On 15 May 2019, at 17:14, Angel Bosch <abosch(a)ticmallorca.net>
wrote:
> Do you have load balancers in here at all? Or is it just directly
> accessible servers? What does the TLS termination?
>
yes, we use LB and VIPs to avoid any failure.
> If you have load balancers/VIP involved, you should set the
> nsslapd-referral to the hostname of the load balancer/VIP, rather
> than to individual servers, and all certs must have the SAN for the
> LB/VIP in them.
>
> Does that help?
>
absolutely, thanks for your time.
No problem, if you have any further questions, we're always happy to help!
abosch
_______________________________________________
389-users mailing list -- 389-users(a)lists.fedoraproject.org
To unsubscribe send an email to 389-users-leave(a)lists.fedoraproject.org
Fedora Code of Conduct:
https://getfedora.org/code-of-conduct.html
List Guidelines:
https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives:
https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproje...
—
Sincerely,
William Brown
Senior Software Engineer, 389 Directory Server
SUSE Labs