How to get certificate from sun one directory server

I have installed sun one directory server 5.2. Now in order to connect to the server through ldap protocol i need certificate on the client side.
How to get the certificate from the sun one directory server...??
( Earlier i tried the same procedure with active directory .and i got the certificate successfully ...as well as ldap authentication..but don't know what to do with the sun one..???)
Any tips on this issue will be helpful
thank you

You didn't make mention of setting up ssl on the server side, so search these boards for openssl. Some nice person uploaded an nice example of how do use openssl to do this.
To get the ssl certs for the solaris-client ssl authentication ( tls:simple ) to work you will need to use netscape to connect to the ssl port to get the right format. There are comments in that same doc on how to do that.

Similar Messages

  • Migrating data from Sun ONE directory server into openLDAP

    Hi,
    I was to migrate the data from Sun ONE directory server into openldap. Has anybody done this or know about this. Can you please share the steps that needs to be done.
    NOTE: I have exported the data into LDIF file but when I run with ldapadd into the open ldap
    ldap_add: Invalid syntax (21)
    additional info: objectClass: value #1 invalid per syntax
    Are there specific schemas that i need. Where can I find them?
    Thanks

    Why would you want to migrate data into an OpenLDAP server ?Good Question, let me explain you my problem with Sun DS.
    No Question DS is the better product (even Red Hat realized this).
    Problem: DS is not a base Solaris 10 OS component, for patch support
    you need some additional plan, now sun marketing nightmare comes ;o)
    Every year service plans are changed (want a SJES or a DS or a DSEE ?)
    so use solaris with OpenLDAP, or linus with NSDS.
    Sun please give us a Solaris Core Component called LDAP Server (no need for trillions of entries).
    joe

  • How to encrypt password in Sun ONE directory server?

    Hi,
    I'm trying to perform an update to a password field in Sun ONE directory server using JNDI, but the stored password does not get encrypted by the directory server. I've searched the forum, and only found examples on how to do so for Active Directory. Please help.
    Thanks

    You didn't make mention of setting up ssl on the server side, so search these boards for openssl. Some nice person uploaded an nice example of how do use openssl to do this.
    To get the ssl certs for the solaris-client ssl authentication ( tls:simple ) to work you will need to use netscape to connect to the ssl port to get the right format. There are comments in that same doc on how to do that.

  • Migrate from Sun One Directory Server 5.1 to 5.2

    Greetings
    I am trying to run the script provided with the 5.2 release MigrateInstance5; I have installed the server and have followed the instructions to a tee. I keep getting the error, Unable to start the Sun One Directory Server, when I run the script, I am at my wits end as this is supposed to be the easy step, I have to go from 4.2 to 5.2 next.
    Please help.

    Hello,
    We upgraded our directory server version for several times.
    If you want a secure method.
    export your data.
    Copy your schema file to the new install path, modify the information related to the old version and server (also the last line containing db number : keep only lines about the schema entry, it's ACI, objectclasse and attributes) and restart your directory.
    Import your data. (you might use a script to clean your ldif file : empty attributes ...)
    For the upgrade from 4.2 to 5.2 you will have to work a little bit more on the schema file as you have two of them instead of one. but the idea is the same.
    edit your New schema file, keep only the following lines "
    dn: cn=schema
    objectClass: top
    objectClass: ldapSubentry
    objectClass: subschema
    cn: schema
    aci: ....
    aci: ....
    copy and paste your custom attributes and then objectclasses form the corresponding files.
    On the import phase, check that you are not using objectclasses whiche were modified or suppressed.
    I hope it was helpfull.

  • Help!! How to install and use Sun ONE Directory Server Resource Kit 5.2

    Hi ! Friend:
    I have some problem on install and use Sun ONE Directory Server Resource Kit 5.2, when I execute "java DSRK", afterwards something like this : com.iplanet.install.until.wbResource::gerstring:resource bundle"locale.resources.S1DSRKResource" not found appeared in the window ,that's why?
    Meanwhile ,can you give some data about it on how to use it ?
    Thank you !

