XenMobile - Moving from LDAP to LDAPS
book
Article ID: CTX236710
calendar_today
Updated On:
Description
I am planning to turn on LDAPS on our XenMobile servers in the DMZ. We are being sure to open port 636 from our firewall to allow proper LDAPS traffic to flow. I understand there is one additional step to be performed prior to making the switch. I believe I need to export the root certificate from the AD DC and import it into the XenMobile server. We need to confirm this.
Instructions
Confirm the Steps Below to Make the Changes to use LDAPS with XenMobile
- First confirm that your AD DC is setup to accept LDAPS traffic on port 636 - Use Microsoft's guide for more information: https://blogs.msdn.microsoft.com/microsoftrservertigerteam/2017/04/10/step-by-step-guide-to-setup-ldaps-on-windows-server/
- Ensure port 636 can be accessed from the XenMobile nodes to your AD DC
- The root certificate needs to be exported from the AD Domain Controller
- The certificate must be in .PEM format and uploaded under XenMobile console's certificate page
- Modify LDAP settings on XenMobile to change ports from 389 to 636 and enable the "Use secure connection" option
- Note: if using a NetScaler as your gateway, make changes to your LDAP policy to reflect using LDAPS. This includes changing the port to 636 and also uploading the same root certificate from your AD DC to the NetScaler
Additional Information
XenMobile 9 - How to Setup LDAPS / Export Root Certificate from your DC -https://support.citrix.com/article/CTX202478
Netscaler LDAP(S) Policy Setup - https://support.citrix.com/article/CTX108876
Was this article helpful?
thumb_up
Yes
thumb_down
No