start_tls: connect error

"Dieter Kluenter" <[email protected]>
Newsgroups gmane.network.openldap.general
Message-ID <[email protected]>
Hi,
I just wonder whether this is a bug in openSSL or in openLDAP, anyhow
the subjectAltName attribute values are nor honoured. 
openssl-0.9.8k-3.5.3.x86_64
openldap-2.4.21

ldapwhoami -Y EXTERNAL -ZZ -H ldap://localhost
ldap_start_tls: Connect error (-11)
additional info: TLS: hostname does not match CN in peer certificate

openssl x509 -in cert.pem -noout -text
Subject: C=DE, L=Hamburg, O=AVCI, OU=Certificate Authority, CN=rubin.avci.de/[email protected]
...
X509v3 Subject Alternative Name: 
 DNS:localhost, DNS:ldap.xxxx.de, DNS:dkluenter.xxxx.org

Not to mention that this is OK with other versions of openldap and
openssl.

-Dieter

-- 
Dieter Klünter | Systemberatung
http://dkluenter.de
GPG Key ID:8EF7B6C6
53°37'09,95"N
10°08'02,42"E
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.