    You should be aware of the following characteristics of your directory when using this tool:
    Size and number of entries.
    Directory structure and access permissions.
    Virtual attributes, class of service, and indexing.
    Usage, types of access, and access patterns.
    Post your error messages completely.
    Thanks
    --Britto                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   

  • The fastest way to extract the data from Sun One Directory Server 5.2

    I'm trying to figure out the best way to extract the whole contents of the Directory Tree of a Sun One DS 5.2. I assum that the best way is db2ldif but it takes about 17 min for about 1.5 GB size database, which seems quite a long time. Is there a faster way?

    Thanks,
    Actually the file I need should be readable - I need to parse it later on. But I think I just found the answer in the development kit. The utility is called dbscan and it works directly on the database files.
    Thanks again anyway,
    Ayelet

  • Install Sun ONE Directory Server 5,2 & how to use it for authenticate user

    Good afternoon, Excuse, are newbie in the scope I am learning and putting desire to him, this in my situation I am trying to install Sun ONE Directory Server 5,2 since I understand that this it is application LDAP for Solaris, ok I want to install it to authenticate user against the system, that is to say, to be able to acces the server entering with a created user from the data base of LDAP and make think user that his created in the system. But the documentation that I finds indicates the installation of Sun ONE Directory Server 5,2 but it not clearly about how to use it for authentication. Some one have any manual step by step of Sun ONE Directory Server 5,2 installation and how to make it for authentication systems users.
    I read the forum seeking for anwser and i get confuse
    Thanks for the help and sorry for any inconvenient
    Message was edited by:
    Aku_28
    Message was edited by:
    Aku_28

    I think that I found the Sun endorsed book locations for using LDAP accounts that don't use authentication besides "crypt". I now can use an account with a "ssha" password. It can be more than 8 characters long.
    Chapter 14 System Administration Guide: Naming and Directory Services
    Read page 201 which is the pam.conf file pam_ldap setups. I edited my "/etc/pam.conf" file to reflect this
    Chapter 7 Directory Server 5.2 2005Q4 - Administration Guide
    Read page 316-318 which has a graphical technique to specify password syntax. I set it up and then tried the password by running "su - brahms". It now requires a longer password than 8 characters and it is set up to use "ssha" for that UID entry "brahms".

  • How to migrate Sun One directory server to a new physical server install

    need help
    We have to move our existing installation of sun on directory server 5.2 to a new physical server.
    We have a new physical server with a new host name. I am trying to find an easiest way to take a snapshot of our existing server and put it on a new installation
    So will installing sun one directory server , its shows me two choices either to create a new instance or copy configuration from a existing server
    What do i choose and which is the fastest route to replicate my old server
    Thanks a bunch in advance
    Sganb

    Hi,
    I'm glad you're still using the old, glorious Sun One Directory Server 5.2, because it brings me back a lot of memories... But are you seriously talking of the 'plain' version, with no patches/hot fixes on top? If that's the case, you're using of a software that has been developed in 2004 and released in Jan 2005! Just for you to be aware, in the last *8* (eight) years a considerable number (in the magnitude of 10^3) of bugs, security problems and performance issues has been identified and fixed...
    However, to provide a better answer to your question, it would be important to understand the 'big picture' in terms of scenario and requirements:
    1) Is this a critical 24x7 service for which you need to perform an on-line migration or you have a 'maintenance window' during which the service may be switched off?
    2) Is the old server member of replication environment? If yes, how many masters/slaves do you have already? Shall the new server be part of this topology? What role shall it have?
    3) Would it be possible to make the the old server able to communicate with the new server?
    4) How big is the database that you've got to migrate? Do you have any requirement in terms of caches?
    5) Do you take backups on a regularly basis and have in place working (*tested*) backup/restore procedures?
    6) Is the new server conserving or changing the O.S. and architecture? [SPARC->SPARC, x86->x86, SPARC->x86, Solaris -> ? , 32 .vs. 64-bit? ]
    7) What are the steps you did to 'install' the software on the new server?
    Thanks,
    Marco
    P.S.: I don't wanna sound 'scaring' with all these questions, neither this should be intended as an 'hidden advertising' for Oracle Professional/Consulting Services, but the only way to not put in jeopardy your data is being aware of the risks, having the control of what's going on and ... possibly have a 'B' plan ;-)
    P.S.S.: My last suggestion is to consider a migration to a later release AS SOON AS POSSIBLE; the latest is ODSEE 11.1.1.7, which is available here:
    http://www.oracle.com/technetwork/middleware/downloads/oid-11g-161194.html
    and seems to work pretty well ;-)

  • How can I import Openldap schema into sun one directory server?

