Bug#512693: slapd - ldap proxy with tls enforces cert check even if disabled

2010-04-25 Thread Matthijs Möhlmann
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, We have currently 2.4.21 in the archive, can you test this again ? There are a lot of improvements to the gnutls code since 2.4.11-1. Thanks in advance. Regards, Matthijs Mohlmann -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.10

Bug#512693: slapd - ldap proxy with tls enforces cert check even if disabled

2009-01-25 Thread Bastian Blank
tags 512693 patch thanks Reason found. In ldap_back_prepare_conn the tls settings are applied via a bindconf_tls_set call _once_, while the settings are per connection. The attached patch changes this to apply the settings for each connection. There is similar code in servers/slapd/config.c,

Bug#512693: [Pkg-openldap-devel] Bug#512693: slapd - ldap proxy with tls enforces cert check even if disabled

2009-01-25 Thread Quanah Gibson-Mount
--On Sunday, January 25, 2009 3:42 PM +0100 Bastian Blank wa...@debian.org wrote: tags 512693 patch thanks Reason found. In ldap_back_prepare_conn the tls settings are applied via a bindconf_tls_set call _once_, while the settings are per connection. The attached patch changes this to apply

Bug#512693: [Pkg-openldap-devel] Bug#512693: slapd - ldap proxy with tls enforces cert check even if disabled

2009-01-25 Thread Bastian Blank
On Sun, Jan 25, 2009 at 09:26:00AM -0800, Quanah Gibson-Mount wrote: Upstream was unable to reproduce this issue, so I'm guessing it is already fixed there. I would advise using the upstream code instead of patching it with your own patch. This code is GnuTLS specific. I don't know where

Bug#512693: slapd - ldap proxy with tls enforces cert check even if disabled

2009-01-22 Thread Bastian Blank
Package: slapd Version: 2.4.11-1 Severity: important I configured slapd to work as a ldap proxy. Because of some problems with the certs of the upstream server, I decided to disable cert checks for now. | databaseldap | suffix o=Example | uri