Before you begin
Before enabling SSL, perform the following steps to confirm LDAP over SSL is working in the AD server:
- In the Start menu, select Run.
- Type
ldp.exe and press
ENTER.
You see a new window named Ldp.
- Click
Connection.
The Connect pop-up opens.
- Enter the Fully Qualified Domain Name (FQDN) of the AD server used to generate the certificate in the
Server field.
Note
If you enable SSL and use a third-party SSL certificate (for example, Verisign, Thawte, etc.), you must provide the same Fully Qualified Domain Name (FQDN) or IP address that is provided in the SSL certificate.
- Select SSL. Confirm that the Port is 636, and then click OK.
Task
- Select Manager → <Admin Domain Name> → Setup → GUI Access → LDAP Authentication.
-
Click
.
The Add an LDAP Server page is displayed. -
Update the following fields to complete adding a new LDAP server:
Option Definition Enable LDAP Authentication? Select Yes to continue adding the LDAP server. Enable SSL? Select the checkbox to enable SSL encryption. Tip
You have to import the LDAP server’s SSL certificate into the Manager keystore for authentication. To import the SSL certificate, see Import SSL certificate.
LDAP Server Name or IP Address Type the LDAP server IPv4 or IPv6 address. Caution
Only use a valid server name, since Trellix IPS does not check to see if the names are valid. A valid server name is the name of the host on which LDAP server is configured.
Server Port Type the port number between 0 and 65535. Default port is 636. Test Connection (Optional) Click to verify that the Manager can connect to the LDAP server. Save Click to save the changes. Cancel Click to cancel the changes and exit.