Read this whole guide offline with no ads, for a low price!
Click Here!
Use coupon code "certiguide" to save 20%!
(Expires 2004/12/31)

Need more practice? 300 additional Security+ questions!
Get It Here!

Custom Search







Table Of Contents  CertiGuide to Security+
 9  Chapter 2:  Communication Security (Domain 2.0; 20%)
      9  2.4  Directory

Previous Topic/Section
2.4  Directory
Previous Page
Pages in Current Topic/Section
1
Next Page
2.4.2  LDAP
Next Topic/Section

2.4.1  SSL/TLS

Secure Sockets Layer (SSL), and its more flexible successor, Transport Layer Security (TLS)222, described in RFC 2246223, are popular standards for encryption of Internet communications, which operate just above TCP/IP224. They were discussed in general in section 2.3.1.

SSL and TLS also have specific application in the area of directory services.

Information provided by directory services can include sensitive details about the enterprise and its network configuration – types of data that you wouldn’t want an attacker with a network packet sniffer to have. Therefore, many directory services can make use of encryption when sending data back and forth between directory service client and server.

If your directory service supports an encrypted communication path, use it. If you’re using vanilla LDAP, consider moving to LDAP over TLS, which provides such encryption.


 __________________

222. http://www.kegel.com/ssl

223. ftp://ftp.isi.edu/in-notes/rfc2246.txt

224. http://developer.netscape.com/docs/manuals/security/sslin/contents.htm

Previous Topic/Section
2.4  Directory
Previous Page
Pages in Current Topic/Section
1
Next Page
2.4.2  LDAP
Next Topic/Section

If you find CertiGuide.com useful, please consider making a small Paypal donation to help the site, using one of the buttons below. You can also donate a custom amount using the far right button (not less than $1 please, or PayPal gets most/all of your money!) In lieu of a larger donation, you may wish to consider buying an inexpensive PDF equivalent of the CertiGuide to Security+ from StudyExam4Less.com. (Use coupon code "certiguide" by December 31, 2004 to save 20%!) Thanks for your support!
Donate $2
Donate $5
Donate $10
Donate $20
Donate $30
Donate: $



Home - Table Of Contents - Contact Us

CertiGuide for Security+ (http://www.CertiGuide.com/secplus/) on CertiGuide.com
Version 1.0 - Version Date: November 15, 2004

Adapted with permission from a work created by Tcat Houser et al.
CertiGuide.com Version Copyright 2004 Charles M. Kozierok. All Rights Reserved.
Not responsible for any loss resulting from the use of this site.