[Date Prev][Date Next]
[Chronological]
[Thread]
[Top]
RE: syncrepl fails after upgrade to openldap 2.4.45
- To: <quanah@symas.com>, <openldap-technical@openldap.org>
- Subject: RE: syncrepl fails after upgrade to openldap 2.4.45
- From: <Juergen.Sprenger@swisscom.com>
- Date: Fri, 23 Jun 2017 07:30:02 +0000
- Accept-language: en-US, de-CH
- Content-language: de-DE
- In-reply-to: <4304E977C4D48D8E6E0E28CB@[192.168.1.30]>
- References: <a146956554c84b45bef9b9971741aebc@SG001738.corproot.net> <WM!83b92ebed934ebe68e0b1dc3ed2accc9cb98ac847bcfd9714b8b1e4b01031a374101e479b843c68909ce2ce76d79a653!@mailstronghold-2.zmailcloud.com> <4304E977C4D48D8E6E0E28CB@[192.168.1.30]>
- Thread-index: AdLrNylJppT6A2SvTPulypDH+mmoFwAMrDx6ACHMdiA=
- Thread-topic: syncrepl fails after upgrade to openldap 2.4.45
The replication worked with 2.4.44-r1 anyway.
In the main section I have these entries:
security tls=1
TLSProtocolMin 3.3
TLSCipherSuite HIGH:MEDIUM:!SSLv2:!SSLv3
TLSCertificateFile /etc/ssl/openldap/dannatu.ch.pem
TLSCertificateKeyFile /etc/ssl/openldap/dannatu.ch.key
TLSCACertificateFile /etc/ssl/certs/dannatuCA-cacert.pem
Have also added these entries to syncrepl now, but without any success:
tls_cert=/etc/ssl/openldap/dannatu.ch.pem
tls_key=/etc/ssl/openldap/dannatu.ch.key
tls_cacert=/etc/ssl/certs/dannatuCA-cacert.pem
Still works with 2.4.44-r1, but not with 2.4.45.
Juergen
-----Original Message-----
From: Quanah Gibson-Mount [mailto:quanah@symas.com]
Sent: Thursday, June 22, 2017 5:12 PM
To: Sprenger Jürgen, INI-ON-CIS-SDI-HES <Juergen.Sprenger@swisscom.com>; openldap-technical@openldap.org
Subject: Re: syncrepl fails after upgrade to openldap 2.4.45
--On Thursday, June 22, 2017 10:25 AM +0000 Juergen.Sprenger@swisscom.com
wrote:
> syncrepl rid=000
> provider=ldaps://ldap.dannatu.ch:636
> type=refreshAndPersist
> retry="5 5 300 +"
> searchbase="dc=dannatu,dc=ch"
> attrs="*,+"
> scope=sub
> bindmethod=simple
> binddn="cn=Manager,dc=dannatu,dc=ch"
> credentials=**************
I don't see anything here configuring for syncrepl to find the CA for your server cert. I.e., something like tls_cacertdir=<path>
--Quanah
--
Quanah Gibson-Mount
Product Architect
Symas Corporation
Packaged, certified, and supported LDAP solutions powered by OpenLDAP:
<http://www.symas.com>