IDP config for load balanced AD servers with SSL (LDAPS)
Yusuf Tran
Yusuf.Tran at kaplan.com
Fri Jun 7 20:11:50 EDT 2013
Hi,
I have setup two Windows Server 2008 R2 servers as Domain Controllers, aswell as two IDPs and they are load balanced.
DCs are accessed via a virtual IP address, (configured on the F5 load balancer) and IDPs work just fine with this virtual address for both authentication and attributes on port 389 (regular LDAP)
I now wish to implement LDAP over SSL (LDAPS - port 636).
Could you advise on the best strategy for creating and implementing the certificate(s)? I've seen guides to do this for one server but not 2 load balanced servers.
I want to use a self-signed certificate and I understand that the certificate must have the fqdn of the server.
So the question is if I add each of the certificates to the IDPs using the java keytool, will this work correctly?
Will I need to do anything special like create a wildcard cert and try to use the same cert on both DC's?
I ask this as I had to do the same to get the IDPs and SPs to load balance properly, using the same private keys on each, but not sure how I would go about this on the DCs.
( Sorry for the long email )
Thanks
Yusuf
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130607/a685b0a6/attachment.html
More information about the users
mailing list