Re: OpenSSL provider support in openldap: OSSL_STORE_open()

Howard Chu <[email protected]> Wed, 3 Jan 2024 18:02:11 +0000
Newsgroups gmane.network.openldap.devel
Message-ID <[email protected]>
Graham Leggett wrote:
> On 19 Dec 2023, at 12:45, Graham Leggett <[email protected]> wrote:
>=20
>> A search in the openldap source shows we don=E2=80=99t yet support the=
 OpenSSL3 provider OSSL_STORE_open() call, which takes a URL as a paramet=
er.
>>
>> I=E2=80=99m happy to patch the openldap client to support this, would =
it make sense to add a LDAP_OPT_X_TLS_URL option to ldap_option_set()?
>=20
> Patch available here:
>=20
> https://bugs.openldap.org/show_bug.cgi?id=3D10149

Looks a bit like a chicken'n'egg situation, why should anyone trust the c=
onnection that was used to
retrieve certs and keys from the designated URI?
>=20
> This allows replication in 389ds to be fixed, with the patch available =
here for anyone interested:
>=20
> https://github.com/389ds/389-ds-base/pull/6021
>=20
> Regards,
> Graham
> =E2=80=94
>=20


--=20
  -- Howard Chu
  CTO, Symas Corp.           http://www.symas.com
  Director, Highland Sun     http://highlandsun.com/hyc/
  Chief Architect, OpenLDAP  http://www.openldap.org/project/