Re: [389-users] replication with ssl

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 05/18/2011 10:28 AM, solarflow99 wrote:
This is the latest: 389-ds-base-1.2.8.2-1.el5  I think its something simple, since I have it working, but just not over startTLS on port 389.  When I change the replication agreement to: use StartTLS, the replication status shows:  LDAP error: Protocol Error. Error code: 2

The docs didn't say much about this, can't dirsrv use default certs from /etc/pki like apache ssl and ssh use for this? 
No.  389 doesn't use the nsspem module that reads openssl/pem style cert files/directories like apache mod_ssl and others.

See http://directory.fedoraproject.org/wiki/Howto:SSL and http://docs.redhat.com/docs/en-US/Red_Hat_Directory_Server/8.2/html-single/Administration_Guide/index.html#Managing_SSL and


Thanks,


On Wed, May 18, 2011 at 11:26 AM, Rich Megginson <rmeggins@xxxxxxxxxx> wrote:
On 05/18/2011 08:35 AM, solarflow99 wrote:
I just wonder why i'm getting: RESULT err=2 when I try to use replication over simple SSL.  The replication agreement works when I use ldap with no encryption, but when I select SSL encryption with ldap it just gives that error.  I'm not looking to use certificates, just simple bind DN/password.
What platform?  What version of 389-ds-base?  What does it say in the errors log?
What replication configuration did you do to use SSL?
Have you installed the CA cert?
 

-- 389 users mailing list 389-users@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/389-users


-- 389 users mailing list 389-users@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/389-users

--
389 users mailing list
389-users@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/389-users

[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux