snowleopard-leopard.merged-1.sucatalog
    To double check this applied you can run the following command:
    /usr/libexec/PlistBuddy -c Print /Library/Preferences/com.apple.SoftwareUpdate.plist
    and /usr/libexec/PlistBuddy -c Print ~/Library/Preferences/com.apple.SoftwareUpdate.plist
    to see what settings are for the computer and user appropriately.
    If  this is working correctly when running Software Update (GUI) you should  see the server address appear in parenthesis in the title of the  window.
    MCX
    Another alternative is to use Workgroup  Manager to manage the preferences via MCX from your server. This can be  done for users, or for computers if they are bound to your Open Directory.
    If you are using 10.5 Server or newer: you can simply use the Software Update section under Preferences.
    Manually:
    Choose the accounts, computers, or groups to have the preference applied to.
    Click on Preferences, and then the Details tab
    Press the Add… button and navigate to /Library/Preferences/com.apple.SoftwareUpdate.plist
    Press Edit…
    Under Often, add a New Key and enter the name CatalogURL
    Make sure the type is string and then enter your SUS URL (eg. http://mysus.example.com:8088/index.sucatalog or if using 10.6: http://mysus.examle.com:8088/ – see above from the defaults section)
    Press  Apply Now, then Done. Once users/computers have refreshed their MCX  settings (usually the next login or restart) the new settings will take  over.
    If this is working correctly when running Software  Update (GUI) you should see the server address appear in parenthesis in  the title of the window.
    In order to have a system-wide configuration one has to run the following:
    sudo defaults write /Library/Preferences/com.apple.SoftwareUpdate CatalogURL "http://your.updates-server.lan:8088/index.sucatalog"
    In order to correctly work both on Leopard and Snow Leopard the right command to issue is:
    defaults write /Library/Preferences/com.apple.SoftwareUpdate CatalogURL "http://your.updates-server.lan:8088/index-leopard-snowleopard.merged-1.sucatalog"
    Happily used and tested on my network
    The DNS trick that Chealion points out is fantastic. I use it at our office, and every computer on our LAN  will automatically pull the updates from the local repository at high  speed without any configuration.
    Create the swscan.apple.com DNS zone on your internal DNS server, and have it resolve via an A record to your Mac
    Tags: automaticupdates mac clients macosx setting as default software update
    Category: Serverfault
    Share
    0
    0
    Google +
    0
    0
    0
    5
    You might also like:
    Can I Update My Jb 4s To 6.1.2 Without Restore? Tue. Jan 21st, 2014
    Iphone 4 Not Charging After Update To IOS6 
    IPad 2 Not Updating To IOS 5.1 
    How To Resolve The â€âunable To Install Update” Error For OTA IOS Updates? 
    What Is â€âSoftware Update” Doing When It Says â€âChecking For New Software”? 
    Advertisement
    Comment
    - See more at:  http://www.eonlinegratis.com/2013/how-do-i-change-the-software-update-server-add ress-on-a-client-mac-to-use-my-own-server/#sthash.YhHp5zWk.dpuf

  • TS3276 I cannot connect to my outgoing email server on my macBook pro, yet I can, for the same email account on my iPad. Also I can send emails from the other email account I have on my MacBook...really confused can anyone help?

    I cannot connect to my outgoing email server on my macBook pro, yet I can, for the same email account on my iPad. Also I can send emails from the other email account I have on my MacBook...really confused can anyone help?

    Sometimes deleting the account and then re-creating it can solve this issue
    Write down all the information in accounts before doing this
    Highlight the account on the left and click the minus button
    Then click the plus button to add the new account and follow the prompts

  • When I try and play music on my iPhone downloaded from iTunes it says 'this URL is not found on this server'. This does not happen when I play the same music through my iPad. Can anyone help?

    When I try to play music downloaded from itunes on my iPhone 4S it says 'this URL is not found on the server'. This does not happen when I play the same music on my iPad. The music plays fine. The message also comes up when I try and login to iTunes on my iMac. Can anyone help?

    I too am having the same issue as the OP.
    Your USER AGENT information is Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_2) AppleWebKit/600.3.18 (KHTML, like Gecko) Version/8.0.3 Safari/600.3.18
    Every webserver that receives a request from your browser is able to determine the HTTP USER AGENT information unless it has been removed by some software (e.g. firewall) before the request was trasmitted.

  • HT4623 I just got an ipad and I use att/yahoo for a server, it comes with free mcafee virus software, but my ipad says that it cant download it because of my upgrade to higher over 6.1.0 and I dont know what to do can anyone help me,want to have mcafee on

    I just got an Ipad and I really dont know much about them its a 32gb 4g wi-fi, I use at&t as my server(dsl) and that works fine but I need to download my mcafee which comes with my at&t for free but it wont let me download it says I need more than 6.1.0and I dont know what to do can anyone help, I know someone that has 1 just like mine but she doesnt use a antivirus and doesnt have any trouble but,,, I have a laptop and a desktop and I use mcafee on both,, so any suggestions, I just down know what to do,,, can anyone give me input on what to do, and I also what to know is there anyway I can use my portable device that I got thru at&t that I can buy minutes on, is there an adapter for this ipad that I can use this on,, help I need all I can get,, thanks chrystie

    You can not install it.
    Only apps from the official Apple App Store can be installed.

Maybe you are looking for

  • IMAC + Graphic Design

    Are any professional graphic designers using the new Imacs. I graduated earlier this year and have been thinking about getting a mac for a while now. My PC just crapped out about a week ago, so it is definitely time to buy a new comp. I know that get

  • Automatic Payment Run-f110 Reg

    Hi, I am not FICO Guy.But,I need to run the Automatic payment Run -F110. Can you please explain step by step procedure how to run the F110. Thanks in advance.

  • Differing Volume Levels-- Can't Find Answers

    I play my iPod and iTunes through my stereo at times. JVC 140 watt stereo. My volume control has a series of marks around it similar to a clock When I play a CD or vinyl record, the volume control for adequate sound is just a few notches above the "m

  • My Ipod Touch can't create a Playlist Folder in My Itunes

    Anyone managed to create Playlist folder in you Ipod Touch to combine all similar Genres into 1 folder? Now my I-Touch is already having huge playlist because I can't organize it. Please Help. Thanks.

  • HR_INFOTYPE_OPERATION - Running in Batch Mode

    I have an ABAP which reads data from a flat file into an internal table and then loops through this internal table and updates HR Infotype 15 records via the HR_INFOTYPE_OPERATION function.  In my program I give the user the option of running it in a