LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise
User Name
Password
Linux - Enterprise This forum is for all items relating to using Linux in the Enterprise.

Notices


Reply
  Search this Thread
Old 12-02-2015, 08:25 AM   #1
CliffordTrueman
LQ Newbie
 
Registered: Jun 2009
Posts: 11

Rep: Reputation: 0
Openldap TLS 'can't trust cert' issue (self signed)


So I've set up a openldap on centos 6, and it works but I have yet to get it successfully login over the SSL/TLS port 636

running this command:

Code:
 ldapsearch -d1 -x -LLL -b cn=root -D "cn=Manager,dc=example,dc=lab,dc=net"   -H "ldaps://localhost:636" -W cn=config
it returns a connect success

but returns this error about the cert,

Code:
TLS: error: connect - force handshake failure: errno 22 - moznss error -8172
TLS: can't connect: TLS error -8172:Peer's certificate issuer has been marked as not trusted by the user..
So it seems to be finding the cert, I've double checked all the perms and played around with those for a bit, but no matter what method it doesn't seem to like a self signed cert.


I followed this to setup the cert and the dirs.

http://www.server-world.info/en/note?os=CentOS_6&p=ssl
 
  


Reply

Tags
certificates, ldap, ssl authentication, tls


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Some questions about OpenSSL self-signed CA cert j9678 Linux - Security 9 06-10-2015 07:37 PM
[SOLVED] Checking self signed cert on apache mattydee Linux - Security 1 05-02-2015 05:53 PM
[SOLVED] Ubuntu OpenLDAP self-signed cert woes hippie131 Linux - Server 2 06-11-2014 03:24 AM
[SOLVED] Centos 6.4 with OpenLDAP+TLS: OpenLDAP ok, add TLS =>not ok chrism01 Linux - Server 2 10-27-2013 03:15 PM
Error: Can't read cert file /etc/pki/tls/certs/cert.pem in Twiki jsaravana87 Linux - Server 1 09-09-2011 06:01 PM

LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise

All times are GMT -5. The time now is 03:19 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration