[check_ldap] Disable SSL common name verification

Pierre GINDRAUD <[email protected]> Sat, 14 May 2016 21:09:25 +0200
Newsgroups gmane.network.nagios.plugins,gmane.network.monitoring.plugins.user
Message-ID <[email protected]>
Hello,

I'm trying to use the 'check_ldap' plugin to monitor an instance of an OpenLDAP server configured with StartTLS on port 389.
In my Nagios host definition, I've set the adresse of the server to a relative name such just 'servername' instead of full qualified domain name.
During the STARTTLS handshake the check plugin, return an error with the following message :

    additional info: TLS: hostname does not match CN in peer certificate

Using relative domain name as address for host definition is convenient and I can't use the full qualified domain name instead.

Is there any way t disable SSL common name verification by using extra opts ?


Thanks by advance

-- 

*Pierre GINDRAUD*

Mail : [email protected] <mailto:[email protected]>

Twitter <https://twitter.com/PierreGindraud> Google plus <https://plus.google.com/116501681304840985858/> Linkedin <https://www.linkedin.com/pub/pierre-gindraud/99/a15/871>
Viadéo <https://www.viadeo.com/fr/profile/pierre.gindraud>
signature.asc (application/pgp-signature, 819 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCAAGBQJXN3foAAoJEJ3zwAxuGXXlVGMP/1b5rgHMA5HF3gvFUDa5tlsj
sNj28OpWafE9M+yLiO2m04X8AyjxXCcsVwF6gT1utLRlhxOJViRIPxs18FHxr2NJ
KlydRujdK955+eJDrBXbtyklsSA6dpLlpLxPx8YHghB9KiHI7BE5tuOGEDiSrs1Q
SlMj4sZnwQFZ1Vm2t1EEq72NeV4luxKzlnEVd9lVyLeJuJscODVAyyOBReh1ZLQj
3w++gFdcghKpArWDSlkIQv0fCEpeY+7bWvR2wWfFoud4U8ntOsTWKGa0DjoJg3UD
FkngQiqFdroGscjn4+cZs0AST0RIng12K4O7fchKvh22J+5dhltPbRe0mO4e6dfq
b/B+7AbleHRs6arMgauBBrAVm+8Iti0WCKu7kLUVHUwk8UpqmB6NtPWQCEw72Mbz
Bl6hCRtDhQBwZtrF8eMLLm/F5jGzgIO+Dznl94qKvhQuSHT4En29eCXqRoicLDdu
NdhEH1NroWxg2VUqYr8XIn7gTvevyQSsgOWU3qCQ0dZfriNQRrMQ7T6EX03sRc1h
iZNxj2XCPytYHM/Q/u+2dW5cLeFDe7RczwJbBZAIn1ntSDE0t+FWj8PRvcXBloua
rE0zG1Yr1uCndTXTzb8ymrHLLrKHgB3mDVCWkhQMlvIS3lYCfHgCQQDUNOETadXt
vL7BDvn/2iZrJRvSUyTu
=TPhU
-----END PGP SIGNATURE-----