Re: Hostname does not match CN

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



> Date: Tue, 04 Apr 2006 11:30:30 -0700
> From: "George Holbert" <gholbert at broadcom.com>
>
>   
>> Does Directory Server support the subjectAltName extension on SSL certs?
>>   
>>     
>
> Yes, the NSS toolkit which Directory Server uses can handle these certs.
>
> The next question is, do your SSL-enabled LDAP clients support these certs?
> I need to support both Solaris and RedHat Linux LDAP name service 
> clients (i.e., passwd, group, automount, etc.).  I've found that:
> - Solaris clients can handle wildcard certs.  RHEL 3 clients can't.
> - RHEL 3 clients can handle subjectAltName certs.  Solaris clients can't.
>
> So, while the server can present either of these cert types, your 
> clients' limitations will also influence how you sign your certs.
>
>   
Someone should file a bug report with Sun then, since LDAP RFC2830 
defines support for subjectAltName and not for wildcard certs. The 
LDAPbis specifications will be pretty much the same here. I.e., Sun's 
LDAP library is not LDAPv3 compliant. RHEL uses OpenLDAP libraries, 
which are fully LDAPv3 compliant.

-- 
  -- Howard Chu
  Chief Architect, Symas Corp.  http://www.symas.com
  Director, Highland Sun        http://highlandsun.com/hyc
  OpenLDAP Core Team            http://www.openldap.org/project/




[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux