> --On Friday, August 24, 2007 6:13 PM -0400 Chuck Keagle
> <[EMAIL PROTECTED]> wrote:
>
> > Here are the current TLS settings in the indicated files (I took out some
> > comments to make reading easier):
> >
> ># grep -i tls /etc/ldap.conf /etc/openldap/ldap.conf
>
> > /etc/ldap.conf:tls_cacertdir /etc/openldap/cacerts
> > /etc/openldap/ldap.conf:TLS_CACERTDIR /etc/openldap/cacerts
>
>
>
> To use the tls_cacertdir bits, you must create the x509 hash of the CA cert
> in /etc/openldap/cacerts directory.
>
> Something like the following:
>
> ln -f -s ca.pem /etc/openldap/cacerts/`openssl x509 -hash -noout -in
> /etc/openldap/ca.pem`.0
>
Here is what I did:
# cd /etc/openldap/cacerts
# ln -f -s CA.pem /etc/openldap/cacerts/`openssl x509 -hash -noout -in
/etc/openldap/cacerts/CA.pem`.0
ls -l
total 8
lrwxrwxrwx 1 root root 6 Aug 24 15:48 69c9c6c2.0 -> CA.pem
lrwxrwxrwx 1 root root 23 Aug 21 11:06 CA.pem -> /usr/share/swamp/CA.pem
# openssl x509 -text -in CA.pem
# Certificate:
Data:
Version: 3 (0x2)
Serial Number: 0 (0x0)
Signature Algorithm: md5WithRSAEncryption
Issuer: C=NZ, L=Wellington, O=Really Irresponsible Authorisation
Authority (RIAA), OU=Cert-stamping, CN=Jackov
al-Trades/[EMAIL PROTECTED]
Validity
Not Before: Jan 16 05:09:59 2002 GMT
Not After : Jan 14 05:09:59 2012 GMT
Subject: C=NZ, L=Wellington, O=Really Irresponsible Authorisation
Authority (RIAA), OU=Cert-stamping, CN=Jackov
al-Trades/[EMAIL PROTECTED]
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public Key: (1024 bit)
Modulus (1024 bit):
00:bb:41:d0:df:14:8a:c9:9f:75:f6:e2:12:a6:a6:
4c:a4:dd:31:b4:22:fc:5d:2b:6c:16:98:33:d7:ab:
5c:23:af:c9:54:4f:0a:c0:ea:13:39:05:af:4d:df:
a8:cb:89:e5:a9:5e:1b:e2:2c:e5:ae:f4:30:73:6b:
91:a6:b6:00:ae:5e:5a:00:4c:a4:c2:f7:8c:4e:74:
a1:e5:72:24:d5:ba:31:b7:c0:39:4b:0c:1e:5e:ef:
5d:0a:6a:bf:38:9e:78:fa:56:e7:8b:d5:1c:99:d1:
b9:8f:e4:f0:0d:6b:89:9b:19:6f:53:a9:ce:c9:0a:
40:53:4d:6d:b2:f5:dd:12:81
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
49:FB:45:72:12:C4:CC:E1:45:A1:D3:08:9E:95:C4:2C:6D:55:3F:17
X509v3 Authority Key Identifier:
keyid:49:FB:45:72:12:C4:CC:E1:45:A1:D3:08:9E:95:C4:2C:6D:55:3F:17
DirName:/C=NZ/L=Wellington/O=Really Irresponsible
Authorisation Authority (RIAA)/OU=Cert-stamping/CN=Jackov
al-Trades/[EMAIL PROTECTED]
serial:00
X509v3 Basic Constraints:
CA:TRUE
Signature Algorithm: md5WithRSAEncryption
61:0a:3d:e5:5f:cd:63:e7:8a:c5:8c:64:86:26:d9:89:44:32:
82:98:7e:81:37:e0:6c:31:b6:d0:cb:27:1f:af:bc:ff:fc:39:
02:b1:da:b8:50:a0:0e:b7:f4:3f:65:72:00:28:2a:f8:de:29:
05:35:85:19:a0:1a:2f:06:e3:2b:2f:47:09:ed:84:8f:d0:bd:
d6:d3:b5:0a:a0:d2:e0:c2:64:0c:1e:40:3f:5d:c5:4e:42:ba:
7c:fd:59:0a:24:d0:ad:a9:ce:02:9d:c3:94:65:93:4d:6b:05:
