Re: SASL/EXTERNAL binding

2017-11-16 Thread Shawn McKinney
> On Nov 16, 2017, at 2:35 PM, Emmanuel Lécharny wrote: > > Regarding this specific feature, teh real problem for us was to get it > tested. But if you don't mind doing this part of the job, we probably > can move forward ! +1 to needing help with the testing. I’ve never

Re: SASL/EXTERNAL binding

2017-11-16 Thread Emmanuel Lécharny
Le 16/11/2017 à 18:35, Frank Crow a écrit : > About four years ago, I started on a project using OpenLDAP and Apache LDAP > API for ldap client applications. Due to requirements we moved away from > using stored passwords and configured for client-side certificates > (SASL/EXTERNAL). That is

SASL/EXTERNAL binding

2017-11-16 Thread Frank Crow
About four years ago, I started on a project using OpenLDAP and Apache LDAP API for ldap client applications. Due to requirements we moved away from using stored passwords and configured for client-side certificates (SASL/EXTERNAL). That is when I discovered that the Apache LDAP API did not

Unavailable Cipher Suites

2017-11-16 Thread Frank Crow
I'm using Apache Directory Studio (which I assume is using the Apache LDAP API) and having an issue connecting due to (apparently) "unavailable cipher suites" with OpenLDAP. I created a self-signed CA using OpenSSL command line tools and have verified that the certificate (and even client-side