Re: ssl/tls troubles
Natxo Asenjo <[email protected]> Thu, 11 Sep 2014 21:10:02 +0200
| Newsgroups | gmane.comp.lang.perl.modules.ldap |
|---|---|
| Message-ID | <CAHBEJzUAMq-ewo3dMrF2KyXbsR1JOx++n69zz1oamRPJ0ZgHcQ@mail.gmail.com> |
--001a11c2f68269a3cf0502ceea3a Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Hi Daniel, On Thu, Sep 11, 2014 at 8:57 PM, Daniel Stutz <[email protected]> wrote= : > Did you try the =E2=80=9Acafile=E2=80=98 option of start_tls? > http://search.cpan.org/~marschap/perl-ldap/lib/Net/LDAP.pod#start_tls > > Yes, I tried that as well, but it did not work either. But apparently the module is smart enough to look into the default paths for openssl and if the cert is in there, you need nothing else but verify =3D> 'require' when using the start_tls method. I tried removing the cert from there and the script croaked inmediately. And wireshark showed that everything was nicely encrypted. Thanks! --=20 groet, natxo --001a11c2f68269a3cf0502ceea3a Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div class=3D"gmail_extra"><div class=3D"gmail_quote">Hi D= aniel,<br><br>On Thu, Sep 11, 2014 at 8:57 PM, Daniel Stutz <span dir=3D"lt= r"><<a href=3D"mailto:[email protected]" target=3D"_blank">dstutz@us= e-strict.net</a>></span> wrote:<br><blockquote class=3D"gmail_quote" sty= le=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div s= tyle=3D"word-wrap:break-word">Did you try the =E2=80=9Acafile=E2=80=98 opti= on of start_tls?<div><a href=3D"http://search.cpan.org/~marschap/perl-ldap/= lib/Net/LDAP.pod#start_tls" target=3D"_blank">http://search.cpan.org/~marsc= hap/perl-ldap/lib/Net/LDAP.pod#start_tls</a></div><br></div></blockquote><d= iv><br></div><div>Yes, I tried that as well, but it did not work either. Bu= t apparently the module is smart enough to look into the default paths for = openssl and if the cert is in there, you need nothing else but verify =3D&g= t; 'require' when using the start_tls method. I tried removing the = cert from there and the script croaked inmediately. And wireshark showed th= at everything was nicely encrypted.<br><br></div><div>Thanks!<br><br>-- <br= ></div><div>groet,<br>natxo <br></div></div></div></div> --001a11c2f68269a3cf0502ceea3a--