Re: [phpldapadmin] Configure 2 different self signed CA
Javi Legido <[email protected]> Thu, 26 Nov 2015 09:08:43 +0100
| Newsgroups | gmane.comp.ldap.davedap |
|---|---|
| Message-ID | <CALbe0QWsEYEUXwb8JjVFjdGbwHmxJEJgiKC4kbkd-MyrWzL+zA@mail.gmail.com> |
--===============2961506194832372862== Content-Type: multipart/alternative; boundary=089e0168199e5a396d05256d15bc --089e0168199e5a396d05256d15bc Content-Type: text/plain; charset=UTF-8 Hi there. I'm not an expert in the tool, since I have a single PHPLDAP server connecting to its own CA server, but reading your e-mail I guess that you need to decompose the problem in little ones. Are you able to setup a fresh new PHPLDAP server that can connect to new CA server? Is it not clear for me if you even already achieved it. Cheers. On 26 November 2015 at 08:26, Olivier Nicole <[email protected]> wrote: > Hi, > > I am in the process of migrating my OpenLDAP from an old self signed > root CA certificate (MD5) to a newer one (SHA). > > To do that, I have set-up 2 LDAP servers replicating, each server using > a different certificate. > > I want to be able to access both servers with phpLDAPadmin. I can access > the old server with no problem (it has worked for years, thank you), but > I get a TLS negociation failure when trying to access the new server. > > I have been poking around in phpLDAPadmin, trying to figure out where > the various certificate files are configured, but I could not find > anyplace. > > How to configure phpLDAPadmin to access OpenLDAp server1, with > certificate 1 signed by CA1 and OpenLDAp server2, with > certificate 2 signed by CA2? (In the past I had no problem accessign > several LDAP servers that all had their keys signed by a unique CA). > > Thanks in advance, > > Olivier > > > ------------------------------------------------------------------------------ > Go from Idea to Many App Stores Faster with Intel(R) XDK > Give your users amazing mobile app experiences with Intel(R) XDK. > Use one codebase in this all-in-one HTML5 development environment. > Design, debug & build mobile apps & 2D/3D high-impact games for multiple > OSs. > http://pubads.g.doubleclick.net/gampad/clk?id=254741551&iu=/4140 > ______________________________________ > phpLDAPadmin development mailing list. > To unsbuscribe: > https://lists.sourceforge.net/lists/listinfo/phpldapadmin-devel > http://phpldapadmin.sourceforge.net/ > --089e0168199e5a396d05256d15bc Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div><div><div><div>Hi there.<br><br></div><div>I'm no= t an expert in the tool, since I have a single PHPLDAP server connecting to= its own CA server, but reading your e-mail I guess that you need to decomp= ose the problem in little ones.<br></div><br></div>Are you able to setup a = fresh new PHPLDAP server that can connect to new CA server?<br><br></div>Is= it not clear for me if you even already achieved it.<br><br></div>Cheers.<= br></div><div class=3D"gmail_extra"><br><div class=3D"gmail_quote">On 26 No= vember 2015 at 08:26, Olivier Nicole <span dir=3D"ltr"><<a href=3D"mailt= o:[email protected]" target=3D"_blank">[email protected]= h</a>></span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margi= n:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi,<br> <br> I am in the process of migrating my OpenLDAP from an old self signed<br> root CA certificate (MD5) to a newer one (SHA).<br> <br> To do that, I have set-up 2 LDAP servers replicating, each server using<br> a different certificate.<br> <br> I want to be able to access both servers with phpLDAPadmin. I can access<br= > the old server with no problem (it has worked for years, thank you), but<br= > I get a TLS negociation failure when trying to access the new server.<br> <br> I have been poking around in phpLDAPadmin, trying to figure out where<br> the various certificate files are configured, but I could not find<br> anyplace.<br> <br> How to configure phpLDAPadmin to access OpenLDAp server1, with<br> certificate 1 signed by CA1 and OpenLDAp server2, with<br> certificate 2 signed by CA2? (In the past I had no problem accessign<br> several LDAP servers that all had their keys signed by a unique CA).<br> <br> Thanks in advance,<br> <br> Olivier<br> <br> ---------------------------------------------------------------------------= ---<br> Go from Idea to Many App Stores Faster with Intel(R) XDK<br> Give your users amazing mobile app experiences with Intel(R) XDK.<br> Use one codebase in this all-in-one HTML5 development environment.<br> Design, debug & build mobile apps & 2D/3D high-impact games for mul= tiple OSs.<br> <a href=3D"http://pubads.g.doubleclick.net/gampad/clk?id=3D254741551&iu= =3D/4140" rel=3D"noreferrer" target=3D"_blank">http://pubads.g.doubleclick.= net/gampad/clk?id=3D254741551&iu=3D/4140</a><br> ______________________________________<br> phpLDAPadmin development mailing list.<br> To unsbuscribe: <a href=3D"https://lists.sourceforge.net/lists/listinfo/php= ldapadmin-devel" rel=3D"noreferrer" target=3D"_blank">https://lists.sourcef= orge.net/lists/listinfo/phpldapadmin-devel</a><br> <a href=3D"http://phpldapadmin.sourceforge.net/" rel=3D"noreferrer" target= =3D"_blank">http://phpldapadmin.sourceforge.net/</a><br> </blockquote></div><br></div> --089e0168199e5a396d05256d15bc-- --===============2961506194832372862== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline ------------------------------------------------------------------------------ Go from Idea to Many App Stores Faster with Intel(R) XDK Give your users amazing mobile app experiences with Intel(R) XDK. Use one codebase in this all-in-one HTML5 development environment. Design, debug & build mobile apps & 2D/3D high-impact games for multiple OSs. http://pubads.g.doubleclick.net/gampad/clk?id=254741551&iu=/4140 --===============2961506194832372862== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline ______________________________________ phpLDAPadmin development mailing list. To unsbuscribe: https://lists.sourceforge.net/lists/listinfo/phpldapadmin-devel http://phpldapadmin.sourceforge.net/ --===============2961506194832372862==--