Re: LDAP over SSL ( ldaps )

Anyone there? Please help me getting out of this problem

this is my /etc/ldap/ldap.conf file:

BASE    dc=platalytics,dc=com

TLS_CACERT      /etc/ldap/cacert.pem

Still i get following error:

modifying entry "cn=config"
ldap_result: Can't contact LDAP server (-1)

I get following result 

ldap_initialize( ldap://localhost:389/??base )
Result: Success (0)

When i add below file i.e., ssl_mod.ldif

dn: cn=config
changetype: modify
add: olcTLSCACertificateFile
olcTLSCACertificateFile: /etc/ldap/cacert.pem
add: olcTLSCertificateFile
olcTLSCertificateFile: /etc/ldap/servercrt.pem
add: olcTLSCertificateKeyFile
olcTLSCertificateKeyFile: /etc/ldap/serverkey.pem
add: olcTLSCipherSuite
olcTLSCipherSuite: HIGH:MEDIUM:!SSLv3:!SSLv2

using following command:

ldapmodify -h localhost -p 389 -D "cn=admin,cn=config" -w 123 -f mod_ssl.ldif

i get ldap_result: Can't contact LDAP server (-1) error.

Although LDAP is running. I can run following command i.e.,

ldapsearch -h localhost -p 389 -D "cn=admin,dc=platalytics,dc=com" -w 123 -b "dc=platalytics,dc=com" "objectclass=*"

How can i make ldaps work?

Where i can find the logs?

I wrote the above lines in olcDatabase={0}config.ldif file. When i restart slapd it gets failed.

Which file i need to write this in?

I have no slapd.conf. I have cn=conf

Thanks Michael and Abdelkader.

Abdelkaded the link you provided is for slapd.conf distribution. Can you please guide me how to do "cn=config" distribution?

Can anyone please provide me some link for enabling "ldaps"

Ciao, Michael.

or http://www.openldap.org/faq/data/cache/185.html


You can convert a slapd.conf to cn=config using slaptest

slaptest -f path/to/slapd.conf -F path/to/slapd.d

# cn=config
dn: cn=config
objectClass: olcGlobal
cn: config
olcTLSCACertificateFile: /path/to/cacert
olcTLSCertificateFile: /path/to/cert
olcTLSCertificateKeyFile: /path/to/key
olcTLSCipherSuite: HIGH:MEDIUM:!SSLv3:!SSLv2

Can you run

ldapwhoami -vxD cn=admin,cn=config -w 123 -H ldap://localhost:389

Ok, retry the "ldapmodify" command using

ldapmodify  -xD cn=admin,cn=config -w 123 -H ldap://localhost:389 -f mod_ssl.ldif

There is something wrong with your setup.

1/ Stops your instance
2/ Exports your configuration

slapcat -F /path/to/slapd.d -n 0 -l config.ldif

3/ Performs the modification directly on config.ldif
4/ Removes the old configuration

rm -rf /path/to/slapd.d/*

5/ Imports the new configuration

slapadd -F /path/to/slapd.d -n 0 -l config.ldif

6/ Starts your instance