[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: ldapi and StartTLS




Michael and Richard, hello.

On 16 Jul 2018, at 5:09, Richard Gray wrote:

Have a look at 'olcLocalSSF' in slapd-config(5), which lets you set the security strength factor for local (i.e. ldapi://) sessions. It defaults to 71, which is likely why you're seeing that error message. Personally, I bump it up to 256, to match the ssf=256 I have set in the olcSecurity attribute on cn=config.

Many thanks for this advice -- it works perfectly. I've set olcLocalSSF to 256.

Hmm: 71 is an oddly-chosen default.  Is there a story there, I wonder?

(Apologies, also, for taking so long to respond: this project had swapped right out of my head, and it was only a couple of days ago that it was able to page back in).

Best wishes,

Norman


--
Norman Gray  :  https://nxg.me.uk