* Apache, LDAP and SSL
@ 2006-04-04 7:33 Martin Klier
2006-04-11 19:03 ` Jan Trautmann
0 siblings, 1 reply; 3+ messages in thread
From: Martin Klier @ 2006-04-04 7:33 UTC (permalink / raw)
To: linux-admin
[-- Attachment #1: Type: text/plain, Size: 1091 bytes --]
Hi Admins,
has anyone ever made a configuration like this:
Apache 2.x.x, SSL and, most important, SSL-encrypted(!) LDAP auth against a
Microcrap ActiveDirectory 2003?
Topday, Apache 2.0.x and 2.2.0 works, LDAP-agaist-AD works, SSL works, but not
LDAPS.
I happily tried on SuSE10.0 (pre-built Apache, no LDAP SSL support built in,
so it's crap) and SLES9 (own-built Apache, with ldap modules with ssl/SASL),
but there are always strange errors, most sounding like a non-available LDAP
server. But, indeed, the 3269 port is open there. Since I have no clue about
the windows box, I can't say any more about this side.
Is there any ressource in the world I can look on?
--
Mit freundlichen Grüßen
i.A. Martin Klier
Systemadministration / Datenbanken
-----------------------------------------------------------------
A.T.U Auto-Teile-Unger
Handels GmbH & Co. KG
Dr.-Kilian-Straße 4
D-92637 Weiden i. d. OPf.
Tel.: +49 961 306 5663
Fax: +49 961 306 5982
martin.klier@atu.de
www.atu.de
-----------------------------------------------------------------
[-- Attachment #2: Type: application/pgp-signature, Size: 189 bytes --]
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: Apache, LDAP and SSL
2006-04-04 7:33 Apache, LDAP and SSL Martin Klier
@ 2006-04-11 19:03 ` Jan Trautmann
2006-04-12 6:32 ` Martin Klier
0 siblings, 1 reply; 3+ messages in thread
From: Jan Trautmann @ 2006-04-11 19:03 UTC (permalink / raw)
To: Martin Klier, linux-admin
Grüsse aus der Operpfalz :)
http://www.rrze.uni-erlangen.de/dienste/arbeiten-rechnen/linux/howtos/ldap/ssl.shtml
There i found something about SSL and LDAP in german.
I´ve had tried a few time ago something simular but after a few hours i
decieded that it costs too much time to integrate this with M$ Active
Directory. I must say that i only have done this for playing and testing.
But i have often read in forums that there is a problem with M$ AD and LDAP in
the same way. I remember a possible solution that the M$ AD must be the PDC
an the Linux must be BPC but in this special case i can´t help much.
Maybe reply some more information like syslogs for the problem in SLES9.
Maybe you can get help in www.linuxforen.de (if you not already searched or
asked there). In this forum i found this link
http://www.oo-services.com/de/articles/sso.aspx .
This is a Howto for making SSL and LDAP running with Active Directory 2003.
I hope this could help you.
I think that the problem with not working LDAP in SLES9 is a configuration or
version problem maybe an new version of LDAP/Samba could help. I realy dont
know which version is in SLES9 but in SuSe most times there are old and crap
versions, this would be nothing new for me ;)
Best regards
Jan Martin Trautmann
Am Dienstag, 4. April 2006 09:33 schrieben Sie:
> Hi Admins,
>
> has anyone ever made a configuration like this:
> Apache 2.x.x, SSL and, most important, SSL-encrypted(!) LDAP auth against a
> Microcrap ActiveDirectory 2003?
>
> Topday, Apache 2.0.x and 2.2.0 works, LDAP-agaist-AD works, SSL works, but
> not LDAPS.
>
> I happily tried on SuSE10.0 (pre-built Apache, no LDAP SSL support built
> in, so it's crap) and SLES9 (own-built Apache, with ldap modules with
> ssl/SASL), but there are always strange errors, most sounding like a
> non-available LDAP server. But, indeed, the 3269 port is open there. Since
> I have no clue about the windows box, I can't say any more about this side.
>
> Is there any ressource in the world I can look on?
-
To unsubscribe from this list: send the line "unsubscribe linux-admin" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: Apache, LDAP and SSL
2006-04-11 19:03 ` Jan Trautmann
@ 2006-04-12 6:32 ` Martin Klier
0 siblings, 0 replies; 3+ messages in thread
From: Martin Klier @ 2006-04-12 6:32 UTC (permalink / raw)
To: phoenix2; +Cc: linux-admin
[-- Attachment #1: Type: text/plain, Size: 1240 bytes --]
Hi Jan,
Am Dienstag 11 April 2006 21:03 schrieb Jan Trautmann:
> Grüsse aus der Operpfalz :)
Ja sauber :))
> I´ve had tried a few time ago something simular but after a few hours i
> decieded that it costs too much time to integrate this with M$ Active
> Directory. I must say that i only have done this for playing and testing.
> But i have often read in forums that there is a problem with M$ AD and LDAP
> in the same way. I remember a possible solution that the M$ AD must be the
> PDC an the Linux must be BPC but in this special case i can´t help much.
In the meantime, I've integrated LDAP and M$ AD 2003, but, as said, without
LDAPS. For an integration of LDAPS a Microsoft Certificate Server within the
AD domain is absolutely neccessary, but AFAIK not so easy to set up. At the
moment, I am waiting for our windows division to set up such a system, then I
will progress.
As soon as it fully works I will provide a description here.
Thanks so far.
--
Mit freundlichen Grüßen
i.A. Martin Klier
Systemadministration / Datenbanken
-----------------------------------------------------------------
A.T.U Auto-Teile-Unger
Handels GmbH & Co. KG
Dr.-Kilian-Straße 4
D-92637 Weiden i. d. OPf.
[-- Attachment #2: Type: application/pgp-signature, Size: 189 bytes --]
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2006-04-12 6:32 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-04-04 7:33 Apache, LDAP and SSL Martin Klier
2006-04-11 19:03 ` Jan Trautmann
2006-04-12 6:32 ` Martin Klier
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).