SSL/TLS hell

From: Steve (nospam_at_nopes)
Date: 04/23/04


Date: Fri, 23 Apr 2004 11:50:15 +1000

Hi,

I apologize for being ignorant but can someone please exlpain to me how
TLS/SSL certificates are supposed to work (in simple words)? We have a
remote LDAP server to which I successfully got connected to without
using SSL/TLS. However, since everything's being sent as clear text, I
was hoping to use TLS for authentication. I tried ldapsearch with -Z and
this is what I got:

"additional info: error:14090086:SSL
routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed"

After fooling around with the ldap.conf file, now I only get a:
ldap_bind: Can't contact LDAP server (81), even if I specify the "-v"
flag. Anyway, it can't seem to bind to the server. Then after reading a
few hundred articles on this, everyone seems to say that I need to have
a certificate with the CN set to the hostname I'm trying to connect to,
for example "myldap.server.com". Now my question is, do I generate a
certificate myself, signing it myself and setting CN to
myladp.server.com? That doesn't seem right to me.. does this instead
mean that I get a the public key/certificate that's on the LDAP server
and copy it to some directory on my box? Please, can anyone explain this
to me in simple words because I'm very confused right now.

thanks,

Steve



Relevant Pages

  • SSL/TLS hell
    ... TLS/SSL certificates are supposed to work? ... remote LDAP server to which I successfully got connected to without ... Can't contact LDAP server, even if I specify the "-v" ... a certificate with the CN set to the hostname I'm trying to connect to, ...
    (comp.unix.programmer)
  • Generate a Self-Signed Certificate for LDAP server.
    ... I have problem to set up ssl for LDAP server. ... These are the steps for generate a Self-Signed Certificate for LDAP server. ...
    (comp.unix.solaris)
  • Re: I need help with LDAP and Evolution
    ... > What I did to solve the problem was to download the CA certificate from ... > method for creating the checksum symlinks, but I don't know it off the ... And I succeeded in connecting, updating the ldap server on my LOCALHOST, ...
    (Fedora)
  • Re: Windows 2003 with third partu CA
    ... >> Now I need to use an external CA for authentication based on SUN Solaris ... >> I have added the CDP point in the proprieties of the CA as LDAP server ... >> How can I tel Windows 2003 to use an external LDAP server for checking ... >> revocation of the Certificate? ...
    (microsoft.public.windows.server.security)