Visit Our UNIX and Linux User Community


AIX LDAP client authenticate against Linux Openldap server over TLS/SSL


 
Thread Tools Search this Thread
Operating Systems AIX AIX LDAP client authenticate against Linux Openldap server over TLS/SSL
# 1  
Old 10-26-2015
AIX LDAP client authenticate against Linux Openldap server over TLS/SSL

Hi folks,

How can i configure an AIX LDAP client to authenticate against an Linux Openldap server over TLS/SSL?

It works like a charm without TLS/SSL.

i would like to have SSL encrypted communication for ldap (secldapclntd) and ldapsearch etc. while accepting every kind of certificate/CA.

Thanks in advance.
# 2  
Old 10-26-2015
What exactly the problem is? I neved did it with OpenLDAP, but did it with IBM Tivoli Directory Server and don't remember any problems with SSL.

On AIX side you must install crypto packages for LDAP and GSKit. Then you create a key file:
Code:
gsk7cmd -keydb -create -db /path/to/key.kdb -pw SOMEPASSWORD

and add your server certificate to the file:
Code:
gsk7cmd -cert -add -db /path/to/key.kdb -pw SOMEPASSWORD -label CertName -file /path/to/certificate.der -format binary

# 3  
Old 10-26-2015
There are also extra filesets (client) if I recall correctly - for the SSL support.
No time to look into this this week - but if a hard answer stays outstanding I shall research in more detail.

Which client version, e.g., 6.2, 6.3, 6.3.1?
# 4  
Old 10-26-2015
From my Openldap server (Suse12) I have generated 3 files (.key, .csr, .crt.) with openssl command, files that i copy to the linux clients side. Then, i just need configure the /etc/ldap.conf file. No more.

Can i use the same 3 files from my OpenLDAP server (.key, .csr, .crt.) and put them on the AIX clients side?

---------- Post updated at 05:51 PM ---------- Previous update was at 04:51 PM ----------

Hi MichaelFelt,

oslevel of my AIX clients:
7100-03-04-1441

Like says agent.kgb, the filesets are:
Code:
idsldap.clt_max_crypto32bit62.rte
idsldap.clt_max_crypto64bit62.rte

GSKit8.gskcrypt32.ppc.rte
GSKit8.gskcrypt64.ppc.rte
GSKit8.gskssl32.ppc.rte
GSKit8.gskssl64.ppc.rte

Moderator's Comments:
Mod Comment Please use CODE tags when displaying sample input, sample output, and code segments.

Last edited by Don Cragun; 10-26-2015 at 11:23 PM.. Reason: Add CODE tags.
# 5  
Old 10-27-2015
Read this article about GSKit - Managing certificates with IBM GSKit

You have to convert your OpenSSL certificate to some format, which GSKit understands.

Code:
openssl pkcs12 -export -in host.mycompany.com.crt -inkey host.mycompany.com.key -out host.mycompany.com.p12 -name "CA signed"


gsk8capicmd -cert -import -db host.mycompany.com.p12 -pw abc -target server.kdb

# 6  
Old 10-27-2015
The final command after creating the key.db and importing the ldap-server certificate should be:
Code:
mksecldap -c \
          -h <ldap-server>,<ldap-server-backup> \
          -a <admin-dn> \
          -p <admin-password> \
          -d <base-dn> \
          -M OS \
          -D LDAP \
          -A ldap_auth \
          -n 636 \
          -k </path/to/key.kdb> \
          -w <SOMEPASSWRD>

Regards
# 7  
Old 10-29-2015
I worked on a set of scripts to automate, read simplify, the installation of idsldap63 (i.e., version 6.3, NOT 6.3.1) filesets.

I never tested them with idsldap version 6.2 but I expect they should work.

FYI: version 6.3.0.X is the version that was supplied with AIX 7.1 on the initial expansion disk. About two years ago idsldap was moved to the IBM Security group (from Tivoli) and they started a new numbering scheme, and naming scheme. I was not able to get my scripts to work with the "Try and Buy" version they posted - then.

