[Date Prev][Date Next]
[Chronological]
[Thread]
[Top]
How to configure OpenLDAP on Debian Stretch to support SSLv3.0
- To: openldap-technical@openldap.org
- Subject: How to configure OpenLDAP on Debian Stretch to support SSLv3.0
- From: Jeremy Davis <jeremy@turnkeylinux.org>
- Date: Tue, 2 Jul 2019 11:58:56 +1000
- Autocrypt: addr=jeremy@turnkeylinux.org; prefer-encrypt=mutual; keydata= mQENBFLb8GcBCAC55vp4RFIiFNX32St2aldX6jk6AeznL6EG+rkkH7bJ410rJFtB8FvSrslO DBgAL7rz89gCPYjXOc5u0h/+5Yl4r68gBA9Vm9AW8clc9/Gsbdu/2kNQrG4CZpPOpedRXOny o0kCyafP1anrvUkdKfjZoCDxKXhagMO/8zjQAOGrA6FQtXnV7VgKqyORtaaqQzrCDDPAp0Hf d19AnJDNwVzP46/KSxFv9r6wUoLE5n5ytbNU1K1pngrGLBq538vUfFhDq9iUxpkD2Lhomam3 HPF9PBwyxuINEFafpVJ+FnivcXFMw5UNHYmDyrEw+Jfoo+JVJ2v97SM8O0mElFz3BFT5ABEB AAG0JkplcmVteSBEYXZpcyA8amVyZW15QHR1cm5rZXlsaW51eC5vcmc+iQFVBBMBCgA/Ahsj BgsJCAcDAgYVCAIJCgsEFgIDAQIeAQIXgBYhBG6vjMeeACulzltFgG0MoksMXMIbBQJcNYl7 BQkNHAAUAAoJEG0MoksMXMIbqh0IALhzPlgQrsWPyD+nOFZi4SqA0qbbla0Fah0uE8aJAbeP 0hEJTd6S7syMNk6k6vQ81Fi3cAYDqyP/9DqYjA1CAYo9Zgj7mgTikmI/AX6Q/j96/hD0tsqx FDWgtG6wgmxWag7RQVDw6w0mED0qyRYzkKp0yBHAd5taWA/LZmtx0a3L+omknZgX3Njwp34r srgNpT2jPBEfr4JIsJrsxhmKOngpth+YuXE5/k4sxYp4L/rVQGr/x82doIX+qgu06WiOIn8x pmNwCq5VjLS50iCq5Pe5Fe3Xr1pvy/x/Z6KF5QQps58y6fwRKIzGIAVgtf3A1/z8wfCh90LS mQmgRLC+JZm5AQ0EUtvwZwEIAMZ0tF7zei1xBBLqLo+JveJvcrIlDpkJ0xLvUOT0po9X+tVJ z0StgkNPT27/nkKkWdgumhKjHWagm96Nyyfhic8U5uS7d6tADA5mZikgDyNkiqy+IhW9GFGm QXbmzsmH5Y6ufL5mqG1CLZ05fsqg7Qja0BzuYf/zDFlhKvvVVpSPRF+OJ6kf6GuLFm9flQbm n+paACnVFwnVi3DWw2KUEtlBItG5vZ+u4LXE6tL2H1t7hLqZqu8u2KpeAUmgSDr1ROCJv+fO 1NY/xvAn3QID6kzw/OfJ6GJvo17J9JxhQ3UvYD8XGGHEMnTLXZFaCkdJ2z2IbJQ4X2gU7wGJ SMse6ZkAEQEAAYkBPAQYAQoAJgIbDBYhBG6vjMeeACulzltFgG0MoksMXMIbBQJcNYnwBQkN HACJAAoJEG0MoksMXMIbIwgH/159x/8LN42W9aVHTyTuND0IpG6VB4kTAr4KwaUX/mDvdrCf 55n3qfCWc+vWHBQHjzO3yqaXK1d47vhoM4c97hZbTUrq11sDDGfWuTIGrPpL755HSIfg98yB raVWX5+008iz5EkWlLIU0WL24OMr2Idr2wAMIea3NIVOiCadj4GQKlQTN+mUZ5Xwt4iFQkY5 bxBT6rxyqhIURwypoE2gUje+3k5hOUduh6Hdv+0YDML4s9d6SHLowwqc6glYDlXY9n2budtQ vuujhuLT4KwOy2Vhyz9xmIEL1cv3yzzy/6fnjCQhWuWlmCavIyq9XnkJkfI9qe4F38A8axh8 WPGUMs8=
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/simple; d=turnkeylinux.org; s=mail; t=1562032741; bh=UEcG/JvC2gxfFox2z1Q/RNn3NetkhAUovqw8PtkliBA=; h=To:From:Subject:Message-ID:Date:MIME-Version:Content-Type; b=Q6owCEf4FkT6mDtAVZDSVUsmdfI44ttrnpnu8te4njEn6hBHQkY/JVYxPQflmgecb sEOvyA3Kvz0pR+LVWYF6/lLQUAp6CWw9dSn2mzE8B+EHUw4VxPMIXDB9GCp3dBZguv QbQBKOgmDlI7aMqPSg2qlFQuzfpsc26qe0CTe49U=
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/simple; d=turnkeylinux.org; s=mail; t=1562032740; bh=UEcG/JvC2gxfFox2z1Q/RNn3NetkhAUovqw8PtkliBA=; h=To:From:Subject:Message-ID:Date:MIME-Version:Content-Type; b=AIq3d2v4spx1MnS8mj5ReFx8P8k8iYbvaCBCwvP2DEGk4oPcLDfsmTwd3eW3Mlv5j fifoj5tEB1IOljPShWa6JDPw1mCQ/RFbq3PS3VVS9RsntkZlq0mQiFu0hCOQA5bmaU Eq73trS39NcJsrRYojRz47963C1jwNQqKd4dIbT4=
- Openpgp: preference=signencrypt
- Organization: Turnkey Linux
Hi all,
I'm writing on behalf of a user ragrading how to go about configuring
LDAPS support for SSLv3.0 certificate under OpenLDAP v2.4.44 - running
on Debian 9/Stretch (default Debian 'slapd' package install).
I know that SSLv3.0 is insecure and generally a bad option, but a user
needs to connect to LDAPS with an old application that only supports
SSLv3.0.
I understand that a complicating factor may be that the Debian OpenLDAP
(slapd) package is compiled against GnuTLS, rather than OpenSSL.
Any insight that might head me in the right direction would be greatly
appreciated.
Also please note that I'm a bit of an OpenLDAP newb and my knowledge of
SSL/TLS is more related to web servers/browsers and more about "best
practices" rather than tweaking to be more permissive.
Regards,
Jeremy Davis
TurnKey Linux
Attachment:
signature.asc
Description: OpenPGP digital signature