    Hello All
    I have a schema which was written for openldap, and I want to import this schema into sun directory server. I found that some attribute syntaxes, like "NumericString", are not exist in sun directory server and some attribute definitions are also different. For example, the "internationaliSDNNumber" in sun directory is defined in "IA5String" syntax, but it is "NumericString" in openldap. Is there any effect on querying data from two different ldap server? How can I solve this problem?
    Thank you!

    http://directory.fedora.redhat.com/wiki/Howto:OpenLDAP
    Migration
    GaryThanks! But after I use some of scripts in that page, I got
    "Unknown attribute syntax OID "1.3.6.1.4.1.1466.115.121.1.36"
    It seems those scripts only transform schema file format, not the gap between different type(attribute syntax). Is it possible to import or add new type(attribute syntax) in sun one directory server?
    Thanks.

  • How to create Roles along with Entitlements in Sun One Directory Server?

    i need to create roles in sun one directory server along with entitlements
    please help me in this regard

    Hi Logeshr,
    Is the issue with deploying the webjobsever resolved ? If yes, could you share the work around so that it can help others who has similar issues.
    Most possible causes for the issue could be Problems with  Problems with Parallel build using MSBuild  or
    HeatDirectory failure on TFS with MSBUILD error MSB4166: Child node “3” exited prematurely
    However, as you said it works fine in Visual studio , ensure your CI server has all of the latest updates to MS Build.  If you're not current, you'll get a build error when .targets file processes at the end of the  buildsequence. 
    Regards,
    Shirisha Paderu

  • Active Directory 2003 and Sun One Directory Server 5.2

    I just installed Sun One Directory Server 5.2 on a Linux machine. I want to configure LDAP on that machine so that it can be authenticated on Active Directory 2003. How do I go about doing this?

    Active Directory server is a "directory server" (and kerberos server.) If your linux client authenticates against Active Directory it doesn't have to involve the Sun Directory Server at all. You have several general approaches you could investigate:
    1. Linux client gets accounts and and authentication via LDAP from Active Directory
    If you use AD to handle unix LDAP authentication (opt 1) you may need to extend schema in AD to add the unix password field. I haven't tried it yet, but hope to.
    2. Linux client gets accounts from AD LDAP and authorization from AD Kerberos.
    There should be docs on support.microsoft.com on enabling kerberos support for non-Win clients.
    3. Linux client (with samba client installed, with winbind or pam_smb to support unix level services) gets accounts and authentication as a "Windows" client from Active directory "Windows server"
    Check the samba.org docn or forums- I think this is a pretty common solution.
    4. Linux client gets account information from Sun Directory server but uses kerberos (against active directory) for authentication.
    There should be docs on support.microsoft.com on enabling kerberos support for non-Win clients.
    5 Linux client gets account and authorization from Sun Directory server, which the sun Directory server configured to use Active Directory as a Kerberos server.
    Probably incredibly complex.

  • Domino R6 Sun ONE Directory Server 5.2 SSL Integration

    We are trying to integrate Lotus Domino R6 server with the third party Sun ONE Directory Server 5.2.
    We were successful in the integration without SSL.
    Next we are trying to enable SSL communication between the two. We have configured the Certificates on both the servers. We get the following error on the Directory server (access logs).
    [18/Jan/2005:16:57:14 +051800] conn=12903 op=-1 msgId=-1 - fd=161 slot=161 LDAPS
    connection from 172.xx.xx.xxx to 172.xx.x.xx
    [18/Jan/2005:16:57:14 +051800] conn=12903 op=-1 msgId=-1 - SSL error -8101 (Cert
    ificate type not approved for application.); unauthenticated client CN=sun-dwc.xxxxxxxx
    .com, OU=TCS, O=PGS, L=Bangalore, ST=Karnataka, C=IN; issuer CN=beTRUSTed M
    achine CA - RSA Implementation, OU=beTRUSTed CAs, O=beTRUSTed
    [18/Jan/2005:16:57:14 +051800] conn=12903 op=-1 msgId=-1 - closing - B1
    [18/Jan/2005:16:57:14 +051800] conn=12903 op=-1 msgId=-1 - closed.
    Can someone please help. Thanks.

