Cause:
OpenSSL hashed CA certificate directory is configured to be used as a source for trusted CA certificates. libldap assumes that filenames of all hashed certificates should end with '.0', which is not correct. Any numeric suffix is allowed.
Consequence:
Only certificates with '.0' suffix are loaded.
Fix:
Patch applied which updates checking of filenames of files in OpenSSL CA certificate directory.
Result:
All certificates with a filename, which is allowed in hashed OpenSSL CA certificate directory are loaded.
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.
http://rhn.redhat.com/errata/RHBA-2013-0364.html