Issue 5360 - wrong default for TLSVerifyClient (with GnuTLS?)
Summary: wrong default for TLSVerifyClient (with GnuTLS?)
Status: VERIFIED FIXED
Alias: None
Product: OpenLDAP
Classification: Unclassified
Component: slapd (show other issues)
Version: 2.4.7
Hardware: All All
: --- normal
Target Milestone: ---
Assignee: OpenLDAP project
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2008-02-09 02:27 UTC by vorlon@debian.org
Modified: 2014-08-01 21:04 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this issue.
Description vorlon@debian.org 2008-02-09 02:27:03 UTC
Full_Name: Steve Langasek
Version: 2.4.7
OS: Debian
URL: http://people.ubuntu.com/~vorlon/slapd-tlsverifyclient-default.patch
Submission from: (NULL) (2001:4830:1244:0:219:d2ff:fe76:2acb)


The code in slapd whose purpose is to override the library default value for
LDAP_OPT_X_TLS_REQUIRE_CERT is failing, at least when OpenLDAP is built with
GnuTLS, because the override is done to a set of "global" options which are
never used.

The patch referenced below has been verified to fix this issue.

Comment 1 Howard Chu 2008-02-10 05:30:55 UTC
changed notes
changed state Open to Feedback
moved from Incoming to Software Bugs
Comment 2 Howard Chu 2008-02-10 05:32:44 UTC
steve.langasek@canonical.com wrote:
> Full_Name: Steve Langasek
> Version: 2.4.7
> OS: Debian
> URL: http://people.ubuntu.com/~vorlon/slapd-tlsverifyclient-default.patch
> Submission from: (NULL) (2001:4830:1244:0:219:d2ff:fe76:2acb)
>
>
> The code in slapd whose purpose is to override the library default value for
> LDAP_OPT_X_TLS_REQUIRE_CERT is failing, at least when OpenLDAP is built with
> GnuTLS, because the override is done to a set of "global" options which are
> never used.
>
> The patch referenced below has been verified to fix this issue.

Thanks for the patch, committed to HEAD.

-- 
   -- Howard Chu
   Chief Architect, Symas Corp.  http://www.symas.com
   Director, Highland Sun        http://highlandsun.com/hyc/
   Chief Architect, OpenLDAP     http://www.openldap.org/project/

Comment 3 Howard Chu 2008-02-12 17:04:40 UTC
changed state Feedback to Test
Comment 4 Quanah Gibson-Mount 2008-02-12 20:19:06 UTC
changed notes
changed state Test to Release
Comment 5 Quanah Gibson-Mount 2008-02-20 02:35:48 UTC
changed notes
changed state Release to Closed
Comment 6 OpenLDAP project 2014-08-01 21:04:13 UTC
fixed in HEAD
fixed in 2.4.8