Openldap 2.4.48-1 vs my company's pki

Quanah Gibson-Mount
Mon Aug 5 19:25:00 GMT 2019

--On Monday, August 05, 2019 9:22 AM -0400 David Goldberg 
> Sorry, was away from work over the weekend. I just tested with openssl
> s_client and it works just fine.  Version is 1.1.1.  there is no self
> signed certificate. It's signed with the company pki rather than
> commercial and I've properly installed that chain. The problem send to be
> with the new build, at least the weird ldd output leads me to that
> conclusion. I'll try to find some time to build from source and see if it

Do you mean you connected to the ldap server using OpenSSL s_client to 
confirm that works?  If that works and the ldapsearch (or other ldap 
client) binary does not, then you likely have a global /etc/ldap.conf (or 
whereever this build looks for it) or a ~/.ldaprc file that defines the 
path or file to find the CA certificate that would need updating.



Quanah Gibson-Mount
Product Architect
Symas Corporation
Packaged, certified, and supported LDAP solutions powered by OpenLDAP:

