[389-users] Re: Clarification - is this certmap.conf file correct?

2020-11-17 Thread William Brown
> On 18 Nov 2020, at 11:45, Marc Sauton wrote: > > and add a > default:DNCompscn > to match the DN components > ? > That changes the search basedn, not the matched dn or attribute content. I think they want to put the cert subject in nsCertSubjectDN and search all BE's, especially

[389-users] Re: Clarification - is this certmap.conf file correct?

2020-11-17 Thread Marc Sauton
and add a default:DNCompscn to match the DN components ? On Tue, Nov 17, 2020 at 5:35 PM William Brown wrote: > > > > > Something missing from the documentation is the DN format expected by > the nsCertSubjectDN attribute. > > > > Is the format CN=X,serialNumber=Y as reported by openssl

[389-users] Re: Clarification - is this certmap.conf file correct?

2020-11-17 Thread William Brown
> > Something missing from the documentation is the DN format expected by the > nsCertSubjectDN attribute. > > Is the format CN=X,serialNumber=Y as reported by openssl x509, or is it > serialNumber=Y,CN=X as reported by the log message above? I seem to recall a few years back, some changes