summaryrefslogtreecommitdiff
path: root/docs/docbook/smbdotconf/ldap/ldapssl.xml
blob: d747d8f7df22319e692d6ec17df24a11544c40f4 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
<samba:parameter xmlns:samba="http://samba.org/common">
		<term><anchor id="LDAPSSL"/>ldap ssl (G)</term>
		<listitem><para>This option is used to define whether or not Samba should
		use SSL when connecting to the ldap server
		This is <emphasis>NOT</emphasis> related to
		Samba's previous SSL support which was enabled by specifying the 
		<command moreinfo="none">--with-ssl</command> option to the <filename moreinfo="none">configure</filename> 
		script.
		</para>
		
		<para>
		The <parameter moreinfo="none">ldap ssl</parameter> can be set to one of three values:
		</para>	
		<itemizedlist>
			<listitem><para><parameter moreinfo="none">Off</parameter> = Never use SSL when querying the directory.</para></listitem>

			<listitem><para><parameter moreinfo="none">Start_tls</parameter> = Use the LDAPv3 StartTLS extended operation 
			(RFC2830) for communicating with the directory server.</para></listitem>
	    
			<listitem><para><parameter moreinfo="none">On</parameter>  =
			Use SSL on the ldaps port when contacting the 
			<parameter moreinfo="none">ldap	server</parameter>.  Only
			available when the backwards-compatiblity <command moreinfo="none">
			--with-ldapsam</command> option is specified
			to configure.  See <link linkend="PASSDBBACKEND"><parameter moreinfo="none">passdb backend</parameter></link></para></listitem>
		</itemizedlist>		
		
		<para>Default : <command moreinfo="none">ldap ssl = start_tls</command></para>
		</listitem>
		</samba:parameter>