****Re: openldap + kmail

Timothy Murphy gayleard at eircom.net
Wed Apr 30 12:08:24 UTC 2008


Craig White wrote:

>> > When I go to KAddressBook=>Settings=>Configure KAddressBook
>> > and click on LDAP Lookup=>Add Host,
>> > I give my DN as "dc=www,dc=xyz,dc=com".
>> 
>> I found in the end that what was wanted here
>> was the first part of the DN, in my case "DN: Address Book".
>> After giving that, I was able to access my LDAP address book
>> from KMail.

> What you are calling a lack of documentation suggests that you expect
> all the various LDAP client programs to tell you how LDAP works.

I don't think that's fair.
What I am complaining about in this case (I have many complaints ...)
is the LDAP Lookup page in KAddressBook/KMail .
You are asked to give the DN,
but what is actually wanted is the first part of the DN, not the DN proper.
But it is quite possible that I misunderstand what is meant by DN.
I assume that it means the unique identifier in each LDAP entry,
in which case it is inaccurate to describe the first part of this
("Address Book" in my case) as the "DN".

>> This is all with Security: No .
>> To complete my homework, I'm trying to make sense of openldap + TLS.

> The way I do it is:
> 1 - set up my own CA
> 2 - generate and sign various client certs for applications
> 3 - assign the client certs to each various application (like
> slapd.conf)

Thanks. I thought that was what I did,
but I'll have another look at it.






More information about the fedora-list mailing list