Bug 795763 - replication with TLS does not work
Summary: replication with TLS does not work
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: openldap
Version: rawhide
Hardware: x86_64
OS: Linux
medium
high
Target Milestone: ---
Assignee: Jan Vcelak
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On: 707599 783445
Blocks:
TreeView+ depends on / blocked
 
Reported: 2012-02-21 13:43 UTC by Jan Vcelak
Modified: 2013-03-04 01:29 UTC (History)
4 users (show)

Fixed In Version: openldap-2.4.31-3.fc17
Clone Of: 707599
Environment:
Last Closed: 2012-07-17 17:22:03 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Jan Vcelak 2012-02-21 13:43:04 UTC
Originally reported for RHEL-6. There are various problems with syncrepl with TLS enabled. The connection between two servers cannot be established.

1.) When MozNSS certdb is used:

TLS: could not initialize moznss - error -8018:Unknown PKCS #11 error..

2.) When PEM certificates are used:

TLS error -12272:SSL peer reports incorrect Message

Comment 1 Jan Vcelak 2012-06-27 13:12:18 UTC
Resolved in openldap-2.4.31-3.fc17

Comment 2 Fedora Update System 2012-06-27 13:17:14 UTC
openldap-2.4.31-3.fc17 has been submitted as an update for Fedora 17.
https://admin.fedoraproject.org/updates/openldap-2.4.31-3.fc17

Comment 3 Fedora Update System 2012-06-28 03:33:14 UTC
Package openldap-2.4.31-3.fc17:
* should fix your issue,
* was pushed to the Fedora 17 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing openldap-2.4.31-3.fc17'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2012-10000/openldap-2.4.31-3.fc17
then log in and leave karma (feedback).

Comment 4 Fedora Update System 2012-07-17 17:22:03 UTC
openldap-2.4.31-3.fc17 has been pushed to the Fedora 17 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.