[check_ldap] Disable SSL common name verification
Pierre GINDRAUD <[email protected]> Sat, 14 May 2016 21:09:25 +0200
| Newsgroups | gmane.network.nagios.plugins,gmane.network.monitoring.plugins.user |
|---|---|
| Message-ID | <[email protected]> |
Hello,
I'm trying to use the 'check_ldap' plugin to monitor an instance of an OpenLDAP server configured with StartTLS on port 389.
In my Nagios host definition, I've set the adresse of the server to a relative name such just 'servername' instead of full qualified domain name.
During the STARTTLS handshake the check plugin, return an error with the following message :
additional info: TLS: hostname does not match CN in peer certificate
Using relative domain name as address for host definition is convenient and I can't use the full qualified domain name instead.
Is there any way t disable SSL common name verification by using extra opts ?
Thanks by advance
--
*Pierre GINDRAUD*
Mail : [email protected] <mailto:[email protected]>
Twitter <https://twitter.com/PierreGindraud> Google plus <https://plus.google.com/116501681304840985858/> Linkedin <https://www.linkedin.com/pub/pierre-gindraud/99/a15/871>
Viadéo <https://www.viadeo.com/fr/profile/pierre.gindraud>
signature.asc
(application/pgp-signature, 819 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCAAGBQJXN3foAAoJEJ3zwAxuGXXlVGMP/1b5rgHMA5HF3gvFUDa5tlsj sNj28OpWafE9M+yLiO2m04X8AyjxXCcsVwF6gT1utLRlhxOJViRIPxs18FHxr2NJ KlydRujdK955+eJDrBXbtyklsSA6dpLlpLxPx8YHghB9KiHI7BE5tuOGEDiSrs1Q SlMj4sZnwQFZ1Vm2t1EEq72NeV4luxKzlnEVd9lVyLeJuJscODVAyyOBReh1ZLQj 3w++gFdcghKpArWDSlkIQv0fCEpeY+7bWvR2wWfFoud4U8ntOsTWKGa0DjoJg3UD FkngQiqFdroGscjn4+cZs0AST0RIng12K4O7fchKvh22J+5dhltPbRe0mO4e6dfq b/B+7AbleHRs6arMgauBBrAVm+8Iti0WCKu7kLUVHUwk8UpqmB6NtPWQCEw72Mbz Bl6hCRtDhQBwZtrF8eMLLm/F5jGzgIO+Dznl94qKvhQuSHT4En29eCXqRoicLDdu NdhEH1NroWxg2VUqYr8XIn7gTvevyQSsgOWU3qCQ0dZfriNQRrMQ7T6EX03sRc1h iZNxj2XCPytYHM/Q/u+2dW5cLeFDe7RczwJbBZAIn1ntSDE0t+FWj8PRvcXBloua rE0zG1Yr1uCndTXTzb8ymrHLLrKHgB3mDVCWkhQMlvIS3lYCfHgCQQDUNOETadXt vL7BDvn/2iZrJRvSUyTu =TPhU -----END PGP SIGNATURE-----