[389-users] 389 DS with two certificates

2016-11-12 Thread murmansk
I want to use two servers with multi-master replication behind a common DNS name (let's call it ldap.foo.net) with two IPs, balancing with round-robin. I plan to use only LDAPS. I have one server installed, with a certificate issued to his own FQDN. I can use ldapsearch over TLS with the -ZZZ p

[389-users] Re: 389 DS with two certificates

2016-11-12 Thread Gordon Messmer
On 11/12/2016 02:49 PM, murma...@hotmail.com wrote: - Can I install and use several certificates to one DS? That would require TLS SNI support in both the server and the client. As far as I know, it doesn't exist in either. You'll need a certificate with both FQDNs. If these hostnames reso