    Hi
    We had the same exact problem.
    The thing is that Domino uses SASL to authenticate against the LDAP directory as soon as the option "make this domain available to notes client & internet authentication" is checked in directory assistance.
    A workaround is to disable client authentication on the encryption tab of the sun directory server, but this is not what we want.
    Did you find another solution ?
    Thanks
    Yann

  • Evaluation version of Sun One Directory Server 5.2

    Dear sirs,
    We downloaded the Sun One Directory Server 5.2 from the following site:
    http://wwws.sun.com/software/download/products/3ee79e69.html
    After studying the License Agreement I actually wonder how long this evaluation software stays operational? May I use this software for operational purposes after I required the necessary license?
    I look forward to reading your comments.
    With best regards,
    Fred

    The bits are the same.
    Definitely before you move to deploy Directory Server in production, you'll want to work out licensing and support with Sun.
    Mark

  • Urgent help on Sun One Directory server 5.1

    Hi All,
    Am trying to access sun one directory server using the JAVA api provided by the tool itself. Developed an application to access that server and perform several operation.
    When I try to unassign a user from a group, all the users from that group are getting unassigned. Can there me any scenario in which this can happen. The user(no an admin user) who is used to connect to the LDAP server has all privileges to do operations on that group. More over this issue is very inconsistent, we could notice only once in separate environment (once per environment) and there hence cannot
    be reproducible.
    Below is snippet which remove a user from a group.
    LDAPAttribute attr = new LDAPAttribute( "uniquemember", userEntryDN );
    LDAPModification ldapMod = new LDAPModification( LDAPModification.DELETE, attr );
    ldapConnection.modify( myEntryDN, ldapMod );
    Any help on will be greatful.
    Thanks in advance
    -Sri

    TTT

  • SSL on Sun One Directory Server

    I am trying to establish SSL connection with Sun One Directory Server 5.2. However, I am unable to establish connection to the server using Microsoft LDP tool if i specify secure port 636. Unsecure connection is established successfully.
    I followed the following steps to enable SSL/TLS on Sun One Server
    1. Generate certificate request
    2. Acquire SSL certificate from CA (used thawte site to obtain trial certificate by entering the certificate request)
    3. Imported certificate to server (server-cert)
    4. Trusting your Certificate Authority and all certificates it issues
    5. Enable SSL on server
    Do i require to add a client certificate to keytstore? From where should i obtain a client certificate? Please help.

    1. Try and make sure that the certificate is issued to the hostname. Similarly, connect from MS to DS using the DS's hostname, not IP.
    2. Import CA root test certificate from thwate on both the DS certstore, as well as MS LDAP client's keystore.
    3. If the purpose of certificates is only encryption, you may look at the client for an option to disable hostname verification.
    4. No client cert is needed, unless you have configured LDAP for certificate based authentication.
    Hope the above help.
    Ankush
    http://www.iamcg.net

Maybe you are looking for

  • Principal mapping across domains -help!

    Hi, I am trying to find a way to authenticate users on a WL6 domain and then have these users' principal object mapped across to a different domain so that I do not have to re-authenticate them (i.e. they are trustworthy). Does anyone know how this i

  • Photoshop CS4 ChangeColorSettings

    I am writing a VB script for Photoshop CS4 and I am trying to change the default color settings from within the script.  <br /><br />However it keeps failing with the following message:  "General Photoshop error occurred. This functionality may not b

  • After updating to iOs5 I'm having a lot of trouble with receiving and making phone calls

    After updating to iOs5 I'm not able anymore to receive and make normal phone calls. This is very frustrating: when somebody calls me they have signal but my iPhone 4 doesn't make any sound or anything and when I try to make a call I don't hear any si

  • IMac running abnormaly slow with Leopard - Intel, 2GHz, 2GB

    Hey All, I've been having an issue with my iMac recently.. I've had it for almost a year now, its been running great till about 3-4 months ago. I mainly do Graphic Design and Photography so the hardrive was pretty full(about 20GB left) I figured this

  • What phone will I get for a replacement iphone 5

    What phone will I get to replace my iphone 5 since they stopped making iphone 5