"TLS_REQCERT allow" rejects CN and hostname mismatch?

2011-10-16 Thread Noël Köthe
Hello, (openldap 2.4.25 on Debian GNU/Linux) TLS_REQCERT allow is documented with "The server certificate is requested. If no certificate is provided, the session proceeds normally. If a bad certificate is provided, it will be ignored and the session proceeds normally." But if I test it it lo

Re: "TLS_REQCERT allow" rejects CN and hostname mismatch?

2011-10-16 Thread Howard Chu
Noël Köthe wrote: Hello, (openldap 2.4.25 on Debian GNU/Linux) TLS_REQCERT allow is documented with "The server certificate is requested. If no certificate is provided, the session proceeds normally. If a bad certificate is provided, it will be ignored and the session proceeds normally." Bu

Re: "TLS_REQCERT allow" rejects CN and hostname mismatch?

2011-10-16 Thread Philip Guenther
On Sun, 16 Oct 2011, Howard Chu wrote: > Noël Köthe wrote: > > (openldap 2.4.25 on Debian GNU/Linux) > > TLS_REQCERT allow is documented with > > "The server certificate is requested. If no certificate is provided, the > > session proceeds normally. If a bad > > certificate is provided, it will