Back to bug 707599

Who When What Removed Added
Jan Vcelak 2011-05-26 12:27:07 UTC CC rmeggins
Radek Vokál 2011-05-27 08:15:51 UTC CC rvokal
Gabor Szathmari 2011-06-03 07:14:07 UTC Attachment #500822 Attachment is obsolete 0 1
Gabor Szathmari 2011-06-03 07:15:53 UTC Attachment #500823 Attachment is obsolete 0 1
Gabor Szathmari 2011-06-03 07:37:47 UTC Attachment #502746 Attachment filename replicate.crt replicate.txt
Ondrej Moriš 2011-12-12 12:54:09 UTC CC omoris
Jeremy West 2012-01-02 15:04:48 UTC Priority unspecified medium
CC jwest
Jan Vcelak 2012-01-20 13:04:37 UTC Depends On 783445
Kamil Dudka 2012-01-31 17:29:47 UTC CC kdudka
Jan Vcelak 2012-02-21 13:43:04 UTC Blocks 795763
Jan Vcelak 2012-04-04 14:50:58 UTC Summary Unable to connect to OpenLDAP server after upgrade replication with TLS does not work
Jan Vcelak 2012-04-04 14:54:58 UTC CC Dario.Palmisano
CCS Admins 2012-05-01 23:18:18 UTC CC ccsadmins
Lutz Willek 2012-06-15 11:04:20 UTC CC lutz.willek
Jan Vcelak 2012-06-18 12:36:53 UTC CC tsmetana
Jan Vcelak 2012-06-27 16:23:30 UTC Status NEW ASSIGNED
Ondrej Vasik 2012-06-28 09:11:10 UTC Blocks 836160
Jan Vcelak 2012-09-25 16:10:09 UTC Status ASSIGNED MODIFIED
Fixed In Version openldap-2.4.23-29.el6
errata-xmlrpc 2012-09-25 16:18:09 UTC Status MODIFIED ON_QA
David Spurek 2012-09-26 14:48:02 UTC CC dspurek
Jan Vcelak 2012-09-26 15:59:58 UTC Doc Text Cause:
OpenLDAP server configured for replication. TLS is enabled both for accepting connections from remote peers and for TLS client authentication to the other replicas. Different TLS configuration used for server and for connecting to the replicas.

Consequence:
Connecting to a replica can fail due to TLS certificate lookup errors or due to unknown PKCS#11 TLS errors.

Fix:
A set of patches applied makes multiple TLS LDAP contexts within one process possible without affecting the others.

Result:
Multiple LDAP TLS contexts with different configurations within one process are possible. OpenLDAP replication in described conditions is possible.
David Spurek 2012-10-09 07:32:13 UTC QA Contact qe-baseos-security dspurek
errata-xmlrpc 2012-11-20 12:36:41 UTC Status ON_QA VERIFIED
Trevor Hemsley 2012-11-21 12:58:21 UTC CC trevor.hemsley
Josh Mullis 2013-01-02 20:22:05 UTC CC josh.mullis
errata-xmlrpc 2013-02-07 00:50:18 UTC Status VERIFIED RELEASE_PENDING
errata-xmlrpc 2013-02-21 09:45:19 UTC Status RELEASE_PENDING CLOSED
Resolution --- ERRATA
Last Closed 2013-02-21 04:45:19 UTC
John Skeoch 2015-03-02 05:26:36 UTC CC ebenes

Back to bug 707599