SSL/TLS protection encrypts the directory user ID and password during a bind to an LDAPv3-compliant directory, to prevent man-in-the-middle attacks and other security threats.
Teradata recommends SSL or TLS protection when:
- LDAP authentication uses simple binding.
- Kerberos authenticates users, while the directory authorizes user privileges in the database, resulting an automatic service bind (a type of simple bind).
You can configure LDAP protection properties in the LDAP, Kerberos, and SPNEGO mechanisms on Teradata Database nodes and on the Unity server, if the AuthorizationSupported property is set to yes. Also see LDAP Protection Properties.
You can also use SSL and TLS protection on systems that use DIGEST-MD5 binding. See Using SSL and TLS Protection for DIGEST-MD5 Binding.
For configuration requirements when authentication is set for multiple directory services, see Creating the <LdapConfig> Section in the TdgssUserConfigFile.xml.