SSL / Certificates / ... Some confusion

2010-04-12 Thread Götz Reinicke - IT-Koordinator
Hi, since a couple of days I try to setup a provider and a consumer over ssl following the documentation in a book [1] an dusing two servers. (Red Hat 5.x, openssl-0.9.8e-12, openldap-2.3.43-3 ) Doing so I was confronted with a lot off different warnings/messages but finaly I got the replication

Re: SSL / Certificates / ... Some confusion

2010-04-12 Thread Dieter Kluenter
Götz Reinicke - IT-Koordinator goetz.reini...@filmakademie.de writes: Hi, [...] I noticed and googeled some provider debug info and wanted to ask for some prove or clarification or work around: From the provider log: TLS certificate verification: Error, unsupported certificate purpose ...

Re: SSL / Certificates / ... Some confusion

2010-04-12 Thread Dieter Kluenter
Götz Reinicke - IT-Koordinator goetz.reini...@filmakademie.de writes: Dieter Kluenter schrieb: Götz Reinicke - IT-Koordinator goetz.reini...@filmakademie.de writes: Hi, [...] I noticed and googeled some provider debug info and wanted to ask for some prove or clarification or work around:

Re: SSL / Certificates / ... Some confusion

2010-04-12 Thread Klaus Lemkau
Hi, X509v3 extensions: X509v3 Basic Constraints: CA:FALSE Netscape Cert Type: SSL Server You can use this Certificate only for Server, not for Client-authentication. Netscape Cert Type: should be SSL Client, SSL Server if

Re: SSL / Certificates / ... Some confusion

2010-04-12 Thread Götz Reinicke - IT-Koordinator
Hi Klaus, thanks a lot. Just two minute ago I finished my two-hour-google-look up ending in the same direction :-) A posting from Howard Chu pointed into the right direction: http://www.openldap.org/lists/openldap-software/200704/msg00129.html Than of to -