sasl encryption not supported over ssl error

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Yu Joe wrote:

> Dear all
>
> I tried to make my FDS work with sasl(digest-md5)+SSL.  I can get 
> correct result by "ldapsearch -Y digest-md5 -U sasl1 ..." or 
> "ldapsearch -x -D 'cn=Directory Manager' -W -H 
> ldaps://rhds.example.com...".
> But I got the error message such as "*sasl encryption not supported 
> over ssl"*, when I execute command like "ldapsearch -Y digest-md5 -U 
> sasl1 -H ldaps://rhds.example.com ...". Some of my friends tell me  
> this works on openldap. So I suggest it must be also working on FDS. 
> Is that right? If so, what's the probably reason causes this error? Or 
> it just really don't support? Please helps, thanks a lot.

No, it really doesn't work. But why are you wanting both SSL and SASL 
privacy ?

For the curious, the way the SSL I/O is layered in the server is not 
compatible with
the implementation of SASL encryption (they're both trying to layer at 
the same place
in the I/O stack). With sufficient motivation I suspect that SASL over 
SSL could be done,
but the question is why would anyone want to do that..

Perhaps all you need to do is to turn off SASL payload encryption. SASL 
authentication
with an SSL connection should work ok.





[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux