GQ to LDAP on FC1

Patrick Nelson pnelson at neatech.com
Mon Apr 19 19:36:32 UTC 2004


On Mon, 2004-04-19 at 08:47, Nigel Wade wrote:
> I don't know anything about gq, but if it uses openldap then that has 
> changed in version 2.1 (which is what FC1 ships with) such that the default 
> action is to verify the server CA chain. If your server cert. isn't signed 
> by a trusted CA then this verify will fail with the above error.
> 
> You can change the default action for openldap in /etc/ldap.conf by adding 
> the line:
> 
> tls_reqcert allow

Yes this is self-signed cert.  However, adding the above line didn't
change outcome.  It still errors with the same message.  I am able to
use ldap tools on FC1 with TLS...





More information about the fedora-list mailing list