[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: How about direct SSL support for OpenLDAP?



Jason Haar wrote:

> I'm currently using stunnel to provide SSL LDAP support. It works well, but
> it certainly won't scale as well as native support for SSL.
>
> Has anyone worked on adding OpenSSL support?
>
> http://www.openssl.org/
>
> --
> Cheers
>
> Jason Haar
>
> Unix/Network Specialist, Trimble NZ
> Phone: +64 3 9635 377 Fax: +64 3 9635 417
>

do you use ldap through stunnel with something like pam_ldap?  is that
possible?
i use ldap for authenticating users to the cyrus imap server, but i also use
it as an email directory.  right now i don't provide access to the directory
from outside the network, but with an SSL link then i wouldn't mind as much
coupled with normal password authentication over the link.

the standard netscape and microsoft directory clients don't support
client-side SSL authentication, do they?

--mk

"Never ascribe to malice, that which can be explained by incompetence."
--Napoleon

begin:vcard 
n:Krischer;Mark
tel;fax:+61 2 8874 5401
tel;work:+61 2 8874 5400
x-mozilla-html:TRUE
url:http://www.radiata.com
org:Radiata Communications
adr:;;P.O. Box 617;North Ryde;NSW;1670;Australia
version:2.1
email;internet:mark.krischer@radiata.com
title:Software Manager
note:"Networking Unplugged" (tm)
x-mozilla-cpt:;8128
fn:Mark Krischer
end:vcard

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature