Re: TLS and Directory Admin
Manuel Amador <[email protected]>
| Newsgroups | gmane.network.directoryadmin |
|---|---|
| Organization | Amautacorp S.A. |
| Message-ID | <[email protected]> |
Tarjei Huse contributed a lot for TLS. He might be able to understand
what is going on.
Fact of the matter is, things have gotten really complicated on the
LDAP+Kerberos+TLS+Schemas+Un-standardiness-of-implementations-of-schemas+PasswordHashes
world =). Having everything work out-of-the-box is still doable, and
should be the ultimate goal for DA, but it takes a multidisciplinary
approach.
El mar, 25-11-2003 a las 13:50, Eric Sandall escribió:
> Hi all,
>
> I'm having problems getting DA to work with a TLS-enabled LDAP server.
>
> I can search my LDAP server through the CLI (with ldapsearch, so I know it
> works), but when I try to test my connection with DA, I get the following error
> (yes, I clicked the "Enable TLS" checkbox):
>
> Error enabling TLS on the LDAP connection
>
> And a popup which says, "Connection failed: Can't contact LDAP server".
>
> Now, I only have slapd listening for ldaps connections (port 636), so just in
> case, I added the port name to "Server address", and received this error when
> testing the connection:
>
> Broken pipe
>
> I haven't done any debugging or looking at code yet, just thought I'd shoot of
> an e-mail before I do to see if anyone else may know what's going on.
>
> If I tell slapd to listen for unencrypted connections, DA seems to connect as it
> reports, "Confidentiality required" when I try to test the connection.
>
> I then skipped the testing of the profile and saved the profile, then edited the
> profile to use TLS and tried to reconnect, which gave me a different report,
> "Could not connect to the directory: TLS appears not to be supported. Please
> disable TLS in your connection profile." (This is with unencrypted connections
> allowed, if I then only allow encrypted connections, DA says that it cannot
> connect to the LDAP server).
>
> If I specify the port after saving the profile, I can then test and try to
> connect and I do not receive the "Broken pipe" error unless I have slapd
> listening for encrypted connections, then I still get the error (it only
> crashes if I specify the port and try to connect to an encrypted-only slapd
> server).
>
> My thought is that SSL/TLS support /may/ be broken in DA.
>
> Anyone else?
>
> -sandalle
--
Manuel Amador
Jefe de I+D
Amauta
+593 (9) 847-7372
-------------------------------------------------------
This SF.net email is sponsored by: SF.net Giveback Program.
Does SourceForge.net help you be more productive? Does it
help you create better code? SHARE THE LOVE, and help us help
YOU! Click Here: http://sourceforge.net/donate/