--On Tuesday, January 29, 2008 10:18 PM +0100 "T.A. van Roermund" <[EMAIL PROTECTED]> wrote:

FQDN: server-timo.van-roermund.nl
CN: van-roermund.nl

Will that be the problem? If so, then the behaviour of GnuTLS *is*
different from the behavious of OpenSSL. I will test it and let you know.

That would be a problem if "server-timo.van-roermud.nl" is not in subjectAltName for the certs. Standard OpenLDAP 2.3 against OpenSSL would also not accept that cert. I don't know why the previous debian package would have allowed it, unless it was related to the old hacked libldap libraries (are those replaced now?).

--Quanah


--

Quanah Gibson-Mount
Principal Software Engineer
Zimbra, Inc
--------------------
Zimbra ::  the leader in open source messaging and collaboration



--
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to