[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: Require use of SSL..



man, 08.03.2004 kl. 07.50 skrev adp:

> And speaking of SSL, I have another issue I'd like to discuss. Okay, when I
> generate a cert I specify the hostname. This locks the SSL cert to that
> hostname. For the LDAP service I am using RRDNS. So I have servers like
> dir1, dir2, dir3, but the service is connected to as dir. So this means when
> I create the cert I need to create it as "dir" and use that cert for dir1,
> dir2, dir3.
> 
> When specifying a replica host I need to specify the real hostname (e.g.,
> dir2). I can't specify dir since this will result in a RRDNS hit which could
> definitely lead to replication failing. (For one thing, you can't replicate
> to yourself.)
> 
> Is there a solution?

subjectAltName will enable different hosts to be sunbject on a single
cert. Edit openssl.cnf after finding out more about it ;)

> How do I handle SSL, replication, and RRDNS at once? Is there a way around
> this?

No idea, I'm afraid ...

--Tonni

-- 

mail: billy - at - billy.demon.nl
http://www.billy.demon.nl