Did you ever find a solution to your question?  I know the newer patches to 
solaris 8 add ssl capability.  If you posted your slapd.conf and ldap.conf 
files I could prolly figure it out unless its how your making your certs?

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED]
Sent: Thursday, October 20, 2005 2:56 AM
To: openssl-users@openssl.org
Subject: openssl on Solaris8 with Openldap

Hello list,

I'm using Solaris8 with Openldap2.2.26 and Openssl-0.9.8. What I want is an
encrypted authentification via ldap. On Solaris you have to use the native
ldapclient as client and I'm using Openldap as the server. The encryption
between Apache2.0 and Openldap works fine. But Apache2.0 brings the
contraint that I have to use SSL, not TLS. So created SSL certificates 

openssl ... -nodes ....

and it works fine with Apache. So I want to use these SSL certificates. If I
start the ldap.client on port 636 I get the output

TLS: can't accept.
TLS: error:140760FC:SSL routines:SSL23_GET_CLIENT_HELLO:unknown protocol
s23_srvr.c:585

I think the certificates are also good for TLS. So I've got no problem to
use TLS. But there is just no reaction on the flag NS_LDAP_AUTH_TLS by the
ldapclient.

The error I got is an ssl error. Maybe somebody knows a workaround or a real
solution to get an encryption between openldap and the ldapclient.

Thx,
Sebastian Lorkowski

-- 
Highspeed-Freiheit. Bei GMX supergünstig, z.B. GMX DSL_Cityflat,
DSL-Flatrate für nur 4,99 Euro/Monat*  http://www.gmx.net/de/go/dsl
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    openssl-users@openssl.org
Automated List Manager                           [EMAIL PROTECTED]
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    openssl-users@openssl.org
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to