Community
    • Categories
    • Recent
    • Popular
    • Users
    • Search
    • Register
    • Login

    ldaps debian Hinweis

    Scheduled Pinned Locked Moved Allgemein
    3 Posts 2 Posters 456 Views 1 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      mio
      last edited by

      Hallo,

      könnt Ihr bitte einmal die FAQ ergänzen!
      Siehe Debian Part.

      Problem unter Debian 12:
      Wir haben ein AD mit self signed certificate.

      Error!
      LDAP Bind failed (Can't contact LDAP server). Host: Server:636.

      Lösung:
      Wie beschrieben das Zertifikat aus Windows exportieren.
      Dann auf dem debian:

      sudo apt-get -y install ldap-utils openssl
      

      Umwandlung Zertifikat auf idoit:

      sudo openssl x509 -inform der -outform pem -in /tmp/yourdomain.cer \
      -out /usr/local/share/ca-certificates/yourdomain.crt
      
      sudo update-ca-certificates
      

      edit /etc/ldap/ldap.conf und füge dein Zertifikat hinzu.

      # TLS certificates (needed for GnuTLS)
      TLS_CACERT      /etc/ssl/certs/ca-certificates.crt
      TLS_CACERT<---->/etc/ssl/certs/yourdomain.pem
      
      
      sudo systemctl restart apache2
      

      Test:

      sudo openssl s_client -connect yourservername.yourdomain:636
      
      

      Erklärung:
      Durch die Zeile

      TLS_CACERT      /etc/ssl/certs/ca-certificates.crt
      

      wird das eigene Zertifikat nicht gegriffen.

      Vielen Dank.

      Grüße mio

      1 Reply Last reply Reply Quote 0
      • M Offline
        mio
        last edited by

        Hallo,

        ich hatte noch eine Zeile vergessen:

        # TLS certificates (needed for GnuTLS)
        TLS_CACERT      /etc/ssl/certs/ca-certificates.crt
        +TLS_CACERT<---->/etc/ssl/certs/yourdomain.pem
        +TLS_REQCERT never
        

        Grüße mio

        1 Reply Last reply Reply Quote 0
        • Michael HuhnM Offline
          Michael Huhn
          last edited by

          undefined @mio

          danke erstmal für die Information!

          Bei Fehlern oder Verbesserungen gerne ein GitHub Issue im KB Repository erstellen.
          Ich hab daraus mal eins gemacht:
          https://github.com/i-doit/knowledge-base/issues/1056

          Hier ist die Info zwar gut für andere Anwender aber ob diese Info dann bei i-doit ankommt ist was anderes ;>

          1 Reply Last reply Reply Quote 0

          Hello! It looks like you're interested in this conversation, but you don't have an account yet.

          Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

          With your input, this post could be even better 💗

          Register Login
          • First post
            Last post