Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

ldap.conf question

Posted on 2014-09-09
1
Medium Priority
?
182 Views
Last Modified: 2014-09-10
I have the following ldap.conf

#
# LDAP Defaults
#

# See ldap.conf(5) for details
# This file should be world readable but not world writable.

BASE    dc=example,dc=com
URI     ldap://127.0.0.1 ldap://127.0.0.1:666

#SIZELIMIT      12
#TIMELIMIT      15
#DEREF          never

TLS_CACERTDIR   /etc/openldap/certs

Open in new window


This is a slightly modified version of what came with the openldap.  on the line

URI     ldap://127.0.0.1 ldap://127.0.0.1:666

Open in new window


I assume the second ldap: entry is normatively the ssl entry.

If so shouldn't it be the following ?

URI     ldap://127.0.0.1 ldaps://127.0.0.1:636

Open in new window


Or am I getting this wrong

Thanks
0
Comment
Question by:Anthony Lucia
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 3

Accepted Solution

by:
CraigFrost earned 2000 total points
ID: 40313900
Not sure what your issue is but:
Port 636 is LDAP over SSL (LDAPS) , port 389 is LDAP.
TLS_CACERTDIR   /etc/openldap/certs will be where your certificate is installed that would be presented to a client if they connect to your server over port 636. The root cert will need to be installed on the client in the trusted root authority store. Certificate details (expiration, DNS name and if trusted) will need to be correct.
Base is the parent OU in the DS tree that LDAP(s) searches will begin from.
Auth credentials may be required also.
0

Featured Post

Survive A High-Traffic Event with Percona

Your application or website rely on your database to deliver information about products and services to your customers. You can’t afford to have your database lose performance, lose availability or become unresponsive – even for just a few minutes.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Attention: This article will no longer be maintained. If you have any questions, please feel free to mail me. jgh@FreeBSD.org Please see http://www.freebsd.org/doc/en_US.ISO8859-1/articles/freebsd-update-server/ for the updated article. It is avail…
In part one, we reviewed the prerequisites required for installing SQL Server vNext. In this part we will explore how to install Microsoft's SQL Server on Ubuntu 16.04.
Learn how to get help with Linux/Unix bash shell commands. Use help to read help documents for built in bash shell commands.: Use man to interface with the online reference manuals for shell commands.: Use man to search man pages for unknown command…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.
Suggested Courses

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question