Configure LDAP clients

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Rusch Philipp pru09 wrote:
> Hello all,
> 
>  
> 
> my last try to move on with the SSL certificates. I have installed 
> fedora-ds 1.0.4 and have used the setupssl.sh script to generate the 
> certificates on my both servers. After that I jumped tot he ?configure 
> ldap clients? section and there it says: ?If you have more than 1 CA 
> cert, you will have to concatenate them into a single file.?
> 
>  
> 
> Can anyone tell me how I have to concatenate the two cacert.asc files? I 
> have tried several things without any result (e.g cat cacert1.asc 
> cacert2.asc > cacert.asc). Only the first certificate is used to 
> establish a new tls connection.
> 
>  
> 
> I woul appreciate any help about this problem!
> 
>  
> 
> Thank you in advance.
> 
>

This is just an educated guess but if you ran setupssl.sh twice and 
didn't change anything then you have 2 Certificate Authorities with the 
same subject and same serial number just different signing keys. My 
guess is this is confusing the heck out of openssl. I'm not sure using 
TLS_CACERTDIR would change anything either.

Ideally you would create just 1 CA and use that to generate the server 
certs for your FDS installation. How to do this isn't particularly 
obvious though. You'd have to poke at the setupssl.sh script to see how 
the Server-Cert is being issued and generate a new CSR and get the CA to 
sign it.

Something simpler/quicker to try would be to modify the subject and CA 
name in setupssl.sh on one of the FDS servers and try again. The subject 
is set by the -s argument to certutil (e.g. cn=CAcert).

rob




[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux