Re: SSL/TLS testing

2011-12-15 Thread rey sebastien
Le jeu. 15 déc. 2011 08:51:29 CET, Raffael Sahli a écrit : OK, it's work, i have a fonctionnal slapd.d/cn=config folder, but i don't understand why i can't access to openldap with cn=admin,dc=parisgeo,dc=cnrs,dc=fr and good password generated by My slapd.conf before conversion contain

Re: SSL/TLS testing

2011-12-15 Thread Raffael Sahli
On 12/15/2011 09:46 AM, rey sebastien wrote: Le jeu. 15 déc. 2011 08:51:29 CET, Raffael Sahli a écrit : OK, it's work, i have a fonctionnal slapd.d/cn=config folder, but i don't understand why i can't access to openldap with cn=admin,dc=parisgeo,dc=cnrs,dc=fr and good password generated by

Re: SSL/TLS testing

2011-12-14 Thread rey sebastien
Le 13/12/2011 16:48, Raffael Sahli a écrit : On 12/13/2011 04:34 PM, rey sebastien wrote: Le mar. 13 déc. 2011 15:16:08 CET, Raffael Sahli a écrit : On 12/13/2011 02:59 PM, rey sebastien wrote: Le mar. 13 déc. 2011 13:00:16 CET, Raffael Sahli a écrit : On 12/13/2011 12:14 PM, rey sebastien

Re: SSL/TLS testing

2011-12-14 Thread Raffael Sahli
On 14.12.2011 16:54, rey sebastien wrote: Le 13/12/2011 16:48, Raffael Sahli a écrit : On 12/13/2011 04:34 PM, rey sebastien wrote: Le mar. 13 déc. 2011 15:16:08 CET, Raffael Sahli a écrit : On 12/13/2011 02:59 PM, rey sebastien wrote: Le mar. 13 déc. 2011 13:00:16 CET, Raffael Sahli a écrit

Re: SSL/TLS testing

2011-12-14 Thread rey sebastien
Le mer. 14 déc. 2011 19:39:13 CET, Raffael Sahli a écrit : On 14.12.2011 16:54, rey sebastien wrote: Le 13/12/2011 16:48, Raffael Sahli a écrit : On 12/13/2011 04:34 PM, rey sebastien wrote: Le mar. 13 déc. 2011 15:16:08 CET, Raffael Sahli a écrit : On 12/13/2011 02:59 PM, rey sebastien

Re: SSL/TLS testing

2011-12-14 Thread Howard Chu
Please trim irrelevant text from your emails. Please update your Subject line to something relevant to the actual discussion topic. Raffael Sahli wrote: On 14.12.2011 16:54, rey sebastien wrote: Le 13/12/2011 16:48, Raffael Sahli a écrit : Hi! It's not easy to start with zero configuration

Re: SSL/TLS testing

2011-12-14 Thread Raffael Sahli
OK, it's work, i have a fonctionnal slapd.d/cn=config folder, but i don't understand why i can't access to openldap with cn=admin,dc=parisgeo,dc=cnrs,dc=fr and good password generated by My slapd.conf before conversion contain the SSHA password generated by slappasswd for rootDn : -

Re: SSL/TLS testing

2011-12-13 Thread rey sebastien
After what, you are right, you and other to point the old debian package, so i try to recompile the last release with open-ssl. This is the best solution, i agree. I try to compile with this option : ./configure --with-tls=openssl --with-threads --with-cyrus-sasl --enable-crypt --enable-debug

Re: SSL/TLS testing

2011-12-13 Thread Raffael Sahli
On 12/13/2011 10:12 AM, rey sebastien wrote: After what, you are right, you and other to point the old debian package, so i try to recompile the last release with open-ssl. This is the best solution, i agree. I try to compile with this option : ./configure --with-tls=openssl --with-threads

Re: SSL/TLS testing

2011-12-13 Thread rey sebastien
Le mar. 13 déc. 2011 11:08:43 CET, Raffael Sahli a écrit : On 12/13/2011 10:12 AM, rey sebastien wrote: After what, you are right, you and other to point the old debian package, so i try to recompile the last release with open-ssl. This is the best solution, i agree. I try to compile with

Re: SSL/TLS testing

2011-12-13 Thread Raffael Sahli
On 12/13/2011 12:14 PM, rey sebastien wrote: Le mar. 13 déc. 2011 11:08:43 CET, Raffael Sahli a écrit : On 12/13/2011 10:12 AM, rey sebastien wrote: After what, you are right, you and other to point the old debian package, so i try to recompile the last release with open-ssl. This is the best

Re: SSL/TLS testing

2011-12-13 Thread rey sebastien
Le mar. 13 déc. 2011 13:00:16 CET, Raffael Sahli a écrit : On 12/13/2011 12:14 PM, rey sebastien wrote: Le mar. 13 déc. 2011 11:08:43 CET, Raffael Sahli a écrit : On 12/13/2011 10:12 AM, rey sebastien wrote: After what, you are right, you and other to point the old debian package, so i try to

