Prerequisites:
Before enabling SSL, perform the following steps to confirm LDAP over SSL is working in the AD server:
In the Start menu, select Run.
Type
ldp.exeand press ENTER.You see a new window named Ldp.
Click Connection.
The Connect pop-up opens.
Enter the Fully Qualified Domain Name (FQDN) of the AD server used to generate the certificate in the Server field.
Note
If you enable SSL and use a third-party SSL certificate (for example, Verisign, Thawte, etc.), you must provide the same Fully Qualified Domain Name (FQDN) or IP address that is provided in the SSL certificate.
Select SSL. Confirm that the Port is 636, and then click OK.
Steps:
Select Manager → <Admin Domain Name> → Setup → GUI Access → LDAP Authentication.
Click
.The Add an LDAP Server page is displayed.
Update the following fields to complete adding a new LDAP server:
Option
Definition
Enable LDAP Authentication?
Select Yes to continue adding the LDAP server.
Enable SSL?
Select the checkbox to enable SSL encryption.
Tip
You have to import the LDAP server’s SSL certificate into the Manager keystore for authentication. To import the SSL certificate, see Import certificate.
LDAP Server Name or IP Address
Type the LDAP server IPv4 or IPv6 address.
Caution
Only use a valid server name, since Trellix IPS does not check to see if the names are valid. A valid server name is the name of the host on which LDAP server is configured.
Server Port
Type the port number between 0 and 65535. Default port is 636.
Test Connection
(Optional) Click to verify that the Manager can connect to the LDAP server.
Save
Click to save the changes.
Cancel
Click to cancel the changes and exit.