Interesting!

You may want to put that in the documentation.

On a related note, is it possible to use PEM files directly instead of messing about with conversions?

Thanks,

Trevor

On Wed, Feb 10, 2021, 5:53 PM William Brown <wbrown@suse.de> wrote:


> On 10 Feb 2021, at 23:17, Trevor Vaughan <tvaughan@onyxpoint.com> wrote:
>
> I noticed that the server was extracting the PEM files from the keystore by default and was wondering if there was really any use for this being on by default.
>
> The relevant setting is nsslapd-extract-pemfiles.

Yep, it's needed. Internally we use some openldap client libraries for outbound connections, and they only support openssl and PEM certificates. So we need to extract these at start up and feed them to the library.


>
> Thanks,
>
> Trevor
>
> --
> Trevor Vaughan
> Vice President, Onyx Point, Inc
> (410) 541-6699 x788
>
> -- This account not approved for unencrypted proprietary information --
> _______________________________________________
> 389-users mailing list -- 389-users@lists.fedoraproject.org
> To unsubscribe send an email to 389-users-leave@lists.fedoraproject.org
> Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
> List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
> List Archives: https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org


Sincerely,

William Brown

Senior Software Engineer, 389 Directory Server
SUSE Labs, Australia
_______________________________________________
389-users mailing list -- 389-users@lists.fedoraproject.org
To unsubscribe send an email to 389-users-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure