ldap服务器与客户端配置TLS SSL认证
ldap监听389/tcp端口
ldaps监听636/tcp端口
创建CA证书
yum -y install openssl
cd /etc/pki/CA
ls private/
openssl req -new -x509 -key private/cakey.pem -out cacert.pem -days 3650 -subj “/C=CN/ST=BeiJing/L=BeiJing/O=bjums.cn/OU=edu/CN=ca.bjums.cn”
(创建十年的证书,这里如果只写到-subj之前会采用交互式创建)
touch index.txt
(黄建一个索引文件,如果之后给https做证书报错,重新创建索引文件即可)
echo “01” > serial
ldap服务器创建证书请求
cd /etc/openldap/certs/
(umask 077;openssl genrsa -out openldapkey135.pem 2048)
openssl req -new -key openldapkey135.pem -out openldap135.csr -days 3650 -subj “/C=CN/ST=BeiJing/L=BeiJing/O=bjums.cn/OU=edu/CN=192.168.153.135”
CA证书服务器签发证书
cd /etc/pki/CA/
openssl ca -in /etc/openldap/certs/openldap135.csr -out certs/openldapcert135.pem -days 3650
Using configuration from /etc/pki/tls/openssl.cnf
Check that the r