Mailinglist Archive: opensuse-bugs (5776 mails)
| < Previous | Next > |
[Bug 629549] ldap connects over TLS fail with self signed certificates
- From: bugzilla_noreply@xxxxxxxxxx
- Date: Tue, 10 Aug 2010 11:59:45 +0000
- Message-id: <20100810115945.F1682CC7CE@xxxxxxxxxxxxxxxxxxxxxx>
http://bugzilla.novell.com/show_bug.cgi?id=629549
http://bugzilla.novell.com/show_bug.cgi?id=629549#c5
Volker _ <volker@xxxxxxxxxxxx> changed:
What |Removed |Added
----------------------------------------------------------------------------
Status|NEEDINFO |NEW
InfoProvider|rhafer@xxxxxxxxxx |
--- Comment #5 from Volker _ <volker@xxxxxxxxxxxx> 2010-08-10 11:59:45 UTC ---
(In reply to comment #4)
Yast does: tls_cacertdir /etc/openldap/cacerts/ is present in my
/etc/ldap.conf
Right. *11.3* seems to need it in /etc/openldap/ldap.conf as well. Maybe this
is related to openssl 1.0.0 in 11.3.
You can test this yourself on a 11,3 standard intallation. Configure a LDAP
server with TLS enabled using Yast's 'LDAP Server' module than try to access
your server with the 'LDAP Browser' module.
--
Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=629549#c5
Volker _ <volker@xxxxxxxxxxxx> changed:
What |Removed |Added
----------------------------------------------------------------------------
Status|NEEDINFO |NEW
InfoProvider|rhafer@xxxxxxxxxx |
--- Comment #5 from Volker _ <volker@xxxxxxxxxxxx> 2010-08-10 11:59:45 UTC ---
(In reply to comment #4)
Yes, that's what I asked for. This means YaST should save that value to
/etc/ldap.conf as tls_cacertdir.
Yast does: tls_cacertdir /etc/openldap/cacerts/ is present in my
/etc/ldap.conf
But you say you need to have it in
/etc/openldap/ldap.conf as well, right?
Right. *11.3* seems to need it in /etc/openldap/ldap.conf as well. Maybe this
is related to openssl 1.0.0 in 11.3.
You can test this yourself on a 11,3 standard intallation. Configure a LDAP
server with TLS enabled using Yast's 'LDAP Server' module than try to access
your server with the 'LDAP Browser' module.
--
Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.
| < Previous | Next > |