Re: SSL certificates, kerberos keytabs, and load balancing

Quanah Gibson-Mount wrote:

For various reasons, I cannot use self-signed certs on our production servers, or I'd just go that route.

How about running your own CA for issuing SSL certs for the LDAP servers? A couple of shell scripts will do most times. Note: Usually you don't need the CA certs being present in every web browser.

Or maybe you're using the term "self-signed certs" equal to "own SSL CA"?

Ciao, Michael.