Re: ssl/tls troubles

Natxo Asenjo <[email protected]> Thu, 11 Sep 2014 21:10:02 +0200
Newsgroups gmane.comp.lang.perl.modules.ldap
Message-ID <CAHBEJzUAMq-ewo3dMrF2KyXbsR1JOx++n69zz1oamRPJ0ZgHcQ@mail.gmail.com>
--001a11c2f68269a3cf0502ceea3a
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Hi Daniel,

On Thu, Sep 11, 2014 at 8:57 PM, Daniel Stutz <[email protected]> wrote=
:

> Did you try the =E2=80=9Acafile=E2=80=98 option of start_tls?
> http://search.cpan.org/~marschap/perl-ldap/lib/Net/LDAP.pod#start_tls
>
>
Yes, I tried that as well, but it did not work either. But apparently the
module is smart enough to look into the default paths for openssl and if
the cert is in there, you need nothing else but verify =3D> 'require' when
using the start_tls method. I tried removing the cert from there and the
script croaked inmediately. And wireshark showed that everything was nicely
encrypted.

Thanks!

--=20
groet,
natxo

--001a11c2f68269a3cf0502ceea3a
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_extra"><div class=3D"gmail_quote">Hi D=
aniel,<br><br>On Thu, Sep 11, 2014 at 8:57 PM, Daniel Stutz <span dir=3D"lt=
r">&lt;<a href=3D"mailto:[email protected]" target=3D"_blank">dstutz@us=
e-strict.net</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" sty=
le=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div s=
tyle=3D"word-wrap:break-word">Did you try the =E2=80=9Acafile=E2=80=98 opti=
on of start_tls?<div><a href=3D"http://search.cpan.org/~marschap/perl-ldap/=
lib/Net/LDAP.pod#start_tls" target=3D"_blank">http://search.cpan.org/~marsc=
hap/perl-ldap/lib/Net/LDAP.pod#start_tls</a></div><br></div></blockquote><d=
iv><br></div><div>Yes, I tried that as well, but it did not work either. Bu=
t apparently the module is smart enough to look into the default paths for =
openssl and if the cert is in there, you need nothing else but verify =3D&g=
t; &#39;require&#39; when using the start_tls method. I tried removing the =
cert from there and the script croaked inmediately. And wireshark showed th=
at everything was nicely encrypted.<br><br></div><div>Thanks!<br><br>-- <br=
></div><div>groet,<br>natxo <br></div></div></div></div>

--001a11c2f68269a3cf0502ceea3a--