Solved

ldap.conf question

Posted on 2014-09-09
1
165 Views
Last Modified: 2014-09-10
I have the following ldap.conf

#
# LDAP Defaults
#

# See ldap.conf(5) for details
# This file should be world readable but not world writable.

BASE    dc=example,dc=com
URI     ldap://127.0.0.1 ldap://127.0.0.1:666

#SIZELIMIT      12
#TIMELIMIT      15
#DEREF          never

TLS_CACERTDIR   /etc/openldap/certs

Open in new window


This is a slightly modified version of what came with the openldap.  on the line

URI     ldap://127.0.0.1 ldap://127.0.0.1:666

Open in new window


I assume the second ldap: entry is normatively the ssl entry.

If so shouldn't it be the following ?

URI     ldap://127.0.0.1 ldaps://127.0.0.1:636

Open in new window


Or am I getting this wrong

Thanks
0
Comment
Question by:Anthony Lucia
1 Comment
 
LVL 3

Accepted Solution

by:
CraigFrost earned 500 total points
ID: 40313900
Not sure what your issue is but:
Port 636 is LDAP over SSL (LDAPS) , port 389 is LDAP.
TLS_CACERTDIR   /etc/openldap/certs will be where your certificate is installed that would be presented to a client if they connect to your server over port 636. The root cert will need to be installed on the client in the trusted root authority store. Certificate details (expiration, DNS name and if trusted) will need to be correct.
Base is the parent OU in the DS tree that LDAP(s) searches will begin from.
Auth credentials may be required also.
0

Featured Post

Master Your Team's Linux and Cloud Stack!

The average business loses $13.5M per year to ineffective training (per 1,000 employees). Keep ahead of the competition and combine in-person quality with online cost and flexibility by training with Linux Academy.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Setting up Secure Ubuntu server on VMware 1.      Insert the Ubuntu Server distribution CD or attach the ISO of the CD which is in the “Datastore”. Note that it is important to install the x64 edition on servers, not the X86 editions. 2.      Power on th…
It’s 2016. Password authentication should be dead — or at least close to dying. But, unfortunately, it has not traversed Quagga stage yet. Using password authentication is like laundering hotel guest linens with a washboard — it’s Passé.
Learn several ways to interact with files and get file information from the bash shell. ls lists the contents of a directory: Using the -a flag displays hidden files: Using the -l flag formats the output in a long list: The file command gives us mor…
Connecting to an Amazon Linux EC2 Instance from Windows Using PuTTY.

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question