Re: TLS and Directory Admin
Tarjei Huse <[email protected]>
| Newsgroups | gmane.network.directoryadmin |
|---|---|
| Message-ID | <[email protected]> |
Hi, (snip a lot) > > You can verify that this works by running ldapsearch -ZZ -h yourhost instead > > > > of -Z the difference is that -Z does just (2) while -ZZ does both (I think). > > > > Tips: > > * You might have to add a path to the CA.cert in the ldap.conf file in > > /etc/openldap as well to get ldapsearch to work. > > * Googling for openssl erromessages will often give help allthough DA is a > > minbor app beacause the messages are generic. > > * A openldap errormessage containing something like "CTX" is often related to > > > > filepermissions and wrong paths in the configfile (the errormessage is > > usually just gibberish). > I used the CA.sh script provided by openssl (I used the OpenSSL HOWTO to create > all my files, they never mentioned putting the cert file in /etc/ssl/certs/ and > running the c_rehash program, at least that I saw). I tried your steps, but I > still receive the same problem; it doesn't seem to like my certificates. So for > now I'm not going to use TLS (all the machines are behind a firewall, so none > of this traffic can be seen by outsiders) for now. I think I probably just > messed up the slapd.conf file, but I'm not sure how. I'll continue to muck with > it, but I can't keep the users waiting too long. ;) :-) Getting tls to work well is a hassle. Consider using tinyca to generate your CA and Keys, that helped me a lot! tarjei > > Thanks for the help. > > -sandalle ------------------------------------------------------- This SF.net email is sponsored by: IBM Linux Tutorials. Become an expert in LINUX or just sharpen your skills. Sign up for IBM's Free Linux Tutorials. Learn everything from the bash shell to sys admin. Click now! http://ads.osdn.com/?ad_id=1278&alloc_id=3371&op=click