Problems connecting to 389 directory server

Darren Boss darren.boss at computecanada.ca
Tue Dec 5 12:05:48 EST 2017


Unfortunately we can not directly implement any changes to the ldap server.
Points two and three have already been tested and I've switched back to
that exact configuration and it's working, but still with the CA in the
JRE's CA bundle.

It's a different IT team outside of our organization that controls the ldap
replica. We can suggest changes but it's at their discretion to make the
changes.

On Tue, Dec 5, 2017 at 11:17 AM Peter Schober <peter.schober at univie.ac.at>
wrote:

> * Darren Boss <darren.boss at computecanada.ca> [2017-12-05 17:12]:
> > Certificate chain
> >  0 s:/C=ca/O=CADC/CN=<redacted>
> >    i:/O=CADC/OU=CADC Internal Root CA
> >  1 s:/O=CADC/OU=CADC Internal Root CA
> >    i:/O=CADC/OU=CADC Internal Root CA
>
> OK, then I'd start with:
>
> * fixing the server to not send the CA root cert (the client has
>   nothing available to verify the root CA as that's self-signed.)
>
> * putting only that CA root cert in
>   %{idp.home}/credentials/CADC_Internal_Root_CA.pem and make that
>   world-readable
>
> * these settings in ldap.properties:
>   idp.authn.LDAP.sslConfig = certificateTrust
>   idp.authn.LDAP.trustCertificates =
> %{idp.home}/credentials/CADC_Internal_Root_CA.pem
>
> That should be all.
> -peter
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-- 

*Darren Boss*
*Senior Programmer/Analyst*
*Programmeur-analyste principal*
*darren.boss at computecanada.ca <darren.boss at computecanada.ca>*
*(o) 416.228.1234 x *230
*(c) 919.525.0083*

155 University Ave, Suite 302 Toronto, ON M5H 3B7
www.computecanada.ca / www.calculcanada.ca
@ComputeCanada
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20171205/28895431/attachment.html>


More information about the users mailing list