The following input errors were detected: Authentication failed. error: error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed (unable to get local issuer certificate) ldap_error: Can't contact LDAP server
[29-Oct-2021 19:49:43 Europe/Berlin] PHP Warning: A non-numeric value encountered in /usr/local/www/system_camanager.php on line 176
#(system local trust) skip intermediate certificate
system: prevent expired or intermediate CA certificates from being added to trust store by default
Hican you please explain why you use intermediate CA cert to trust the ldap server and not the root CA cert?
Because there is no root CA
X509v3 extensions: X509v3 Basic Constraints: critical CA:TRUE[...] X509v3 Key Usage: Certificate Sign, CRL Sign Netscape Cert Type: SSL CA, S/MIME CA, Object Signing CA X509v3 Subject Alternative Name: email:**** X509v3 Issuer Alternative Name: email:***** Netscape Comment: This certificate is a Root CA Certificate
why OPNSENSE thinks that isn't a root CA
Certificate: Data: Version: 3 (0x2) Serial Number: *censored* Signature Algorithm: sha256WithRSAEncryption Issuer: *censored* Validity Not Before: *censored* Not After : *censored* Subject: *censored* Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (2048 bit) Modulus: *censored* Exponent: *censored* X509v3 extensions: X509v3 Basic Constraints: critical CA:TRUE X509v3 Subject Key Identifier: *censored* X509v3 Authority Key Identifier: keyid:*censored* / equal to X509v3 Subject Key Identifier DirName:*censored* serial:*censored* X509v3 Key Usage: Certificate Sign, CRL Sign Netscape Cert Type: SSL CA, S/MIME CA, Object Signing CA X509v3 Subject Alternative Name: email:*censored* X509v3 Issuer Alternative Name: email:*censored* Netscape Comment: This certificate is a Root CA Certificate Signature Algorithm: sha256WithRSAEncryption
@benyaminI'm not talking about which certification authority should issue certificates to servers. I'm talking about which certification authority the connecting server should trust