[Date Prev][Date Next] [Chronological] [Thread] [Top]

RE: Error in certificate



The openssl verify command doesn't fully validate a certificate; its result
is relatively useless. Run both slapd and ldapsearch with "-d7" debug and see
what error messages are shown. This error was generated by the OpenSSL
library, not by OpenLDAP.

  -- Howard Chu
  Chief Architect, Symas Corp.       Director, Highland Sun
  http://www.symas.com               http://highlandsun.com/hyc
  Symas: Premier OpenSource Development and Support

> -----Original Message-----
> From: owner-openldap-software@OpenLDAP.org
> [mailto:owner-openldap-software@OpenLDAP.org]On Behalf Of François
> Beretti

> PS: here is my log on the server :
>
> 	conn=0 fd=12 ACCEPT from IP=10.10.50.6:1423 (IP=0.0.0.0:389)
> 	TLS certificate verification: Error, Unknown error
> 	conn=0 fd=12 closed
>
>
> and on the client :
>
> 	debian-ldap:/etc/ldap# ldapsearch -Z -x -d 256
> 	request 1 done
> 	TLS certificate verification: Error, Unknown error
> 	TLS: can't connect.
> 	ldap_start_tls: Connect error (91)
> 	        additional info: Error in the certificate.
> 	ldap_bind: Can't contact LDAP server (81)
> 	        additional info: Error in the certificate.
>
>
> ____________
> Virus checked by G DATA AntiVirusKit
> Version: AVK 12.0.575 from 10.09.2003
> Virus news: www.antiviruslab.com
>
>
>