> > > With "export NSS_DISABLE_HW_AES=1" there are no crashes. > > > > > > Hello, > > the certificate is there (in the "-----BEGIN CERTIFICATE-----") > section, I just edited it. Here is the certificate without some > internal information like the DN: > Ahhh okay. I see what happened now. > > I have tried > openssl s_client -connect ldap:636 -tls1_2 - it crashes the server > -tls1 / -tls1_1 is OK > The server is crashing before it can complete the negotiation which is why there is the weird openssl s_client output. So I think that Noriko is onto the correct work around here. I would advise that you leave NSS_DISABLE_HW_GCM=1 set to prevent the crash. -- Sincerely, William Brown Software Engineer Red Hat, Brisbane
Attachment:
signature.asc
Description: This is a digitally signed message part
-- 389 users mailing list 389-users@%(host_name)s http://lists.fedoraproject.org/admin/lists/389-users@xxxxxxxxxxxxxxxxxxxxxxx