cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
663
Views
0
Helpful
3
Replies

keepalive script ap-kal-ldap for secure LDAP

aajvandewiel
Level 1
Level 1

I tested the default ap-kal-ldap script with success towards our LDAP 3 servers on port 389. But I need another script for port 636 secure LDAP. Just changing the script to use port 636 doesn't seem to be the trick... I suppose the hex data needs to be altered, or do I need to install a client certificate on the CSS?

3 Replies 3

Gilles Dufour
Cisco Employee
Cisco Employee

unfortunately you will not find any script to do this. The CSS script language does not have the option to encrypt/decrypt data which is required for secure LDAP.

Gilles

Gilles, thanks for your answer. So no support for encrypt/decrypt on the CSS. What about changing the raw string to match the socket requests etc?

nope, because encryption/decryption mechanism are exactly there to prevent resending some raw data :-)

All you can do is check if the tcp port is responding to SYN.

Gilles.