<HTML>
<HEAD>
<TITLE>Re: [389-users] SubjectAltName MMR question</TITLE>
</HEAD>
<BODY>
<FONT FACE="Calibri, Verdana, Helvetica, Arial"><SPAN STYLE='font-size:11pt'>Rich,<BR>
<BR>
I specify the individual host’s FQDN in the replication agreement. I use haproxy for LB, so the hosts are in ACTIVE-PASSIVE state.<BR>
<BR>
<BR>
Prashanth Sundaram wrote:<BR>
</SPAN></FONT><BLOCKQUOTE><FONT FACE="Calibri, Verdana, Helvetica, Arial"><SPAN STYLE='font-size:11pt'>Hi All,<BR>
<BR>
</SPAN></FONT><FONT SIZE="2"><FONT FACE="Consolas, Courier New, Courier"><SPAN STYLE='font-size:10pt'>Which one of the case below is suitable for a Multi-Master replication. I have a load balancer with/ ldap.domain.com,/ which is what clients will use to authenticate. <BR>
</SPAN></FONT></FONT><FONT FACE="Calibri, Verdana, Helvetica, Arial"><SPAN STYLE='font-size:11pt'><BR>
*_Question:<BR>
</SPAN></FONT><FONT SIZE="2"><FONT FACE="Consolas, Courier New, Courier"><SPAN STYLE='font-size:10pt'>_*Which one is a better implementation? What are the trade-offs? Please input your feedback as it might be useful for someone coming this way later. This can serve as a knowledge bank. <BR>
</SPAN></FONT></FONT><FONT FACE="Calibri, Verdana, Helvetica, Arial"><SPAN STYLE='font-size:11pt'><BR>
Case-I<BR>
ldap01: server-cert with cn=ldap01.domain.com, subjAltName=ldap.domain.com<BR>
ldap02: server-cert with cn=ldap02.domain.com, subjAltName=ldap.domain.com<BR>
</SPAN></FONT><FONT SIZE="2"><FONT FACE="Consolas, Courier New, Courier"><SPAN STYLE='font-size:10pt'>-MMR with tls throws error when “*Check hostname against name in certificate for outbound SSL connections”* option is enabled. But RH recommends it to be turned ON. <BR>
</SPAN></FONT></FONT></BLOCKQUOTE><FONT FACE="Calibri, Verdana, Helvetica, Arial"><SPAN STYLE='font-size:11pt'>What is the FQDN you specified in the replication agreement?<BR>
</SPAN></FONT><BLOCKQUOTE><FONT FACE="Calibri, Verdana, Helvetica, Arial"><SPAN STYLE='font-size:11pt'><BR>
Case-II<BR>
</SPAN></FONT><FONT SIZE="2"><FONT FACE="Consolas, Courier New, Courier"><SPAN STYLE='font-size:10pt'>ldap01: server-cert with cn=ldap.domain.com, subjAltName=ldap01.domain.com, ldap02.domain.com ldap01: server-cert with cn=ldap.domain.com, subjAltName=ldap01.domain.com,ldap02.domain.com -Does not comply with the requirement that “server-cert” should have hostname as cn.I found this method working perfectly fine. <BR>
</SPAN></FONT></FONT><FONT FACE="Calibri, Verdana, Helvetica, Arial"><SPAN STYLE='font-size:11pt'><BR>
*Knowledge Sharing:<BR>
</SPAN></FONT><FONT SIZE="2"><FONT FACE="Consolas, Courier New, Courier"><SPAN STYLE='font-size:10pt'>*Here’s a useful link which I use all the time and look before posting to the list. This is the archive for the mailing list and has /search/ feature which very useful. <BR>
</SPAN></FONT></FONT><FONT FACE="Calibri, Verdana, Helvetica, Arial"><SPAN STYLE='font-size:11pt'><BR>
<a href="http://www.mail-archive.com/fedora-directory-users">http://www.mail-archive.com/fedora-directory-users</a> redhat com/info.html<BR>
------------------------------------------------------------------------<BR>
<BR>
--<BR>
389 users mailing list<BR>
389-users redhat com<BR>
<a href="https://www.redhat.com/mailman/listinfo/fedora-directory-users">https://www.redhat.com/mailman/listinfo/fedora-directory-users</a><BR>
</SPAN></FONT><FONT SIZE="2"><FONT FACE="Consolas, Courier New, Courier"><SPAN STYLE='font-size:10pt'>  <BR>
</SPAN></FONT></FONT></BLOCKQUOTE><FONT FACE="Calibri, Verdana, Helvetica, Arial"><SPAN STYLE='font-size:11pt'><BR>
<HR ALIGN=CENTER SIZE="3" WIDTH="100%">[Date Prev <<a href="https://www.redhat.com/archives/fedora-directory-users/2010-January/msg00006.html">https://www.redhat.com/archives/fedora-directory-users/2010-January/msg00006.html</a>> ][Date Next <<a href="https://www.redhat.com/archives/fedora-directory-users/2010-January/msg00008.html">https://www.redhat.com/archives/fedora-directory-users/2010-January/msg00008.html</a>> ]   [Thread Prev <<a href="https://www.redhat.com/archives/fedora-directory-users/2010-January/msg00006.html">https://www.redhat.com/archives/fedora-directory-users/2010-January/msg00006.html</a>> ][Thread Next <<a href="https://www.redhat.com/archives/fedora-directory-users/2010-January/msg00008.html">https://www.redhat.com/archives/fedora-directory-users/2010-January/msg00008.html</a>> ]   [Thread Index <<a href="https://www.redhat.com/archives/fedora-directory-users/2010-January/thread.html#00007">https://www.redhat.com/archives/fedora-directory-users/2010-January/thread.html#00007</a>> ] [Date Index <<a href="https://www.redhat.com/archives/fedora-directory-users/2010-January/date.html#00007">https://www.redhat.com/archives/fedora-directory-users/2010-January/date.html#00007</a>> ] [Author Index <<a href="https://www.redhat.com/archives/fedora-directory-users/2010-January/author.html#00007">https://www.redhat.com/archives/fedora-directory-users/2010-January/author.html#00007</a>> ]</SPAN></FONT>
</BODY>
</HTML>