Add Directory Server screen details

A directory server is the physical or virtual machine that hosts the authentication directory service.

Screen component Description
IP address or host name

The IP address or host name of the server that hosts the authentication directory service. You must specify this information so that the appliance can access it.

Examples:

192.0.2.0

corpldap.example.com

Port

The LDAPS (LDAP over SSL) port to be used.

The appliance and the authentication directory service use LDAPS when communicating.

Data type:

Numeric characters

Default values:

636 (SSL)

3269 (SSL Global Catalog searches)

Specify certificate

Installing a certificate ensures integrity and authenticity between the appliance and the authentication directory service.

If you leave this check box unchecked, the appliance attempts to fetch the server certificate chain and trusts the topmost certificate (either root CA or intermediate CA) that it can reach.

Selecting this check box reveals the Directory server certificate field in which you can paste an X509 certificate that you copied from the directory service provider.


[NOTE: ]

NOTES:

  • The public key for the directory server certificate must be based on an RSA algorithm. Non-RSA based public keys are not supported.

  • If directory-server-host is a DNS server that uses a load balancing method, also referred to as round robin DNS, you will need to get the certificate for the server using its IP address.

    You can retrieve the IP address for a round robin DNS server with the nslookup command. For example, if the server is regionspecific.cpqcorp.net, retrieve its IP address with the command:

    nslookup regionspecific.cpqcorp.net




See also  

Add an authentication directory service