> Do you have load balancers in here at all? Or is it just directly > accessible servers? What does the TLS termination? > yes, we use LB and VIPs to avoid any failure. > If you have load balancers/VIP involved, you should set the > nsslapd-referral to the hostname of the load balancer/VIP, rather > than to individual servers, and all certs must have the SAN for the > LB/VIP in them. > > Does that help? > absolutely, thanks for your time. abosch _______________________________________________ 389-users mailing list -- 389-users@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to 389-users-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/389-users@xxxxxxxxxxxxxxxxxxxxxxx