57:25:b9:91:57:d0:f5:d8:92:64:ec:89:67:d1:62:b7:95:cc:
d9:7d
-----BEGIN CERTIFICATE-----
MIID9zCCA2CgAwIBAgIBADANBgkqhkiG9w0BAQQFADCBtDELMAkGA1UEBhMCTlox
EzARBgNVBAcTCldlbGxpbmd0b24xPDA6BgNVBAoTM1JlYWxseSBJcnJlc3BvbnNp
YmxlIEF1dGhvcmlzYXRpb24gQXV0aG9yaXR5IChSSUFBKTEWMBQGA1UECxMNQ2Vy
dC1zdGFtcGluZzEZMBcGA1UEAxMQSmFja292IGFsLVRyYWRlczEfMB0GCSqGSIb3
DQEJARYQbm9uZUBmYWtlLmRvbWFpbjAeFw0wMjAxMTYwNTA5NTlaFw0xMjAxMTQw
NTA5NTlaMIG0MQswCQYDVQQGEwJOWjETMBEGA1UEBxMKV2VsbGluZ3RvbjE8MDoG
A1UEChMzUmVhbGx5IElycmVzcG9uc2libGUgQXV0aG9yaXNhdGlvbiBBdXRob3Jp
dHkgKFJJQUEpMRYwFAYDVQQLEw1DZXJ0LXN0YW1waW5nMRkwFwYDVQQDExBKYWNr
b3YgYWwtVHJhZGVzMR8wHQYJKoZIhvcNAQkBFhBub25lQGZha2UuZG9tYWluMIGf
MA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC7QdDfFIrJn3X24hKmpkyk3TG0Ivxd
K2wWmDPXq1wjr8lUTwrA6hM5Ba9N36jLieWpXhviLOWu9DBza5GmtgCuXloATKTC
94xOdKHlciTVujG3wDlLDB5e710Kar84nnj6VueL1RyZ0bmP5PANa4mbGW9Tqc7J
CkBTTW2y9d0SgQIDAQABo4IBFTCCAREwHQYDVR0OBBYEFEn7RXISxMzhRaHTCJ6V
xCxtVT8XMIHhBgNVHSMEgdkwgdaAFEn7RXISxMzhRaHTCJ6VxCxtVT8XoYG6pIG3
MIG0MQswCQYDVQQGEwJOWjETMBEGA1UEBxMKV2VsbGluZ3RvbjE8MDoGA1UEChMz
UmVhbGx5IElycmVzcG9uc2libGUgQXV0aG9yaXNhdGlvbiBBdXRob3JpdHkgKFJJ
QUEpMRYwFAYDVQQLEw1DZXJ0LXN0YW1waW5nMRkwFwYDVQQDExBKYWNrb3YgYWwt
VHJhZGVzMR8wHQYJKoZIhvcNAQkBFhBub25lQGZha2UuZG9tYWluggEAMAwGA1Ud
EwQFMAMBAf8wDQYJKoZIhvcNAQEEBQADgYEAYQo95V/NY+eKxYxkhibZiUQygph+
gTfgbDG20MsnH6+8//w5ArHauFCgDrf0P2VyACgq+N4pBTWFGaAaLwbjKy9HCe2E
j9C91tO1CqDS4MJkDB5AP13FTkK6fP1ZCiTQranOAp3DlGWTTWsFVyW5kVfQ9diS
ZOyJZ9Fit5XM2X0=
-----END CERTIFICATE-----
# /etc/init.d/ldap restart
Stopping slapd: [ OK ]
Checking configuration files for slapd: config file testing succeeded
Starting slapd: [ OK ]
I then tried to ssh in using the ldap only test user and got the same
error:
Permission denied, please try again.
Other ideas?
>
> >> That's an interesting error, which I've never seen before. Can you print
> >> out the text information of the cert the ldap server is using?
> >
> >
> > Any general user can see certificate /etc/openldap/cacerts/CA.pem.
> >
> > I figured you weren't asking for the cert it is using.
> > I tried using openssl ca to get key ifno.
>
> openssl x509 -text -in <cert>
>
> For example:
>
> openssl x509 -text -in ca.pem
>
> > More sleuthing info would be very helpful here.
> >
> > Thank you, Quanah for helping me gain knowledge and insight here.
>
> np. :)
>
> --Quanah
>
> --
>
> Quanah Gibson-Mount
> Principal Software Engineer
> Zimbra, Inc
> --------------------
> Zimbra :: the leader in open source messaging and collaboration
---
You are currently subscribed to [EMAIL PROTECTED] as: [EMAIL PROTECTED]
To unsubscribe send email to [EMAIL PROTECTED] with the word UNSUBSCRIBE as the
SUBJECT of the message.