Re: LDAP instead of /etc/ssl/certs ?

2007-07-22 Thread Victor Duchovni
On Sat, Jul 21, 2007 at 09:28:16AM +0200, Bernhard Froehlich wrote: > I agree it would be a cool extension to OpenSSL to fetch certificates > from an LDAP server, but I would like to be able to use OpenSSL with > only that simple file storage also! This makes sense for finding certs of peers fo

Re: LDAP instead of /etc/ssl/certs ?

2007-07-21 Thread Bernhard Froehlich
Mark H. Wood schrieb: [...] (think what would happen if you were to look up these certificates somewhere other than locally, and someone were to spoof the DNS entry... since you are looking up these certificates to make a trust decision, it would be possible for an attacker to

Re: LDAP instead of /etc/ssl/certs ?

2007-07-20 Thread Mark H. Wood
On Fri, Jul 20, 2007 at 12:04:18PM -0400, Patrick Patterson wrote: > Hi Hadmut; > > On Friday 20 July 2007 11:05:37 you wrote: > > On Fri, Jul 20, 2007 at 04:32:08PM +0200, Bernhard Froehlich wrote: > > > Of course it would be possible (though probably a good bit of coding > > > work) to use a LDA

Re: LDAP instead of /etc/ssl/certs ?

2007-07-20 Thread Patrick Patterson
Hi Hadmut; On Friday 20 July 2007 11:05:37 you wrote: > On Fri, Jul 20, 2007 at 04:32:08PM +0200, Bernhard Froehlich wrote: > > Of course it would be possible (though probably a good bit of coding > > work) to use a LDAP library like OpenLDAP to fetch the certificates and > > then use them with Op

Re: LDAP instead of /etc/ssl/certs ?

2007-07-20 Thread Hadmut Danisch
On Fri, Jul 20, 2007 at 04:32:08PM +0200, Bernhard Froehlich wrote: > Of course it would be possible (though probably a good bit of coding work) > to use a LDAP library like OpenLDAP to fetch the certificates and then use > them with OpenSSL library functions. > > Hope it helps. Not really, thi

Re: LDAP instead of /etc/ssl/certs ?

2007-07-20 Thread Bernhard Froehlich
Hadmut Danisch schrieb: Hi, is there a way to retrieve certificates from LDAP instead from /etc/ssl/certs ? Didn't find anything in FAQs and man pages... regards Hadmut AFAIK LDAP is not used in OpenSSL tools or library functions. Of course it would be possible (though probably a good bit o

LDAP instead of /etc/ssl/certs ?

2007-07-20 Thread Hadmut Danisch
Hi, is there a way to retrieve certificates from LDAP instead from /etc/ssl/certs ? Didn't find anything in FAQs and man pages... regards Hadmut __ OpenSSL Project http://www.openssl.org User Suppo