Small correction:
Owen
On Dec 29, 2006, at 5:32 AM, Rafal ((sxat)) wrote:
TLS_CACERT /usr/local/etc/raddb/RTFE/conca.pemproxy should not be able to >check the certificate sent by the backend ldap.
TLS_REQCERT demand
My issue is that the ssl connexion still works if i comment the line with
TLS_CACERT /usr/local/etc/raddb/RTFE/conca.pem.
and it should not because without this certificate authority my openldapTLS certificate verification: Error, self signed certificate in certificatechainbut it works with this error.
You must have your root CA -> selfsigned after you create - CA and key for your LDAP server - CA anad key for client
both CA(client,server) you must sign by your CA root certificate
pozdr rafal
Attachment:
smime.p7s
Description: S/MIME cryptographic signature