[Date Prev][Date Next]
[Chronological]
[Thread]
[Top]
Re: TLS headache
Dave Lewney wrote:
> This does not look correct to me ...
>
> > TLSCertificateFile /usr/local/openldap/etc/openldap/slapd.pem
> > TLSCACertificateFile /usr/local/openldap/etc/openldap/slapd.pem
>
> ie. your server certificate is the same as the CA you signed it with!
As far as I know it's a valid configuration since a self-issued
certificate the subject (slapd.pem) and the issuer (slapd.pem)
are the same.
--
-----BEGIN GEEK CODE BLOCK-----
Version: 3.1
GCS/IT d- s+:+() a- C+++ UBL+++$ P+ L+++ E--- W++ N+ o++ K- w---
O+ M+ V- PS+ PE+ Y++ PGP+>+++ t+ 5 X+$ R- tv-- b+++ DI D++>+++
G++ e- h+(++) !r !z
------END GEEK CODE BLOCK------