Installation guide

SSL Support
11
Web server authentication (HTTP/HTTPS Basic Authentication), including public key infrastructure (PKI)
client certificates
2.1.9.1. Supported Versions of Active Directory
Active Directory authentication and LDAP authentication are supported on the following versions of Active
Directory:
Windows Server 2003
Windows Server 2003 R2
Windows Server 2008
Windows Server 2008 R2
2.1.9.2. Supported LDAP Directories
SGD supports version 3 of the standard LDAP protocol. You can use LDAP authentication with any LDAP
version 3-compliant directory server. However, SGD only supports the following directory servers:
Oracle Internet Directory 11gR1 (all 11.1.1.x.0 releases)
Oracle Directory Server Enterprise Edition version 11gR1
Microsoft Active Directory, as shown in Section 2.1.9.1, “Supported Versions of Active Directory”
Sun Directory Server 6.3 or later
Other directory servers might work, but are not supported.
Novell eDirectory is no longer supported as an LDAP directory server.
2.1.9.3. Supported Versions of SecurID
SGD works with versions 4, 5, 6, and 7 of RSA Authentication Manager (formerly known as ACE/Server).
SGD supports system-generated PINs and user-created PINs.
2.1.10. SSL Support
SGD supports TLS version 1.0 and SSL version 3.0.
SGD supports Privacy Enhanced Mail (PEM) Base 64-encoded X.509 certificates. These certificates have
the following structure:
-----BEGIN CERTIFICATE-----
...certificate...
-----END CERTIFICATE-----
SGD supports the Subject Alternative Name (subjectAltName) extension for SSL certificates. SGD also
supports the use of the * wildcard for the first part of the domain name, for example *.example.com.
SGD includes support for a number of Certificate Authorities (CAs). The /opt/tarantella/etc/data/
cacerts.txt file contains the X.500 Distinguished Names (DNs) and MD5 signatures of all the CA