using a chain cert with LDAP connector?

Cantor, Scott cantor.2 at osu.edu
Mon Mar 24 14:02:08 EDT 2014


On 3/24/14, 1:54 PM, "Liam Hoekenga" <liamr at umich.edu> wrote:
>
>Looks like I need one file with all of the certs in the chain (the cert
>for the LDAP server, intermediary CA, and the top level root CA).

That would mean the LDAP server is misconfigured, and it's also dangerous
because it means you're trusting things inadvertently below the root
(which if that's the intent, should mean you should directly trust the
end-entity cert alone).

-- Scott




More information about the users mailing list