OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • [Solved?] OPNsense 19.7.3 LDAP StartTLS/SSL
« previous next »
  • Print
Pages: [1]

Author Topic: [Solved?] OPNsense 19.7.3 LDAP StartTLS/SSL  (Read 3166 times)

hbc

  • Hero Member
  • *****
  • Posts: 501
  • Karma: 47
    • View Profile
[Solved?] OPNsense 19.7.3 LDAP StartTLS/SSL
« on: March 11, 2019, 12:27:28 pm »
Anybody else having issues with ldap as authentication server and using encrypted connections?

I made the update to 19.7.3 this morning and ldap with startTLS worked. After upgrade no authentication possible any more. I also tried SSL but neither works.

Changelog:
Quote
system: improve LDAPS mode and related authentication cleanups

Quote
opnsense: Could not startTLS on ldap connection [error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed (unable to get issuer certificate),Connect error]

Edit:
Changed from StartTLS to SSL and vice versa. Changed hostnames of ldap from subjectAlternative to main and back. Everything configured like before.

I do not know why, but now it works again. Very strange. All certificates in chain had been imported. Else I would say a cache has been deleted during upgrade and certificates got just fetched by a cron during my tests.
« Last Edit: March 11, 2019, 01:00:22 pm by hbc »
Logged
Intel(R) Xeon(R) Silver 4116 CPU @ 2.10GHz (24 cores)
256 GB RAM, 300GB RAID1, 3x4 10G Chelsio T540-CO-SR

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17707
  • Karma: 1618
    • View Profile
Re: [Solved?] OPNsense 19.7.3 LDAP StartTLS/SSL
« Reply #1 on: March 11, 2019, 03:26:34 pm »
Worst case it required a reoobt, best case a reconfigure as we don't do that automatically on upgrade. Some files were moved and function calls replaced.


Cheers,
Franco
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • [Solved?] OPNsense 19.7.3 LDAP StartTLS/SSL
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2