[389-users] FDS cert check

Emmanuel BILLOT emmanuel.billot at ird.fr
Sun May 17 19:25:36 UTC 2009


Hi,

I posted a question few weeks ago about cert recognizing when 
replication begions. Indeed it seems that FDS works on SSL when 
replicationg with "fake certs".
Ex : ldap1 replicates with ldap2 on 636 with SSL. Actually the cert used 
by ldap2 to encrypt data must contain the ldap2 DNS name. However, 
replication works even if the DNS name containes in the cert does not 
corresond with the host.

THis particular feature is also present on S1DS. So i thought there is a 
mistake in our configuration...

Is the any option that enforce DNS check on replication. ?

BR,

-- 
==========================================
Emmanuel BILLOT
IRD - Orléans
Délégation aux Systèmes d'Information (DSI)
tél : 02 38 49 95 88
========================================== 




More information about the Fedora-directory-users mailing list