[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: TLS headache



Dave Lewney wrote:
> This does not look correct to me ...
> 
>  > TLSCertificateFile /usr/local/openldap/etc/openldap/slapd.pem
>  > TLSCACertificateFile /usr/local/openldap/etc/openldap/slapd.pem
> 
> ie. your server certificate is the same as the CA you signed it with!

As far as I know it's a valid configuration since a self-issued 
certificate the subject (slapd.pem) and the issuer (slapd.pem)
are the same.

-- 
-----BEGIN GEEK CODE BLOCK-----
Version: 3.1
GCS/IT d- s+:+() a- C+++ UBL+++$ P+ L+++ E--- W++ N+ o++ K- w---
O+ M+ V- PS+ PE+ Y++ PGP+>+++ t+ 5 X+$ R- tv-- b+++ DI D++>+++
G++ e- h+(++) !r !z
------END GEEK CODE BLOCK------