[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: pam_ldap debugging



Hallo Andreas,

Andreas Tille, 20.06.2008 (d.m.y):

> /etc/pam_ldap.conf:
>   # OpenLDAP SSL mechanism
>   # start_tls mechanism uses the normal LDAP port, LDAPS typically 636
>   ssl start_tls
>   ssl on
>
> Die letzten beiden Zeilen waren vorher auskommentiert - nun sehen sie wie
> oben aus.  Das führt zu
>
>   pam_ldap: ldap_result Can't contact LDAP server
>   pam_ldap: reconnecting to LDAP server...
>   pam_ldap: ldap_result Can't contact LDAP server
>
> Ich habe noch mal weiter gespielt:
>
>   # OpenLDAP SSL options
>   # Require and verify server certificate (yes/no)
>   # Default is to use libldap's default behavior, which can be configured in
>   # /etc/openldap/ldap.conf using the TLS_REQCERT setting.  The default for
>   # OpenLDAP 2.0 and earlier is "no", for 2.1 and later is "yes".
>   #tls_checkpeer yes
>   tls_checkpeer no

Schau mal in man ldap.conf nach "TLS_CACERT".

Gruss/Regards,
Christian Schmidt

-- 
Your domestic life may be harmonious.

Attachment: signature.asc
Description: Digital signature


Reply to: