IDP config for load balanced AD servers with SSL (LDAPS)

Yusuf Tran Yusuf.Tran at kaplan.com
Fri Jun 7 20:11:50 EDT 2013


Hi,

I have setup two Windows Server 2008 R2 servers as Domain Controllers, aswell as two IDPs and they are load balanced.

DCs are accessed via a virtual IP address, (configured on the F5 load balancer) and IDPs work just fine with this virtual address for both authentication and attributes on port 389 (regular LDAP)

I now wish to implement LDAP over SSL (LDAPS - port 636).

Could you advise on the best strategy for creating and implementing the certificate(s)? I've seen guides to do this for one server but not 2 load balanced servers.
I want to use a self-signed certificate and I understand that the certificate must have the fqdn of the server.

So the question is if I add each of the certificates to the IDPs using the java keytool, will this work correctly?

Will I need to do anything special like create a wildcard cert and try to use the same cert on both DC's?

I ask this as I had to do the same to get the IDPs and SPs to load balance properly, using the same private keys on each, but not sure how I would go about this on the DCs.

( Sorry for the long email )

Thanks

Yusuf

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130607/a685b0a6/attachment.html 


More information about the users mailing list