help-gnutls
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: LDAP over SSL does not work with Ubuntu Prolonged Pain


From: Бранко Мајић
Subject: Re: LDAP over SSL does not work with Ubuntu Prolonged Pain
Date: Mon, 14 May 2012 13:21:31 +0200

If I were you, I'd try to download the source of the Ubuntu package and
check the patches, possibly rebuilding the relevant packages by hand
without those patches. You may find this guide helpful:

http://www.cyberciti.biz/faq/rebuilding-ubuntu-debian-linux-binary-package/

Iirc, all you need is to remove the patch files from patches directory
of some sorts.

What happens if you tell gnutls-cli to ignore check of certificates?
Does it fail in the same way (i.e. just curious if the actual
establishing of connections works ok)?

I know that, for example, between upgrade Lenny from Squeeze the slapd
server would no longer be able to read a PKCS#8 PEM-encoded private key
(a bit unrelated, but a small note).

Best regards

Дана Mon, 14 May 2012 10:20:57 +0200 (CEST)
Thorsten Glaser <address@hidden> написа:

> On Sat, 12 May 2012, Nikos Mavrogiannopoulos wrote:
> 
> > You can use --print-certs to get the certificates.
> 
> This doesn’t work either:
> 
> # gnutls-cli --print-cert -p 636 --x509cafile /etc/ssl/certs/ca-c*
> dc.lan.tarent.de Processed 407 CA certificate(s).
> Resolving 'dc.lan.tarent.de'...
> Connecting to '172.26.100.1:636'...
> *** Verifying server certificate failed...
> *** Fatal error: Error in the certificate.
> *** Handshake has failed
> GnuTLS error: Error in the certificate.
> 
> I think it may misparse the certificates or something.
> Do you think I’d better raise this with Ubuntu? I had
> looked here first because it seems way more active and
> responsive…
> 
> bye,
> //mirabilos


-- 
Branko Majic
Jabber: address@hidden
Please use only Free formats when sending attachments to me.

Бранко Мајић
Џабер: address@hidden
Молим вас да додатке шаљете искључиво у слободним форматима.

Attachment: signature.asc
Description: PGP signature


reply via email to

[Prev in Thread] Current Thread [Next in Thread]