On 10 Feb 2021, at 23:17, Trevor Vaughan
<tvaughan(a)onyxpoint.com> wrote:
I noticed that the server was extracting the PEM files from the keystore by default and
was wondering if there was really any use for this being on by default.
The relevant setting is nsslapd-extract-pemfiles.
Yep, it's needed. Internally we use some openldap client libraries for outbound
connections, and they only support openssl and PEM certificates. So we need to extract
these at start up and feed them to the library.
Thanks,
Trevor
--
Trevor Vaughan
Vice President, Onyx Point, Inc
(410) 541-6699 x788
-- This account not approved for unencrypted proprietary information --
_______________________________________________
389-users mailing list -- 389-users(a)lists.fedoraproject.org
To unsubscribe send an email to 389-users-leave(a)lists.fedoraproject.org
Fedora Code of Conduct:
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines:
https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives:
https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproje...
—
Sincerely,
William Brown
Senior Software Engineer, 389 Directory Server
SUSE Labs, Australia