[389-users] Decrypting SSL for 389-ds

2010-11-12 Thread Gerrard Geldenhuis
Hi I am trying to decrypt SSL traffic capture with tcpdump in wireshark. A quick google turned up a page that said the NSS utils does not allow you to expose your private key. Is there different way or howto that anyone can share to help decrypt SSL encrypted traffic for 389? Regards

Re: [389-users] Decrypting SSL for 389-ds

2010-11-12 Thread David Boreham
On 11/12/2010 8:59 AM, Gerrard Geldenhuis wrote: I am trying to decrypt SSL traffic capture with tcpdump in wireshark. A quick google turned up a page that said the NSS utils does not allow you to expose your private key. Is there different way or howto that anyone can share to help decrypt

Re: [389-users] Decrypting SSL for 389-ds

2010-11-12 Thread Gerrard Geldenhuis
Hi David, I created a new certificate datase with certutil, and I can view the private key fingerprints with certutil -d . -K but I can't actually extract the private key from the certutil database. I can create a certificate sign request using certutil again. I thus have the private key but it

Re: [389-users] Decrypting SSL for 389-ds

2010-11-12 Thread Rich Megginson
Gerrard Geldenhuis wrote: Hi I am trying to decrypt SSL traffic capture with tcpdump in wireshark. A quick google turned up a page that said the NSS utils does not allow you to expose your private key. Is there different way or howto that anyone can share to help decrypt SSL encrypted

Re: [389-users] Decrypting SSL for 389-ds

2010-11-12 Thread Rich Megginson
Gerrard Geldenhuis wrote: Hi David, I created a new certificate datase with certutil, and I can view the private key fingerprints with certutil -d . -K but I can’t actually extract the private key from the certutil database. I can create a certificate sign request using certutil again. I

Re: [389-users] Decrypting SSL for 389-ds

2010-11-12 Thread David Boreham
On 11/12/2010 9:21 AM, Gerrard Geldenhuis wrote: I created a new certificate datase with certutil, and I can view the private key fingerprints with certutil -d . -K but I can't actually extract the private key from the certutil database. I can create a certificate sign request using certutil

Re: [389-users] Slow response from server

2010-11-12 Thread Rich Megginson
Gerrard Geldenhuis wrote: Hi We are getting a slow responses from one of our LDAP servers and I am not sure what is causing the problem I have run a logconv.pl -j and the following is interesting: Connections Reset By Peer:0 Resource Unavailable: 136 - 136 (T1)

Re: [389-users] Bind to consumer binds to provider as well

2010-11-12 Thread Rich Megginson
Gerrard Geldenhuis wrote: Hi In our setup we have clients authenticating against a consumer server. The consumer server is chained to the provider server for writes and we have passwordpolicy configured including lockout settings. We replicate all password data. When I do a bind to

Re: [389-users] dsml packages

2010-11-12 Thread Rich Megginson
Angel Bosch Mora wrote: hi, i can't find last dsml packages anywhere. must i compile from sources? Yes. We never released dsmlgw as an rpm package. i use epel repos. regards, abosch -- 389 users mailing list 389-users@lists.fedoraproject.org

Re: [389-users] Bind to consumer binds to provider as well

2010-11-12 Thread Rich Megginson
Gerrard Geldenhuis wrote: Are you using Chain On Update for Binds? http://directory.fedoraproject.org/wiki/Howto:ChainOnUpdate We are indeed, we used that howto to set it up. Reading it now again it does say it will use the chaining backend for binds. Why is that?

Re: [389-users] Slow response from server

2010-11-12 Thread Rich Megginson
Gerrard Geldenhuis wrote: -Original Message- From: 389-users-boun...@lists.fedoraproject.org [mailto:389-users- boun...@lists.fedoraproject.org] On Behalf Of Rich Megginson Sent: 12 November 2010 16:32 To: General discussion list for the 389 Directory server project. Subject: Re: