[Bug 1051695] New: ldap_start_tls: Connect error (-11) additional info: error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed (self signed certificate in certificate chain)
http://bugzilla.opensuse.org/show_bug.cgi?id=1051695 Bug ID: 1051695 Summary: ldap_start_tls: Connect error (-11) additional info: error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed (self signed certificate in certificate chain) Classification: openSUSE Product: openSUSE Distribution Version: Leap 42.3 Hardware: Other OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Basesystem Assignee: bnc-team-screening@forge.provo.novell.com Reporter: bruno@ioda-net.ch QA Contact: qa-bugs@suse.de Found By: --- Blocker: --- After upgrading a working openSUSE Leap 42.1 (ldap, sssd, samba) server there's no way to do a simple ldapsearch -x -ZZ without getting the error in subject. the self-signed ca is stored in /etc/pki/anchor/trust and symlinks are present in /var/lib/ca-certificates/pem There doesn't seems to have any changes needed in /etc/ldap.conf ps : this also create a fail condition for samba using ldap is start tls is on. What and How can this be debugged. ps2 : This symptom has been seen now on 2 servers. -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1051695 http://bugzilla.opensuse.org/show_bug.cgi?id=1051695#c1 Bruno Friedmann <bruno@ioda-net.ch> changed: What |Removed |Added ---------------------------------------------------------------------------- Assignee|bnc-team-screening@forge.pr |hguo@suse.com |ovo.novell.com | --- Comment #1 from Bruno Friedmann <bruno@ioda-net.ch> --- Possible related boo entry * mar mai 17 2016 hgo - Enable build flag LDAP_USE_NON_BLOCKING_TLS to fix bsc#978408. The bug entry is not accessible (even logged in bugzilla) as openSUSE contributor. Other related ? stuff https://bugzilla.opensuse.org/show_bug.cgi?id=1009470 -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1051695 http://bugzilla.opensuse.org/show_bug.cgi?id=1051695#c2 --- Comment #2 from Bruno Friedmann <bruno@ioda-net.ch> --- Another interesting things. Package libldap doesn't require libldap-data and as such /etc/openldap/ldap.conf file isn't there. Recommends: libldap-data >= 2.4.44 In case of upgrade 42.1 to 42.3 for example (with --no-recommends for obvious reasons on server), the old libldap rpm is removed, ldap.conf is saved as ldap.conf.rpmsave and no new is installed. I've seen here sysadmins thinking the file is no more needed. So there's two thing, if the file is not useful for having a running system, then recommends is the right tags. If file is mandatory (which seem clearly the case) then Requires is the right tag. After installing libldap-data package, restored old ldap.conf file a command using -ZZ is again working. An update would be really appreciate, and also a line in the Release note. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com