Re: Solved - F15, ldap/ssl/sssd and certs from CAcert.org

2011-08-10 Thread Bobby Krupczak
Hi! > Bobby Krupczak wrote: > > Uggh. This was really frustrating . . . . . I dont suppose something > > could be placed in release notes when these kinds of changes occur? > > I've said the same thing for the past several releases. The NSS folks > don't care. They only want to use NSS to be c

Re: Solved - F15, ldap/ssl/sssd and certs from CAcert.org

2011-08-10 Thread Michael Cronenworth
Bobby Krupczak wrote: > Uggh. This was really frustrating . . . . . I dont suppose something > could be placed in release notes when these kinds of changes occur? I've said the same thing for the past several releases. The NSS folks don't care. They only want to use NSS to be certified for FIPS

Solved - F15, ldap/ssl/sssd and certs from CAcert.org

2011-08-10 Thread Bobby Krupczak
Hi! I was having problems getting ldapsearch (openldap) and sssd to accept x509 certs from CAcert.org. Thanks to sgallagh for pointing me to where to find a solution. Apparently, in F15, openldap and sssd do not use openssl for TLS/SSL libs. They use Mozilla NSS instead. Therefore, the default