Re: Limit which database is reachable on which port (slapd is listening on)?

2017-06-20 Thread John Lewis
On Tue, 2017-06-20 at 14:56 +0200, Karsten Heymann wrote: > Hi John, > > 2017-06-20 14:18 GMT+02:00 John Lewis : > > I know that, but can DNS influence LDAP or are they completely > > independent and all of the name redirection all the clients > > responsibility? For example I

Re: Limit which database is reachable on which port (slapd is listening on)?

2017-06-20 Thread Karsten Heymann
Hi John, 2017-06-20 14:18 GMT+02:00 John Lewis : > I know that, but can DNS influence LDAP or are they completely > independent and all of the name redirection all the clients > responsibility? For example I have two domains stuff.com and junk.net If > someone tried to connect

Re: Limit which database is reachable on which port (slapd is listening on)?

2017-06-20 Thread John Lewis
On Tue, 2017-06-20 at 08:23 +0200, Karsten Heymann wrote: > Hi John, > > 2017-06-20 2:02 GMT+02:00 John Lewis : > > On Mon, 2017-06-19 at 16:46 +0200, Karsten Heymann wrote: > >> 2017-06-19 15:48 GMT+02:00 Howard Chu : > >> > Read the slapd.access(5) manpage,

Delete the root entry of a DIT (mdb as backend)

2017-06-20 Thread Hongfu Huang
Hi all, I have defined a DIT (LMDB) as follows: dn: olcDatabase={3}mdb,cn=config objectClass: olcDatabaseConfig objectClass: olcMdbConfig olcDatabase: {3}mdb olcDbDirectory: /var/lib/ldap/mycompany/o=mycompany olcSuffix: o=mycompany olcRootDN: uid=admin,ou=system olcAccess: {0}to

RE: Using TLS

2017-06-20 Thread Daniel Le
I rebuilt with libssl (an OpenSSL library which supports SSL and TLS) and that worked. Thanks. However, I got into the connect error "14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed (self signed certificate)", even though the LDAP_OPT_X_TLS_REQUIRE_CERT option is

Re: Limit which database is reachable on which port (slapd is listening on)?

2017-06-20 Thread Karsten Heymann
Hi John, 2017-06-20 2:02 GMT+02:00 John Lewis : > On Mon, 2017-06-19 at 16:46 +0200, Karsten Heymann wrote: >> 2017-06-19 15:48 GMT+02:00 Howard Chu : >> > Read the slapd.access(5) manpage, use an ACL specifying sockname=xxx for >> > the >> > local port