Skip to content
GitLab
Projects Groups Topics Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • fusiondirectory fusiondirectory
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributor statistics
    • Graph
    • Compare revisions
  • Issues 35
    • Issues 35
    • List
    • Boards
    • Service Desk
    • Milestones
  • Packages and registries
    • Packages and registries
    • Package Registry
    • Container Registry
    • Terraform modules
  • Activity
  • Graph
  • Create a new issue
  • Commits
  • Issue Boards
Collapse sidebar
  • fusiondirectoryfusiondirectory
  • fusiondirectoryfusiondirectory
  • Issues
  • #2684
Closed
Open
Issue created Aug 30, 2013 by bmortier@bmortierMaintainer

FusionDirectory fails to log in if LDAP server requires client certificate

I made the following change to my LDAP server config:

dn: cn=config
replace: olcTLSCACertificateFile
olcTLSCACertificateFile: /etc/ssl/certs/ssl-cert-local-ca.pem
-
replace: olcTLSCertificateFile
olcTLSCertificateFile: /etc/ssl/certs/slapd.pem
-
replace: olcTLSCertificateKeyFile
olcTLSCertificateKeyFile: /etc/ssl/private/slapd.key
-
replace: olcTLSVerifyClient
olcTLSVerifyClient: demand
-
replace: olcLocalSSF
olcLocalSSF: 256

...and FusionDirectory failed to log in with:

Fatal error
FATAL: Error when connecting the LDAP. Server said 'Could not bind to cn=admin,dc=strategicit,dc=homelinux,dc=net (Error in the push function., while operating on '' using LDAP server 'ldap://fusion.strategicit.homelinux.net:389')'.

Please fix the above error and reload the page. 

Things work if I delete olcTLSVerifyCLient from my config. Perhaps there's an error if the server requires client side certs?

Edited Feb 21, 2022 by bmortier
Assignee
Assign to
Time tracking