In order to connect to the LDAP server over SSL (LDAPS) perform the following steps:
The default password for the JVM TrustStore is “changeit”, and you should change it to a new password:
Keytool -storepasswd -keystore /app/java/jre/lib/security/cacerts Enter keystore password: <old password> New keystore password: <new password> Re-enter new keystore password: <new password>
Import the LDAP / CA certificate to the JVM trustStore. You can either import a self signed certificate, or the CA certificate that signed the LDAP certificate.
Keytool -import -v -noprompt -trustcacerts -file <certificate file location > -keystore /app/java/jre/lib/security/cacerts -storepass <key store password>
- Make sure you use ldaps:// prefix and SSL ports in the LDAP configuration script properties file.