Secure authentication to LDAP via TLS

Róbert Čerňanský <[email protected]> Tue, 28 Dec 2010 14:42:09 +0100
Newsgroups gmane.network.dns.bind9.dlz
Message-ID <[email protected]>
Hi,

I'd like configure DLZ to use secure authentication to the LDAP server;
preferably via TLS.  However I can not figure out how to turn it on for
DLZ.

I've found post [1] where it is advised to follow openldap FAQ article
about TLS.  But TLS, in general, is working with LDAP in my case.
Standard openldap clients, like 'ldapsearch' have -Z[Z] parameter to
turn on/force TLS connection and it works here.

It seems that DLZ just uses plain authentication no matter what.  I can
not find a -Z[Z] equivalent for DLZ.  Also I did not find any option
outside DLZ (in openldap's ldap.conf) that would force TLS for all LDAP
clients.

When I've tried to use ldaps:// in queries (to use SSL) then I've got
error: "named[13094]: lookup query must not specify a port".

I'm using bind 9.7.2_p3 and openldap 2.4.23.

Does anyone know how to turn on TLS for DLZ to LDAP connections?

Regards,
Robert

[1] http://thread.gmane.org/gmane.network.dns.bind9.dlz/2167/focus=2170


-- 
Robert Cernansky
E-mail: [email protected]
Jabber: [email protected]

------------------------------------------------------------------------------
Learn how Oracle Real Application Clusters (RAC) One Node allows customers
to consolidate database storage, standardize their database environment, and, 
should the need arise, upgrade to a full multi-node Oracle RAC database 
without downtime or disruption
http://p.sf.net/sfu/oracle-sfdevnl