certutil -L -d /etc/dirsrv/slapd-instance certutil -L -d /etc/dirsrv/admin-serv Anand Vaddarapu wrote: > Hi, > > ls -al ~/.fedora-idm-console/ > total 12 > drwxr-xr-x 2 root root 4096 Feb 26 08:46 . > drwxr-x--- 12 root root 4096 Mar 26 16:10 .. > > > certutil -L -d ~/.fedora-idm-console/ > certutil: function failed: security library: bad database. > > Thanks > > > > > On Tue, Apr 1, 2008 at 4:57 AM, Rich Megginson <rmeggins at redhat.com > <mailto:rmeggins at redhat.com>> wrote: > > Anand Vaddarapu wrote: > > Hi, > > > > After enabling SSL with console using the procedure > > > _http://directory.fedoraproject.org/wiki/Howto:SSL#Console_SSL_Information_ > > i am getting these following error messages when i am trying to > login > > into directory server in the console. SSL is enabled in both the > admin > > console & the Ldap server > > > > From logs: > > [27/Mar/2008:14:56:24 +1100] conn=47 fd=66 slot=66 SSL connection > > from 10.50.5.81 <http://10.50.5.81> <http://10.50.5.81> to > 10.50.1.24 <http://10.50.1.24> <http://10.50.1.24> > > [27/Mar/2008:14:56:24 +1100] conn=47 op=-1 fd=66 closed - SSL peer > > cannot verify your certificate. > ls -al ~/.fedora-idm-console > certutil -L -d ~/.fedora-idm-console > > > > we are these when starting the Ldap server > > > > 27/Mar/2008:14:45:04 +1100] - attrcrypt_unwrap_key: failed to unwrap > > key for cipher AES > > [27/Mar/2008:14:45:04 +1100] - Failed to retrieve key for cipher AES > > in attrcrypt_cipher_init > > [27/Mar/2008:14:45:04 +1100] - Failed to initialize cipher AES in > > attrcrypt_init > > [27/Mar/2008:14:45:04 +1100] - attrcrypt_unwrap_key: failed to > unwrap > > key for cipher AES > > [27/Mar/2008:14:45:04 +1100] - Failed to retrieve key for cipher AES > > in attrcrypt_cipher_init > > [27/Mar/2008:14:45:04 +1100] - Failed to initialize cipher AES in > > attrcrypt_init > > [27/Mar/2008:14:45:05 +1100] - slapd started. Listening on All > > Interfaces port 389 for LDAP requests > > [27/Mar/2008:14:45:05 +1100] - Listening on All Interfaces port 636 > > for LDAPS requests > > > > > > > > Console error message: > > > > netscape.ldap.LDAPException:JSSSocketFactory.makeSocket > > devil.wcg.net.au:636 <http://devil.wcg.net.au:636> > <http://devil.wcg.net.au:636>, SSL_ForceHandshake > > failed: (-8054) unknown error (91) > > > > Help Appreciated. > > > > Thanks > > > > > > > > > > > > > > > ------------------------------------------------------------------------ > > > > -- > > Fedora-directory-users mailing list > > Fedora-directory-users at redhat.com > <mailto:Fedora-directory-users at redhat.com> > > https://www.redhat.com/mailman/listinfo/fedora-directory-users > > > > > -- > Fedora-directory-users mailing list > Fedora-directory-users at redhat.com > <mailto:Fedora-directory-users at redhat.com> > https://www.redhat.com/mailman/listinfo/fedora-directory-users > > > ------------------------------------------------------------------------ > > -- > Fedora-directory-users mailing list > Fedora-directory-users at redhat.com > https://www.redhat.com/mailman/listinfo/fedora-directory-users > -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3245 bytes Desc: S/MIME Cryptographic Signature Url : http://lists.fedoraproject.org/pipermail/389-users/attachments/20080401/0fee8d3e/attachment.bin