Bug#514578: libgnutls26: LDAP STARTTLS is broken

2009-02-09 Thread Gábor Gombás
Package: libgnutls26 Version: 2.4.2-5 Severity: important Hi, After upgrading to libgnutls26 2.4.2-5, LDAP authentication fails (including ldap-utils, libnss-ldap and apache's mod_authnz_ldap). The error message from ldapsearch ends with: TLS: peer cert untrusted or revoked (0x102)

Bug#514578: libgnutls26: LDAP STARTTLS is broken

2009-02-09 Thread Simon Josefsson
Gábor Gombás gomb...@sztaki.hu writes: Package: libgnutls26 Version: 2.4.2-5 Severity: important Hi, After upgrading to libgnutls26 2.4.2-5, LDAP authentication fails (including ldap-utils, libnss-ldap and apache's mod_authnz_ldap). The error message from ldapsearch ends with:

Bug#514578: libgnutls26: LDAP STARTTLS is broken

2009-02-09 Thread Gabor Gombas
On Mon, Feb 09, 2009 at 01:40:59PM +0100, Simon Josefsson wrote: Please provide output from: gnutls-cli -p 663 your.ldap.server -d 4711 --print-cert Here it is: |3| HSK[8a6c0b8]: Keeping ciphersuite: DHE_RSA_AES_128_CBC_SHA1 |3| HSK[8a6c0b8]: Keeping ciphersuite:

Bug#514578: libgnutls26: LDAP STARTTLS is broken

2009-02-09 Thread Simon Josefsson
On Mon, 2009-02-09 at 16:48 +0100, Gabor Gombas wrote: On Mon, Feb 09, 2009 at 01:40:59PM +0100, Simon Josefsson wrote: Please provide output from: gnutls-cli -p 663 your.ldap.server -d 4711 --print-cert Here it is: Thanks. The server certificate is signed using RSA-MD5 so the