Bug 918730
| Summary: | [RFE] Command line perl scripts should support more secure connections - LDAPI and SSL | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Nathan Kinder <nkinder> |
| Component: | 389-ds-base | Assignee: | Rich Megginson <rmeggins> |
| Status: | CLOSED CURRENTRELEASE | QA Contact: | Sankar Ramalingam <sramling> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | high | ||
| Version: | 7.0 | CC: | amsharma, jgalipea, jrusnack, mreynolds, nhosoi, nkinder |
| Target Milestone: | rc | Keywords: | FutureFeature |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | 389-ds-base-1.3.1.2-1.el7 | Doc Type: | Enhancement |
| Doc Text: |
Cause: By default the servers perl scripts used the non-secure port for ldap connections.
Consequence: Servers that requires SSL connections would not work wit the existing scripts.
Change: A new protocol argument was added to each scripts where you can set the desired connection protocol(LDAP, LDAPS, START-TLS, and LDAPI). By default, if a protocol is not specified, it will try and use the most secure protocol available.
Result: The server scripts can now handle many LDAP connection protocols.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2014-06-13 11:05:56 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Nathan Kinder
2013-03-06 18:43:22 UTC
moving all ON_QA bugs to MODIFIED in order to add them to the errata (can't add bugs in the ON_QA state to an errata). When the errata is created, the bugs should be automatically moved back to ON_QA. [root@localhost slapd-dstet]# ./db2bak.pl -v -D "cn=Directory Manager" -w "Secret123" -P STARTTLS Back up directory: /var/lib/dirsrv/slapd-dstet/bak/dstet-2013_11_11_9_38_48 Protocol STARTTLS requested, but this protocol is not supported by the Directory Server. Using the next most secure protocol (LDAP) ldap_initialize( ldap://dstet.example.com:389 ) Successfully added task entry "cn=backup_2013_11_11_9_38_48, cn=backup, cn=tasks, cn=config" [root@localhost slapd-dstet]# rpm -qa | grep 389-ds-base 389-ds-base-1.3.1.6-8.el7.x86_64 Feature is implemented in latest RHEL7 389, testing is yet to be done - bugs in this feature will be filed separately. Test Plan :: https://wiki.idm.lab.bos.redhat.com/export/idmwiki/index.php/Centralize_instance_specific_and_Secure_protocols_for_scripts Automation :: clu/cluUtil.sh and ldapi/ladirun.sh All test cases passed hence marking bug as VERIFIED. This request was resolved in Red Hat Enterprise Linux 7.0. Contact your manager or support representative in case you have further questions about the request. |