Bug#1093578: release-notes: openldap switches TLS library impacting behavior

Paul Gevers <[email protected]>
Newsgroups gmane.linux.debian.devel.documentation
Message-ID <11a85b2a-2c11-40ea-a89a-aa72596e6869__18094.2174790957$1737355888$gmane$org@debian.org>
Package: release-notes
Severity: normal
X-Debbugs-Cc: Ryan Tandy <[email protected]>

Hi,

I just saw this on my daily upgrade of my system. Probably worth 
mentioning in the release notes.

Paul

openldap (2.6.9+dfsg-1~exp2) experimental; urgency=medium

   The TLS library used for the OpenLDAP packages has changed from GnuTLS to
   OpenSSL. This affects the set of configuration options available, as 
well as
   the behaviour of some options.

   If no TLS CA certificates are specified, the system default trust 
store will
   now be loaded automatically. If you do not want the default CAs to be 
used,
   you must configure the trusted CAs explicitly.

   Previously, the TLS_CIPHER_SUITE option accepted a GnuTLS priority 
string.
   Now, the option accepts an OpenSSL cipher list. For information about the
   cipher list format, see the openssl-ciphers(1) man page.

   The TLS_CRLFILE option is no longer supported; it is accepted, but 
silently
   ignored. Use the TLS_CRLCHECK option instead. The TLS_CACERTDIR 
option must
   also be set.

   For more information about the libldap configuration, see the 
ldap.conf(5)
   man page.

   For more information about the slapd(8) configuration, see
   /usr/share/doc/slapd/README.Debian.gz.

  -- Ryan Tandy <[email protected]>  Fri, 10 Jan 2025 18:17:14 -0800
OpenPGP_signature.asc (application/pgp-signature, 495 B)
-----BEGIN PGP SIGNATURE-----

wsB5BAABCAAjFiEEWLZtSHNr6TsFLeZynFyZ6wW9dQoFAmeN8ewFAwAAAAAACgkQnFyZ6wW9dQrK
dQf+OPZdQgXa9Mq4frolkGQMKw9UXWAWA63SVYYiLIZZBEoln4Q6m+wbp4rZwPUG3L69k7LdQjwf
J/T6xFI22tMNzemVZ7BLXBSdbWyzAuEhgXmi46IBSL5VsfDrGFTMZ92yw5HkHeSgvi2lrat/iR0x
lNFB38pDfLCHLgmT493CnDwRHQhxE8SSAm4ExKlBUdwLjRs2saQqGPcWxeAgyV5U2sXllTIuQPr/
X1c4bTufWN+Nt604gR9fgjDX9uPSUUtjtDdMQmP0AN98566qHqrGvixGx1xDGc79jsb1mPagQNHJ
WbH2pPNSGNSFE45HfQgrNpUzZhIZ1/E9KQNIlABLCw==
=eYIQ
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.