ldap tls question

Marek Greško via Kerberos <[email protected]> Thu, 16 Apr 2026 07:18:06 +0000
Newsgroups gmane.comp.encryption.kerberos.general
Message-ID <Wue5t2JvMQ5zG470bx88Nm-TkZTm0lrlD4NZQN8uTudXRMZ9IhaySGpjjm8u1VezYyZy6-mSm473bUkPRhNSEohj7dgq8OJ8Vf-mgXJDBrI=@protonmail.com>
Hello,

I use mit kerberos with ldap backend. I have defined ldap_servers in dbmodule to ldap://FQDN. Since this is a local host it is not a problem. But I am interested in how to configure it correctly if the ldap server is not local and I want to use start_tls on ldap instead od ssl on ldaps. Also I am interested in how can I specify CA certificate file for either start_tls or ssl and how ro require certificate verification. I cannot see option for these settings in manuals.

Thanks

Marek
________________________________________________
Kerberos mailing list           [email protected]
https://mailman.mit.edu/mailman/listinfo/kerberos