Can't use Bind DLZ through LDAPS SSL

Dario García Díaz-Miguel <[email protected]> Fri, 12 Feb 2021 06:39:46 +0000
Newsgroups gmane.network.dns.bind9.dlz,gmane.network.dns.bind.user
Message-ID <[email protected]>
Hi there,

I really don't know If this is the correct place to ask about Bind DLZ, but=
 I'm afraid that I could not have any responses from the BIND DLZ mail list=
 and, since this seems to be an "official" plugin and it's compiled on the =
bind9 package from the SuSE15 SP2 repository I will try to ask it over here.
I've deployed an OpenLDAP using the security options recommended by my cybe=
rsecurity team:

- olcSecurity: ssf=3D256
- olcLocalSSF: 256
- olcRequires: authc
- olcDisallow: bind_anon
- olcTLSVerifyClient: try

So essentially right now is required to use certificates and LDAPS in order=
 to bind to the OpenLDAP server. Otherwise a Confidential error will appear=
 since TLS SSL Handshake is not possible. Well, this is the expected behavi=
or.
All the software of the environment works flawlessly using the SSL Certific=
ates through LDAPS SSL except Bind DLZ. I could not find the way to configu=
re it to use SSL.

The Bind DLZ used is the one compiled with the BIND 9.16.6 (Stable Release)=
 from the SUSE 15 SP2 repository.

Could anybody help me?

Thank you so much.
Regards.



Dario Garcia
D=EDaz-Miguel
GGCS-SES Unit
GGCS SKMF Infrastructure Division
GMV
C\ de Isaac Newton, 11
28760, Tres Cantos, Madrid
Espa=F1a
+34 918 07 21 00
+34 918 07 21 99
www.gmv.com









P Please consider the environment before printing this e-mail.