[Date Prev][Date Next]
Re: start_tls: connect error
Howard Chu wrote:
> Dieter Kluenter wrote:
>> I just wonder whether this is a bug in openSSL or in openLDAP, anyhow
>> the subjectAltName attribute values are nor honoured.
>> ldapwhoami -Y EXTERNAL -ZZ -H ldap://localhost
>> ldap_start_tls: Connect error (-11)
>> additional info: TLS: hostname does not match CN in peer certificate
>> openssl x509 -in cert.pem -noout -text
>> Subject: C=DE, L=Hamburg, O=AVCI, OU=Certificate Authority, CN=rubin.avci.de/emailAddressemail@example.com
>> X509v3 Subject Alternative Name:
>> DNS:localhost, DNS:ldap.xxxx.de, DNS:dkluenter.xxxx.org
>> Not to mention that this is OK with other versions of openldap and
> Show the output with debugging enabled. Note that "localhost" is treated
> specially, and will be replaced by the local hostname instead of being used
> directly in the name comparison.
Why that? I strongly dislike automagic things when doing security checks.