Configure Certificate Directives for LDAP Use of TLS
An XCCDF Rule
Description
Ensure a copy of a trusted CA certificate has been placed in the file
/etc/pki/tls/CA/cacert.pem
. Configure LDAP to enforce TLS use and
to trust certificates signed by that CA. First, edit the file
/etc/nslcd.conf
, and add or correct either of the following lines:
tls_cacertdir /etc/pki/tls/CAor
tls_cacertfile /etc/pki/tls/CA/cacert.pemThen review the LDAP server and ensure TLS has been configured.
Rationale
The tls_cacertdir or tls_cacertfile directives are required when tls_checkpeer is configured (which is the default for openldap versions 2.1 and up). These directives define the path to the trust certificates signed by the site CA.
- ID
- xccdf_org.ssgproject.content_rule_ldap_client_tls_cacertpath
- Severity
- Medium
- References
- Updated