[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: How about direct SSL support for OpenLDAP?

Jason Haar wrote:

> I'm currently using stunnel to provide SSL LDAP support. It works well, but
> it certainly won't scale as well as native support for SSL.
> Has anyone worked on adding OpenSSL support?
> http://www.openssl.org/
> --
> Cheers
> Jason Haar
> Unix/Network Specialist, Trimble NZ
> Phone: +64 3 9635 377 Fax: +64 3 9635 417

do you use ldap through stunnel with something like pam_ldap?  is that
i use ldap for authenticating users to the cyrus imap server, but i also use
it as an email directory.  right now i don't provide access to the directory
from outside the network, but with an SSL link then i wouldn't mind as much
coupled with normal password authentication over the link.

the standard netscape and microsoft directory clients don't support
client-side SSL authentication, do they?


"Never ascribe to malice, that which can be explained by incompetence."

tel;fax:+61 2 8874 5401
tel;work:+61 2 8874 5400
org:Radiata Communications
adr:;;P.O. Box 617;North Ryde;NSW;1670;Australia
title:Software Manager
note:"Networking Unplugged" (tm)
fn:Mark Krischer

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature