[Date Prev][Date Next]
[Chronological]
[Thread]
[Top]
Re: olcTLSCACertificateFile and olcTLSCertificateFile displayed as encrypted?
- To: OpenLDAP Technical <openldap-technical@openldap.org>
- Subject: Re: olcTLSCACertificateFile and olcTLSCertificateFile displayed as encrypted?
- From: Michael Wandel <m.wandel@t-online.de>
- Date: Fri, 28 Sep 2018 07:16:39 +0200
- Autocrypt: addr=m.wandel@t-online.de; prefer-encrypt=mutual; keydata= xsFNBFa8wmYBEADDqqaSr0pozxbOZoIUIVu9rtQzRJTMPeuTDPmBmmvWnTEm4EZBiRyAWNG7 pB40rVI9KWxs1rc+6DyjhO/1nmYgH7quDE7retFcQD7Acy+StjVkkEcjJG5+CT0KdRw3/yci oAuOg82xa0MQxk6Vx1hzZl1yK7divd1ZEnnDa9VEw0nVeulAxYA9KXDffDe5VO1ehhgb2JAf 3FIjmOxU8x+scVAWtRzzPm7H4sONycG/7Vu28dPLK5xdwuRzJG+DThhtkU0ek5zcHRxlmKc0 alUrGnC2T9m50BFLlU3lwcltFARueq7pbAuuUnTmqP2J+gQ2qoXV4+SLNmwotkOfMHSVB22l WHFdkAlVeoRVHnWUN5kRXVrWI9CJ18JTSb6mCCKVUI64L7pEZfvZPDVavIv3CAv9E6+VvuHc eXEYOGYWNLOrOOm9atGISAZK/TuFqOoGhqKo5fTJfC4PLvuMdaQ1gE0FrkM/UsuorrImZ8Qp Jlviv+J2eWSDlBdL6D+PCYL1runVFQch4gEoOlhjFw48FVbU2sa/K185uRKNyVareNRrysG9 +vxCzcgqnYvOQ6nS/aZsZqZJ4WbHhEkL9HROVijJbDKvH9C8L6Ueo94Xpqin9VWPjzE2/eZq Ruk1SdbPD9ntaNJo2Pa35eVcrsOumGFyTkLJqFhiibsizfpoOQARAQABzSVNaWNoYWVsIFdh bmRlbCA8bS53YW5kZWxAdC1vbmxpbmUuZGU+wsGdBBMBAgBHBQJWvMJmJBSAAAAAABQAB20u d2FuZGVsQHQtb25saW5lLmRlbWFpbmtleQIbAwYLCQgHAwIGFQgCCQoLBBYCAwECHgECF4AA CgkQKGiKMJSBe2Q1xxAAhgBqnlLtUQQxsI7vumfws9HFKsYxxuFCjo25EbyX5ZyR1qQM/c6H ovVuHER+czWPNitC7aXbgHjpfNmnn2n289lFNVtLabq8jrND5VIfMcp4Ch9LyTtVRCxitOP+ L7r+rzt3ZncdPgyju34cz6aTAE1txZeannYrbNV1NBCP/4Ev3AffkwLZTWRan4vzWYfbVFna /OxxnBE/znjvno/agR+Oi1s+a5Lf0SqB+v9HFpQk6NvWx0DGby+HGyVzTwMnJlWHdWNNZ2D2 VkK9y1aEToqLYrvMNqJp3afHHr14bRrQ9leUifA3aWvzWRf6Bobs+q7xh8zUFiwVcY5C5ZGZ PgEJl9nQzTlQPeWj6CVD7Kc4xXnd9xiT87aw2wRZNf3758cRv6rT+B8uBdvaN66m8V8RYNeK zSxwe4SqArsQ3bbbLmQxATFptrFOyLrvZeEsu36mItOJNbRjEhGcTAWJoYAYDONasXzG8B7V FTA4yb90uLk6uxtYo1KZ2mBIT1MbjblaxQsIB1TSExf6TI2Z+l8QOj5Al9J6KTmP7Za+QTAn OFUUjGOqiy1LnXmJ0YZjojGI5/16TL4huM8pzpLaTWb26aJMIecq0NW66VFAonCEz8oQVh5R c/cV312We0F5rHKFgmS/3wIjin97QZBczIID16V/qUib1myesV5T5O7OwU0EVrzCZgEQAOcU fKWA7L/vAjDQdo44cblfy17qEIPf+PccU2rP1dvkc3M5/NRJGl6KpTWLleJfPo8zFRdDtGlf WLfvneCa34o+EKL/HgiGGG+2MQJmUvw9Sru108dgtppg5ws1cXuK41MHMtk7sTfUwi7zvXZt slkVUwmQXMEQjDzOOPQHj3BmZdvOCsj/Wtxrc78CnzvPy/Q3MYRgdCn1fo0gwrRqcUMs0Eqt egx5DcQjJaVMHs703NhQnUzMCPFc+RmQYkh7NrAmxcpS8XvYFh6wovlrBNZEk0kSn+PI0d9R Qyi03zh92E8tu2XhLvFsCEgriNNS5oAsNyVPw7icZU4U8kFjILnGILlutP7XpjXPRJHwzqFo dVsLrTwyuHcotWTf+UyozHrbthehOW2iAANxV+APRI6qp+AxQLHkxDp2Ui6MUIXWKNwuMYtK u5xxgbNg+jArprgXVXyV6QdKUfQgbam38FxA8SzLP9UG9t22gDJPGCb+at8EL0cxSPfBo7bQ 4784k+Y/fYYMvdywz64DCZdDF8LQbW/utjp/niqYCSBmx1oh32Gl+z6jKmKWR9AH5ijGYRwI Qn/PZzGEwoQVesH/xCVKyCzc9KIIuqZRRvHrH1l0JNDM9xwPbfpByMvpS8+5urMWlWG/YF4L bZS+uDo7QCW+v4ZpQXPhTlz3E8nejA0RABEBAAHCwYQEGAECAC4FAla8wmYkFIAAAAAAFAAH bS53YW5kZWxAdC1vbmxpbmUuZGVtYWlua2V5AhsMAAoJEChoijCUgXtk2NQP/jE7R7b0iels Ut1IJuiYVhNc7ttyGbeHIkqsGM+9jlz3HRD5wr5e/ENMD169GZs3Fk06oa41RRIGHQ172wuQ cAZKxEhtmaWQAgoABaIRElQJd7x9OpRW1bOXVrRoAhrO0ZSOCt7M1+KOxocf/AYW3o5dAodN Oznoj1vh1Mj3aHsy8lXu/ImvmCkgYgxcuhbYCEbz5aFQsPnTyYr+0vKPo7sTOfdjT/Q6A2Cz PeNRP5bByeota2I4S0Tw7XJUtz35j/2DqXUr5ptZ3p1LAtXauS14rOTgMa8c2Z2fErtyHtvv bJ4LdZP/QPTxxd11BqxNImDoRWLJSBiKLTghhQB/FWMycPBSGW5p7TW7s+Kqolsc+yRtMcRS +nPEshiCC14HCbDoGywa9NRCd+x4xjbxBma2JFbBms9p+1jk4kVMCYyjfVsZau43g3aFay42 HpC/XYYFhP5U3NhUBBL2wN+1hwidq/7kM+jAPpLxv3bkHtBM9h86EJCx16DmxszsSYIzKRya CfB4F/9Gsnj2LT59aT+RiQOBsTaaK0eD3/Htg1shp32A0HM6rpbVU9jth6g2efsIwLz3io+w NgkyvtZDbrCHrB64P0C7KlZJRsPfH+yS2xSAslCUI2PZdnMm+G0vyd14tSKmBgVWW7z0UAbr VPa/vUG1qlI0tjEd1lCJPmWm
- Content-language: en-US
- In-reply-to: <20180926201153.GB19287@bic.mni.mcgill.ca>
- Openpgp: preference=signencrypt
- References: <20180926201153.GB19287@bic.mni.mcgill.ca>
- User-agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.9.1
Am 26.09.2018 um 22:11 schrieb Jean-Francois Malouin:
> Hi>
> Not a very important question, just a little puzzled by this...
> Is there a reason why the olcTLSCACertificateFile and olcTLSCertificateFile
> paths show up as encrypted in this cn=config search?
>
> slapd 2.4.46 on Debian 9.5 (Stretch)
>
> ldapsearch -LLLQY EXTERNAL -H ldapi:/// -b 'cn=config' -s base
> dn: cn=config
> objectClass: olcGlobal
> cn: config
> olcArgsFile: /var/run/slapd/slapd.args
> olcLogLevel: stats
> olcLogLevel: sync
> olcPidFile: /var/run/slapd/slapd.pid
> olcServerID: 1
> olcTLSCACertificateFile:: IC9ldGMvbGRhcC9zc2wvQ09NT0RPX0NBX2J1bmRsZS5jcnQ=
> olcTLSCertificateFile:: ICAgL2V0Yy9sZGFwL3NzbC9TVEFSX2JpY19tbmlfbWNnaWxsX2NhLmNydA==
> olcTLSCertificateKeyFile: /etc/ldap/ssl/STAR_bic_mni_mcgill_ca.key
> olcTLSCipherSuite: NORMAL
> olcTLSVerifyClient: allow
> olcToolThreads: 1
>
> There is an extra ':' ...
>
> When I edit/display the cn=config with ldapvi (old fart here!) they show up as:
>
> olcTLSCACertificateFile:; /etc/ldap/ssl/COMODO_CA_bundle.crt
> olcTLSCertificateFile:; /etc/ldap/ssl/STAR_bic_mni_mcgill_ca.crt
>
Hi,
everything looks good, the "::" is a notation for base64 coding of
values. Your filenames have spaces inside.
You have no problems, if you want to check your Values
# echo ICAgL2V0Yy9sZGFwL3NzbC9TVEFSX2JpY19tbmlfbWNnaWxsX2NhLmNydA== |
base64 -d
hth
best regards
Michael
> again, notice the ';' this time...
>
> Just curious!
>
> Thanks,
> jf
>