ESP dSeries Workload Automation

 View Only

  • 1.  ESP dSeries workload automation with LDAP Integration[SSL Enabled] - Certificate Renewal of LDAP Server

    Posted May 23, 2025 01:26 PM

    Hi Team,

    We have configured CA Scheduler with LDAP integration [SSL Enabled].

    We have high availability of 4 AD/LDAP Servers, for each we have created separate Authentication system total of 5 authentication with one LB connection.

    Now we out of 4 servers for 2 LDAP Servers the certificate was renewed, so I can remove/delete the old certs and import the new renewed certs in keystore right?

    So, on next time when CA connect to either of these 2 servers authentication system whose certs renewed it will take work with new certs right? or do I have to consider any other steps?


    Your response is much appreciated, Thank you.



  • 2.  RE: ESP dSeries workload automation with LDAP Integration[SSL Enabled] - Certificate Renewal of LDAP Server

    Broadcom Employee
    Posted May 25, 2025 01:21 PM

    Hi Satish,

    Yes, you can remove and import new certs in keystore.  Then DE should be able to use SSL cert to talk to your LDAP.

    HTH,

    Nitin Pande



    ------------------------------
    Support
    Broadcom
    Toronto
    ------------------------------



  • 3.  RE: ESP dSeries workload automation with LDAP Integration[SSL Enabled] - Certificate Renewal of LDAP Server

    Posted Jun 17, 2025 07:11 AM

    Also Sathish,  Based on our experience we got suggestion from our LDAP team to use Domain name to establish connection instead of explicitly adding individual domain controllers as it'll be the functionality of the domain which re-directs connections to active Domain controller.

    Nitin can comment .




  • 4.  RE: ESP dSeries workload automation with LDAP Integration[SSL Enabled] - Certificate Renewal of LDAP Server

    Broadcom Employee
    Posted Jun 17, 2025 10:53 AM

    Hi,

    Yes, you are right.  Ideally, you should point to a cluster or some VIP for AD.  Then it should direct your request to any available DC.  You can add individual DC as well on the DE side.  

    HTH,

    Nitin Pande



    ------------------------------
    Support
    Broadcom
    Toronto
    ------------------------------