Re: [389-users] Problems with SSL

2010-03-05 Thread Ski Kacoroski
Rich, Thanks for all your help. I got it all working like I expect except I still get the errors in the logs about admserv_host_ip_check's. I really do not want to turn on HostnameLookups so is there anyway to stop the notices so they do not fill up the logs. I searched the documentation an

Re: [389-users] Problems with SSL

2010-03-03 Thread Ski Kacoroski
Ah, I do not get this error when I connect to the IP, only to the hostname. I am also getting a lot of notices for: admserv_host_ip_check: ap_get_remote_host could not resolve 10.1.9.10 even though I have defined in the /etc/hosts file and in dns: ;; ANSWER SECTION: 10.9.1.10.in-addr.arpa. 864

Re: [389-users] Problems with SSL

2010-03-03 Thread Ski Kacoroski
Ok, I got the admin server to partially work (took a while to figure out that it uses a different way to get the password from a file for a restart). So it works, but even though the cert path is ok and the cert is ok for SSL server and SSL client, I am getting this warning on logon: "The cert

Re: [389-users] Problems with SSL

2010-03-03 Thread Ski Kacoroski
Rich & Rob, I am making some progress. I got it to work partially. My problem was that it did not like the default digicert root cert (the one I see by linking to /usr/lib64/libnssckbi.so). When I installed the digicert root cert that came with the server cert, it worked. I figured this out

Re: [389-users] Problems with SSL

2010-03-03 Thread Rob Crittenden
Ski Kacoroski wrote: > Rich, > > Thanks very much for your replies. I tried again with no luck. I had > it working with the self-signed cert using setupssl2.sh. I changed the > password on the database to one I could type and verified that it worked > ok. I then added in my star cert, remov

Re: [389-users] Problems with SSL

2010-03-03 Thread Ski Kacoroski
Rich, Thanks very much for your replies. I tried again with no luck. I had it working with the self-signed cert using setupssl2.sh. I changed the password on the database to one I could type and verified that it worked ok. I then added in my star cert, removed the self-signed certs, and st

Re: [389-users] Problems with SSL

2010-03-02 Thread Ski Kacoroski
Ok, looks like I need to reboot the entire server to get the admin console stop server functionality to work. Now, has anyone had any luck using a * cert with the 389 server? cheers, ski On 03/02/2010 03:24 PM, Ski Kacoroski wrote: > Hi, > > I am having problems with SSL setup. First I tried

[389-users] Problems with SSL

2010-03-02 Thread Ski Kacoroski
Hi, I am having problems with SSL setup. First I tried via the admin console to use our company's star cert, but no matter what [in/password I picked for the keystore, when I tried to restart the server it would not accept my pin/password that I had just entered. I then gave up and ran the s