[389-users] File Permissions

Paul Whitney paul.whitney at mac.com
Thu Aug 6 15:25:14 UTC 2015


I have a several openldap clients.  Certs are installed in /etc/openldap/cacerts.  I am using server certificates to to establish an SSL connection with the LDAP server.  Using PAM LDAP to authenticate users. I would like to test hardening these clients.

1.  What are the absolute minimum permissions required for the TLS CERT and TLS KEY?

2.  Can the TLS key have a password or must it always be without password?

Thanks,

Paul M. Whitney
E-mail: paul.whitney at mac.com
Sent from my browser.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.fedoraproject.org/pipermail/389-users/attachments/20150806/94cd59ad/attachment.html>


More information about the 389-users mailing list