# Configuring ldap client, need cert

**URL:** <https://forums.suse.com/t/configuring-ldap-client-need-cert/22408>\
**Category:** SLES Networking\
**Created:** [March 23, 2012, 7:39pm UTC](https://forums.suse.com/t/configuring-ldap-client-need-cert/22408 "2012-03-23T19:39:04Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![toneyc](https://avatars.discourse-cdn.com/v4/letter/t/958977/32.png) [@toneyc](https://forums.suse.com/u/toneyc)\
**Post date:** [March 23, 2012, 7:39pm UTC](https://forums.suse.com/t/configuring-ldap-client-need-cert/22408/1 "2012-03-23T19:39:04Z")

</div>

I am configuring my first SLES11SP2 server today and the LDAP configuration has got me stopped in my tracks. There’s a new button on the “yast2 ldap” screen that is “Download CA Certificate” and a new section in the Advanced page that has a blank for Certificate Directory and CA Certificate File. How and where do I get the information needed for these? I really need more information about certificates in SLES in general if anyone has a link for documentation of same. I’m clueless when it comes to certs and how they are used and where they come from, etc.

Thanks,  
Toney.

---

<div class="post-metadata">

**Author:** ![malcolmlewis](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/malcolmlewis/32/11375_2.png) [@malcolmlewis](https://forums.suse.com/u/malcolmlewis)\
**Post date:** [March 23, 2012, 7:57pm UTC](https://forums.suse.com/t/configuring-ldap-client-need-cert/22408/2 "2012-03-23T19:57:08Z")

</div>

> [@toneyc](#):
>
> I am configuring my first SLES11SP2 server today and the LDAP  
> configuration has got me stopped in my tracks. There’s a new button on  
> the “yast2 ldap” screen that is “Download CA Certificate” and a new  
> section in the Advanced page that has a blank for Certificate Directory  
> and CA Certificate File. How and where do I get the information needed  
> for these? I really need more information about certificates in SLES in  
> general if anyone has a link for documentation of same. I’m clueless  
> when it comes to certs and how they are used and where they come from,  
> etc.
> 
> Thanks,  
> Toney.

Hi  
Your subject is confusing LDAP Client, or are you talking about a LDAP  
server?

If it’s a server, then all is normally done during the install (CA Root  
Certificate).

–  
Cheers Malcolm Â°Â¿Â° (Linux Counter #276890)  
SUSE Linux Enterprise Desktop 11 (x86\_64) Kernel 3.0.13-0.27-default  
up 1 day 3:54, 2 users, load average: 0.00, 0.01, 0.05  
CPU Intel i5 CPU M520@2.40GHz | Intel Arrandale GPU

---

<div class="post-metadata">

**Author:** ![toneyc](https://avatars.discourse-cdn.com/v4/letter/t/958977/32.png) [@toneyc](https://forums.suse.com/u/toneyc)\
**Post date:** [March 23, 2012, 9:16pm UTC](https://forums.suse.com/t/configuring-ldap-client-need-cert/22408/3 "2012-03-23T21:16:57Z")

</div>

[QUOTE=malcolmlewis;3485]Your subject is confusing LDAP Client, or are you talking about a LDAP  
server?[/QUOTE]

LDAP client.

-Toney.

---

<div class="post-metadata">

**Author:** ![malcolmlewis](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/malcolmlewis/32/11375_2.png) [@malcolmlewis](https://forums.suse.com/u/malcolmlewis)\
**Post date:** [March 23, 2012, 9:34pm UTC](https://forums.suse.com/t/configuring-ldap-client-need-cert/22408/4 "2012-03-23T21:34:13Z")

</div>

> [@toneyc](#):
>
> malcolmlewis;3485 Wrote:[color=blue]
> 
> > Your subject is confusing LDAP Client, or are you talking about a LDAP  
> > server?[/color]
> 
> LDAP client.
> 
> -Toney.

Hi  
Have a read here;  
[http://www.suse.com/documentation/sles11/singlehtml/book\_security/book\_security.html#sec.ldap.yast.client](http://www.suse.com/documentation/sles11/singlehtml/book_security/book_security.html#sec.ldap.yast.client)  
[http://www.suse.com/documentation/sles11/singlehtml/book\_security/book\_security.html#sec.ldap.yast.client.conf.basic](http://www.suse.com/documentation/sles11/singlehtml/book_security/book_security.html#sec.ldap.yast.client.conf.basic)

The certificates should come from the LDAP server your connecting to  
(if they are needed).

–  
Cheers Malcolm Â°Â¿Â° (Linux Counter #276890)  
SUSE Linux Enterprise Desktop 11 (x86\_64) Kernel 3.0.13-0.27-default  
up 1 day 5:32, 3 users, load average: 0.22, 0.11, 0.07  
CPU Intel i5 CPU M520@2.40GHz | Intel Arrandale GPU

---

<div class="post-metadata">

**Author:** ![toneyc](https://avatars.discourse-cdn.com/v4/letter/t/958977/32.png) [@toneyc](https://forums.suse.com/u/toneyc)\
**Post date:** [March 23, 2012, 10:17pm UTC](https://forums.suse.com/t/configuring-ldap-client-need-cert/22408/5 "2012-03-23T22:17:52Z")

</div>

Ok. I unchecked the TLS/SSL box and was able to continue. Thanks!

However… If I want to use SSL I’ll need the cert. I understand that they need to come from the LDAP server, but where? It asks for a “CA Certificate URL for Download”, what should that URL be? I’ve tried [http://LDAPServerName](http://LDAPServerName) and [https://LDAPServerName](https://LDAPServerName) but neither works.

Thanks,  
Toney.

---

<div class="post-metadata">

**Author:** ![toneyc](https://avatars.discourse-cdn.com/v4/letter/t/958977/32.png) [@toneyc](https://forums.suse.com/u/toneyc)\
**Post date:** [September 11, 2012, 9:02pm UTC](https://forums.suse.com/t/configuring-ldap-client-need-cert/22408/6 "2012-09-11T21:02:15Z")

</div>

The Internet is great. I was trying to get this fixed today and thought I would come here and post the question only to find that I already did it!

Specifically, I need more information on section 4.4.1.4.

😃  
Toney.

---

<div class="post-metadata">

**Author:** ![tkp](https://avatars.discourse-cdn.com/v4/letter/t/ed655f/32.png) [@tkp](https://forums.suse.com/u/tkp)\
**Post date:** [March 5, 2015, 3:23pm UTC](https://forums.suse.com/t/configuring-ldap-client-need-cert/22408/7 "2015-03-05T15:23:28Z")

</div>

I know it’s an old thread, but I have come across questions like this before. The first tab/page where you can click “Download CA Certificate” is used to retrieve a certificate that you have already exported and placed somewhere.  
Then, when you go into to the “Advanced Configuration”, you have 2 options…“Certificate Directory” and “CA Certificate file”. So the first allows you to choose a folder to store multiple Certificates (in a folder) the other allows you to select a specific issuing CA certificate for the connection…that’s how I understand it. So in any case, I would say, you need to export the certificate first, you can’t use the config tool to connect and then store the certificate locally.
