Michael StröderDate: Slide 1 Datei: /home/michael/Bizness/SURFnet/web2ldap_presentation_TF-LSD.sdd web2ldap Personal info Michael Ströder Freelancer Focus on PKI / LDAP Presentation of PKI features in
Michael StröderDate: Slide 2 Datei: /home/michael/Bizness/SURFnet/web2ldap_presentation_TF-LSD.sdd Overview Intro Features Limitations Enhancements Demo / Discussion
Michael StröderDate: Slide 3 Datei: /home/michael/Bizness/SURFnet/web2ldap_presentation_TF-LSD.sdd Intro Started in diploma thesis Simple search and download tool for certificates stored on LDAP server Add / modify entries
Michael StröderDate: Slide 4 Datei: /home/michael/Bizness/SURFnet/web2ldap_presentation_TF-LSD.sdd Features (1) Stand-alone or through CGI of web server on Unix and Windows Best viewed with any browser (CSS for formatting) Handling of NON-ASCII character sets
Michael StröderDate: Slide 5 Datei: /home/michael/Bizness/SURFnet/web2ldap_presentation_TF-LSD.sdd Features (2) Many output formats for exports (LDIF, vCard, DSML) Customization possible but reasonable defaults
Michael StröderDate: Slide 6 Datei: /home/michael/Bizness/SURFnet/web2ldap_presentation_TF-LSD.sdd Features (3) - PKI Many different standards for storing certificates in directory Directory server itself is not trustworthy 1 Display and handle certificates directly instead storing many certificate-related attributes
Michael StröderDate: Slide 7 Datei: /home/michael/Bizness/SURFnet/web2ldap_presentation_TF-LSD.sdd Limitations Uses python-ldap module built with OpenLDAP 1.2.x libs 1 limited to LDAPv2 WWW-Interface (stateless HTTP)
Michael StröderDate: Slide 8 Datei: /home/michael/Bizness/SURFnet/web2ldap_presentation_TF-LSD.sdd Road Map Web session managment (passwords, re-use LDAP connections) LDAPv3 (Referrals, Schema) Improve exports (DSML, vCard) Advanced Authentication Schemes (Kerberos, SASL)
Michael StröderDate: Slide 9 Datei: /home/michael/Bizness/SURFnet/web2ldap_presentation_TF-LSD.sdd Ideas Complete certificate validation DSML engine Windowing GUI with wxWindows (Windows and Unix)
Michael StröderDate: Slide 10 Datei: /home/michael/Bizness/SURFnet/web2ldap_presentation_TF-LSD.sdd Discussion Required features? Referrals, GUI Authentication Schemes (Kerberos, vs. SASL), Encryption (LDAPS vs. STARTTLS) Let's browse your favourite LDAP server! (preferrably with certs ;-)