Re: AD SSL, what impact?



If you really only need to make SSL LDAP available to a limited number of
clients, you could just install a self-signed certificate. As long as you
can get the client to trust it (by installing the certificate in the
client's trusted roots store if it is using Windows Schannel for SSL
support), that will work. The selfssl tool that I mentioned can make quick
work of this.

You'll just have a deployment nightmare getting other clients to trust the
cert if you need broad deployment. That's the main advantage with getting a
cert from an issuer that everyone already trusts.

Joe K.

"GrimGrningGhost" <GrimGrningGhost@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message news:1B62F006-AC67-47EC-8D00-46898A8E816C@xxxxxxxxxxxxxxxx
I appreciate the replies. I suggested an ECA, but our structure makes such
a
thing technically fall under IT security which is a different management
branch than the server group. For whatever reason, they are dragging feet
on
the idea. The LDAP SSL queries would technically only flow from one
server
to another in the same rack across one switch secured in our computer room
(I
can't say much, but let me say that our computer room is extremely hard to
get access to by outsiders). So really, the packets aren't accessible and
so
I'd rather wait on security to approve/roll out the ECA. But I guess it's
my
bosses call. Thanks for the thoughts.


.



Relevant Pages

  • Re: Its me
    ... down systems because I market more upscale clients. ... If the average crook thinks someone has an alarm he will ... It cost money to install a system, ... Why wouldn't Bass, if he was so honest & caring, explain to his clients ...
    (alt.security.alarms)
  • Re: sbs 2003 Clients do not have internet access
    ... clients on your clients side, please make sure that firewall clients works ... If you did not install firewall clients on client side, ... |>This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • RE: word reports an error when trying to print
    ... Hopefully it will continue to work - after re-starts of clients and server ... I install the printer on the server - and then I share it.. ... please refer to the following Microsoft ... newsgroups so that they can be resolved in an efficient and timely manner. ...
    (microsoft.public.windows.server.sbs)
  • Re: Management Points
    ... > server which has been installed as a secondary site. ... > Advanced clients to their correct site, ... > "Proxy Management Point" being talked about but am a little confused. ... If so how do I install this proxy, ...
    (microsoft.public.sms.setup)
  • RE: word reports an error when trying to print
    ... I install the printer on the server - and then I share it.. ... On the clients - I can make a 'print test page' OK.. ... please refer to the following Microsoft ... newsgroups so that they can be resolved in an efficient and timely manner. ...
    (microsoft.public.windows.server.sbs)