Re: Sync Replication via TLS/SSL - get bind err

2007-12-21 Thread RUMI Szabolcs
Hello! On Thu, 20 Dec 2007 16:34:03 -0800 Quanah Gibson-Mount <[EMAIL PROTECTED]> wrote: > Just to note, we use self-signed certs @ Zimbra with OpenLDAP, we > force TLS, and it works without a problem. Which is why I know > you're incorrect. ;) And I'd hardly look to the gentoo folks as a > sou

Re: Sync Replication via TLS/SSL - get bind err

2007-12-20 Thread RUMI Szabolcs
Hello! On Thu, 20 Dec 2007 12:08:16 -0800 Quanah Gibson-Mount <[EMAIL PROTECTED]> wrote: > > IMHO it is extremely harsh how the self-signed certs are treated by > > OpenLDAP. In the majority of cases this is forcing people (after > > many hours of struggling) to use "TLS_REQCERT never" or similar

Re: Sync Replication via TLS/SSL - get bind err

2007-12-20 Thread RUMI Szabolcs
Hello! On Thu, 20 Dec 2007 11:03:44 -0500 "Chris G. Sellers" <[EMAIL PROTECTED]> wrote: > I have setup sync replication on two OpenLDAP servers. I have it > successfully working via ldap://:389 > > I then setup TLS for SSL connections. I used a self signed cert > (using the OpenLDAP how-to

Re: sync replication fails

2007-12-05 Thread RUMI Szabolcs
On Wed, 05 Dec 2007 06:42:51 -0800 Quanah Gibson-Mount <[EMAIL PROTECTED]> wrote: > Your log does not show it trying a SASL bind, and it clearly shows > that starting TLS was successful. It also shows that it didn't even > try to bind, so you have something else wrong somewhere. You don't > real

sync replication fails

2007-12-05 Thread RUMI Szabolcs
Hello! I've got a syncrepl setup with the following settings: provider slapd.conf: overlay syncprov syncprov-checkpoint 100 10 syncprov-sessionlog 100 consumer slapd.conf: syncrepl rid=100 provider="ldaps://ldap-master.com.com" binddn="cn=syncrepl,ou=services,dc=com,dc=com"