Anyway, if you want to look at my scripts you wil need to "install" them. They include some scripts for generating keys for a client (as well as for a server).

See idsldap - AIXTOOLS for more info.

Not promising anything - but I hope it helps!

Previous Thread | Next Thread
Test Your Knowledge in Computers #428
Difficulty: Medium
JavaScript supports regular expressions in a manner similar to Perl.
True or False?

9 More Discussions You Might Find Interesting

1. Solaris

LDAP Client not connecting to LDAP server

I have very limited knowledge on LDAP configuration and have been trying fix one issue, but unsuccessful. The server, I am working on, is Solaris-10 zone. sudoers is configured on LDAP (its not on local server). I have access to login directly on server with root, but somehow sudo is not working... (9 Replies)
Discussion started by: solaris_1977
9 Replies

2. AIX

How to integrate AIX Client LPAR to make use of existing MS AD LDAP ?

Hi All, Its regarding the LDAP in AIX. we already have Microsoft Active Directory (LDAP) Server. And would like to integrate My client AIX LPAR to this LDAP server. So' that we can directly use Active directory crdentials to login. (instead of creating USERs on AIX) from my AIX LPAR. ... (4 Replies)
Discussion started by: System Admin 77
4 Replies

3. AIX

AIX 5.2 ldap client AD

I have been able to configure on an AIX 5.2 ldap.cfg so service starts correctly. but when I try to log on with a windows user after entering the password login hangs and get no response. I have set it up on Aix 5.3 with no problem but in Aix 5.2 I have not been able to log in. ldap.cfg... (1 Reply)
Discussion started by: laxtnog
1 Replies

4. UNIX for Advanced & Expert Users

SSL/TLS with openldap

Hello to all, I'm beguinner in Linux instalations and I'm trying to Communicate from Web Sites that i have running under apache with openLDAP for users authentication using SSL mediation that seems to be connected with LDAPS. Can someone advise me how to do this, I have already installed... (1 Reply)
Discussion started by: CPMarco
1 Replies

5. IP Networking

Linux Client To Authenticate using TACACS

I have customer who controls access to the internet via TACACS server, basically a PIX firewall uses authentication from the TACACS to say if traffic is allowed to pass out of the gateway. I can't find anything on how to configure a linux client of TACACS authentication only how to set up a linux... (1 Reply)
Discussion started by: metallica1973
1 Replies

6. UNIX for Advanced & Expert Users

ldap over tls -- ssl cert help

Hey Guys, I am trying to setup ldap over tls in our lab. I am generating a self signed cert on the ldap server and importing that into the ldap system so it will use ldap over port 636. The clients will be a mix of solaris and redhat. I am lost on what I need to do on the client side to get... (0 Replies)
Discussion started by: s ladd
0 Replies

7. UNIX for Dummies Questions & Answers

TLS/SSL Openldap Centos 5.5

hi guys I configured my openldap but now I want to implement SSL-TLS This is my basic slapd.conf configuration include /etc/openldap/schema/core.schema include /etc/openldap/schema/cosine.schema include /etc/openldap/schema/inetorgperson.schema include ... (2 Replies)
Discussion started by: karlochacon
2 Replies

8. AIX

can not mount from aix client to linux nfs server

Hi, I am trying to mount a nfs folder from AIX client to Linux NFS Server, but I got the following error: # mount 128.127.11.121:/aix /to_be_del mount: 1831-010 server 128.127.11.121 not responding: RPC: 1832-018 Port mapper failure - RPC: 1832-008 Timed out mount: retrying... (1 Reply)
Discussion started by: victorcheung
1 Replies

9. UNIX for Dummies Questions & Answers

AIX v5.3 LDAP CLIENT and AD

Has anyone successfully authenticated unix users via Active Directory using LDAP client on AIX v5.2 or v5.3?? ldapsearch from our unix box retrieves info from AD but having trouble authenticating unix id when I logon - get a msg ': 3004-318 Error obtaining the user's password information'. Not... (0 Replies)
Discussion started by: DANNYC
0 Replies

Featured Tech Videos