[Date Prev][Date Next] [Chronological] [Thread] [Top]

RE: testing ldaps:// w/ client certificates



I have found a couple SEGVs in SASL/EXTERNAL code which I have just fixed.
Is that
what you were referring to? It now works both with ldaps and with StartTLS.

There are some client issues with SASL/EXTERNAL, the SASL library doesn't
seem to
think that EXTERNAL is a sufficiently secure mechanism with the default
secprops.
I think if the connection has TLS then we should be doing something with the
secprops to tell Cyrus that EXTERNAL is acceptable.

  -- Howard Chu
  Chief Architect, Symas Corp.       Director, Highland Sun
  http://www.symas.com               http://highlandsun.com/hyc

> -----Original Message-----
> From: owner-openldap-devel@OpenLDAP.org
> [mailto:owner-openldap-devel@OpenLDAP.org]On Behalf Of Kurt D. Zeilenga

> I'm not setup to test this.  If you are, please test
> HEAD and OPENLDAP_REL_ENG_2 and report any success/failure.
>
> Thanks, Kurt
>