Re: SSL/TLS testing

2011-12-13 Thread Raffael Sahli
On 12/13/2011 02:59 PM, rey sebastien wrote: Le mar. 13 déc. 2011 13:00:16 CET, Raffael Sahli a écrit : On 12/13/2011 12:14 PM, rey sebastien wrote: Le mar. 13 déc. 2011 11:08:43 CET, Raffael Sahli a écrit : On 12/13/2011 10:12 AM, rey sebastien wrote: After what, you are right, you and other

Re: SSL/TLS testing

2011-12-13 Thread rey sebastien
Le mar. 13 déc. 2011 15:16:08 CET, Raffael Sahli a écrit : On 12/13/2011 02:59 PM, rey sebastien wrote: Le mar. 13 déc. 2011 13:00:16 CET, Raffael Sahli a écrit : On 12/13/2011 12:14 PM, rey sebastien wrote: Le mar. 13 déc. 2011 11:08:43 CET, Raffael Sahli a écrit : On 12/13/2011 10:12 AM,

Re: SSL/TLS testing

2011-12-13 Thread Raffael Sahli
On 12/13/2011 04:34 PM, rey sebastien wrote: Le mar. 13 déc. 2011 15:16:08 CET, Raffael Sahli a écrit : On 12/13/2011 02:59 PM, rey sebastien wrote: Le mar. 13 déc. 2011 13:00:16 CET, Raffael Sahli a écrit : On 12/13/2011 12:14 PM, rey sebastien wrote: Le mar. 13 déc. 2011 11:08:43 CET,

SSL/TLS testing

2011-12-12 Thread Jayavant Patil
Hi, I am using openldap-2.4.19-4.x86_64 on fedora 12 machine. I have enabled openldap SSL/TLS. How do I know (test) that I am using SSL/TLS connections instead of normal ldap:///? -- Thanks Regards, Jayavant Ningoji Patil Engineer: System Software Computational Research Laboratories Ltd.

Re: SSL/TLS testing

2011-12-12 Thread reyman
With the option -ZZ i think, try this ldapsearch -x -LLL -ZZ -d 150 On Mon, Dec 12, 2011 at 11:21 AM, Jayavant Patil jayavant.pati...@gmail.com wrote: Hi, I am using openldap-2.4.19-4.x86_64 on fedora 12 machine. I have enabled openldap SSL/TLS. How do I know (test) that I am using

Re: SSL/TLS testing

2011-12-12 Thread mark cunningham
To run with tls or die, ldapsearch -ZZ (man ldapsearch for explanation) You could make the server require clients use tls and finally run tcpdump / wireshark with and without tls and see if you can see results in plaintext Mark On 12 Dec 2011, at 10:40 a.m., Jayavant Patil

Re: SSL/TLS testing

2011-12-12 Thread Jayavant Patil
Hi, On Mon, Dec 12, 2011 at 4:19 PM, reyman reyma...@gmail.com wrote: With the option -ZZ i think, try this ldapsearch -x -LLL -ZZ -d 150 Yeah, It shows output containing ber_dump, ldap_write,ldap_read, tls_write, tls_read etc. But at the end is shows the following: TLS certificate

Re: SSL/TLS testing

2011-12-12 Thread reyman
You have a self signed certificate, so you don't need to verify your certificate. When you activate the tls on ldap, you only need this two lines, and you don't need the line with certificate verification* olcTLSCACertificateFile : * dn: cn=config add: olcTLSCertificateFile olcTLSCertificateFile:

Re: SSL/TLS testing

2011-12-12 Thread Howard Chu
reyman wrote: You have a self signed certificate, Correct. so you don't need to verify your certificate. When you activate the tls on ldap, you only need this two lines, and you don't need the line with certificate verification*olcTLSCACertificateFile : * Wrong. RTFM.

Re: SSL/TLS testing

2011-12-12 Thread rey sebastien
Le 12/12/2011 19:24, Howard Chu a écrit : reyman wrote: You have a self signed certificate, Correct. so you don't need to verify your certificate. When you activate the tls on ldap, you only need this two lines, and you don't need the line with certificate

Re: SSL/TLS testing

2011-12-12 Thread Howard Chu
rey sebastien wrote: Le 12/12/2011 19:24, Howard Chu a écrit : reyman wrote: You have a self signed certificate, Correct. so you don't need to verify your certificate. When you activate the tls on ldap, you only need this two lines, and you don't need the line with certificate

Re: SSL/TLS testing

2011-12-12 Thread Raffael Sahli
On 12.12.2011 21:55, rey sebastien wrote: Le 12/12/2011 21:07, Howard Chu a écrit : rey sebastien wrote: Le 12/12/2011 19:24, Howard Chu a écrit : reyman wrote: You have a self signed certificate, Correct. so you don't need to verify your certificate. When you activate the tls on ldap,

Re: SSL/TLS testing

2011-12-12 Thread Quanah Gibson-Mount
--On Monday, December 12, 2011 9:55 PM +0100 rey sebastien reyma...@gmail.com wrote: IMHO i know this problem but i think this is better than nothing, and actually i have nothing. I wait for valid certificate... And sorry but your RTFM answer doesn't help me to resolve this problem with gnutls