Bug#506853: libgnutls26: 2.4.2-3 breaks OpenLDAP access

2008-12-12 Thread Stefan Söffing
Simon Josefsson schrieb: > Thank you, I believe this is a problem with your CA certificate, it > contains a basic constraint as follows: > > Certificate Authority (CA): FALSE > > You need to set the CA constraint to TRUE for CA certificates. > Oh well, thanks a lot! Creati

Bug#506853: libgnutls26: 2.4.2-3 breaks OpenLDAP access

2008-12-10 Thread Simon Josefsson
Simon Josefsson <[EMAIL PROTECTED]> writes: > Basic Constraints (not critical): > Certificate Authority (CA): FALSE Btw, don't forget to mark the basic constraint as critical as well. See RFC 5280: 4.2.1.9. Basic Constraints ... Conforming CAs MUST includ

Bug#506853: libgnutls26: 2.4.2-3 breaks OpenLDAP access

2008-12-10 Thread Simon Josefsson
Stefan Söffing <[EMAIL PROTECTED]> writes: > Thanks for your help, here is the output: Thank you, I believe this is a problem with your CA certificate, it contains a basic constraint as follows: Certificate Authority (CA): FALSE You need to set the CA constraint to TRUE

Bug#506853: libgnutls26: 2.4.2-3 breaks OpenLDAP access

2008-12-08 Thread Stefan Söffing
Thanks for your help, here is the output: teilchen01:~# gnutls-cli -p 636 thea.physik.uni-kl.de -d 1 --print-cert --x509cafile /etc/ssl/certs/thea_cacert.pem Processed 1 CA certificate(s). Resolving 'thea.physik.uni-kl.de'... Connecting to '131.246.123.113:636'... - Certificate type: X.509 - Got

Bug#506853: libgnutls26: 2.4.2-3 breaks OpenLDAP access

2008-12-08 Thread Simon Josefsson
Stefan Söffing <[EMAIL PROTECTED]> writes: > Hi, > > thank you for looking into this problem. > > I just tried libgnutls26 2.4.2-4, unfortunately it doesn't solve this > problem for me, I still get > > - Peer's certificate is NOT trusted > > for the self-signed certificate. LDAP access is still br

Processed: Re: Bug#506853: libgnutls26: 2.4.2-3 breaks OpenLDAP access

2008-12-08 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > unmerge 506853 Bug#506853: libgnutls26: 2.4.2-3 breaks OpenLDAP access Bug#507633: libgnutls26: GnuTLS does not know VeriSign any more Disconnected #506853 from all other report(s). > reopen 506853 Bug#506853: libgnutls26: 2.4.2-3 breaks Op

Bug#506853: libgnutls26: 2.4.2-3 breaks OpenLDAP access

2008-12-08 Thread Stefan Söffing
Hi, thank you for looking into this problem. I just tried libgnutls26 2.4.2-4, unfortunately it doesn't solve this problem for me, I still get - Peer's certificate is NOT trusted for the self-signed certificate. LDAP access is still broken. - Stefan -- To UNSUBSCRIBE, email to [EMAIL PROT