Re: LDAP and SELINUX

2016-02-03 Thread Jens Vagelpohl
> On 03 Feb 2016, at 17:48 , Borresen, John - 0444 - MITLL > wrote: > > Does anyone out there in OpenLDAP land have experience with working with > OpenLDAP and SELINUX? The standard procedure I use to debug SELinux issues and then create SELinux rule files to allow previosuly forbidden inter

Re: OpenLDAP and DH parameter size / LogJam vulnerability

2015-07-15 Thread Jens Vagelpohl
> On 15 Jul 2015, at 18:07 , Howard Chu wrote: > > Jens Vagelpohl wrote: >> >> Since that ITS is several years old I guess the fix is not in >> OPENLDAP_REL_ENG_2_4? > > Surely you can read the ITS yourself. > > https://www.openldap.org/its/index.cgi/S

Re: OpenLDAP and DH parameter size / LogJam vulnerability

2015-07-15 Thread Jens Vagelpohl
> On 15 Jul 2015, at 17:35 , Howard Chu wrote: > > No ITS needed, this code was already rewritten in HEAD, ITS#7506. Hi Howard, Since that ITS is several years old I guess the fix is not in OPENLDAP_REL_ENG_2_4? jens signature.asc Description: Message signed with OpenPGP using GPGMail

Re: OpenLDAP and DH parameter size / LogJam vulnerability

2015-07-15 Thread Jens Vagelpohl
> On 15 Jul 2015, at 10:50 , Emmanuel Dreyfus wrote: > > On Wed, Jul 15, 2015 at 08:59:25AM +0200, Jens Vagelpohl wrote: >> Yes, I have read your article and confirmed again that everything >> is indeed set up along the lines of your example configuration. >> The serv

Re: OpenLDAP and DH parameter size / LogJam vulnerability

2015-07-15 Thread Jens Vagelpohl
> On 15 Jul 2015, at 8:42 , Dieter Klünter wrote: > > You may have read this article > > https://sys4.de/de/blog/2013/09/09/perfect-forward-secrecy-eine-zusammenfassung/ Hallo Dieter, Yes, I have read your article and confirmed again that everything is indeed set up along the lines of your e

Re: OpenLDAP and DH parameter size / LogJam vulnerability

2015-07-14 Thread Jens Vagelpohl
> On 14 Jul 2015, at 19:39 , Howard Chu wrote: > > Jens Vagelpohl wrote: >> I am now testing the actual DH parameter size used during a TLS connection >> with instructions from https://bettercrypto.org/blog/2015/05/20/tls-logjam/ >> and it only shows DH parameter s

OpenLDAP and DH parameter size / LogJam vulnerability

2015-07-14 Thread Jens Vagelpohl
Hi all, In my setup (CentOS7, OpenLDAP 2.4.41 from the LDAP Tool Box project) I am using the following slapd.conf parameters for SSL-related configuration: TLSProtocolMin 3.1 TLSCertificateFile /etc/pki/tls/certs/NNN.crt TLSCertificateKeyFile /etc/pki/tls/private/NNN.key TLSCACer

Re: SLAPD Proxy and AD backend - Binding by UPN.

2014-01-25 Thread Jens Vagelpohl
On 25 Jan 2014, at 16:31 , egidiomeliss...@libero.it wrote: >> You can configure dovecot to use any (unique) user record attribute for > authentication > > Could you give me an example, please? The documentation I pointed you at (http://wiki2.dovecot.org/AuthDatabase/LDAP) contains links to

Re: SLAPD Proxy and AD backend - Binding by UPN.

2014-01-25 Thread Jens Vagelpohl
On 25 Jan 2014, at 15:32 , egidiomeliss...@libero.it wrote: > And it is a very BIG BIG problem for me: I cannot force users to authenticate > themselves in Dovecot by complicated and unacceptable (because of comma, > equal > and space characters) D.N. You can configure dovecot to use any

Re: Antw: Re: Log service time?

2013-09-06 Thread Jens Vagelpohl
On Sep 6, 2013, at 14:05, Покотиленко Костик wrote: > В Птн, 06/09/2013 в 04:42 -0700, Howard Chu пишет: >> It is Project policy to only investigate issues in the current release. >> There >> is no sense in tracing back thru old code whose bugs have already been fixed. > > This means old vers

Re: RE24 testing call #2 (2.4.31)

2012-04-17 Thread Jens Vagelpohl
OK on OS X 10.7.3/x86_64 against DBD 4.7.25+patches jens

Re: RE24 testing call #1 (2.4.31)

2012-04-07 Thread Jens Vagelpohl
On Apr 4, 2012, at 22:20 , Quanah Gibson-Mount wrote: > If you know how to build OpenLDAP manually, and would like to participate in > testing the next set of code for the 2.4.31 release, please do so. All OK on Mac OS X 10.7.3 x86_64 against BDB 4.7.25+patches jens

Re: RE24 testing call#1 (2.4.30)

2012-02-25 Thread Jens Vagelpohl
On Feb 24, 2012, at 19:20 , Quanah Gibson-Mount wrote: > If you know how to build OpenLDAP manually, and would like to participate in > testing the next set of code for the 2.4.30 release, please do so. All OK on OS X 10.7.3 x86_64 against BDB 4.7.52+patches jens