Verify Server Certificate for SSL sessions | Select this option (cleared by default)
if you want the firewall to verify the certificate that the directory
server presents for SSL/TLS connections. The firewall verifies the
certificate in two respects: The certificate is trusted
and valid. For the firewall to trust the certificate, its root certificate
authority (CA) and any intermediate certificates must be in the
certificate store under . The certificate name must match the host Name of
the LDAP server. The firewall first checks the certificate attribute
Subject AltName for matching, then tries the attribute Subject DN.
If the certificate uses the FQDN of the directory server, you must
use the FQDN in the LDAP Server field for
the name matching to succeed.
If the verification
fails, the connection fails. To enable this verification, you must
also select Require SSL/TLS secured connection.
Enable the firewall to verify the server certificate
for SSL sessions to increase security.
|