We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent f6efcd3 commit b4f3ab7Copy full SHA for b4f3ab7
1 file changed
script/install-openldap
@@ -96,6 +96,13 @@ add: olcTLSCertificateKeyFile
96
olcTLSCertificateKeyFile: /etc/ssl/private/ldap01_slapd_key.pem
97
EOF
98
99
+# LDAP over TLS/SSL (ldaps://) is deprecated in favour of StartTLS. The latter
100
+# refers to an existing LDAP session (listening on TCP port 389) becoming
101
+# protected by TLS/SSL whereas LDAPS, like HTTPS, is a distinct
102
+# encrypted-from-the-start protocol that operates over TCP port 636. But we
103
+# enable it for testing here.
104
+sudo sed -i -e 's|^SLAPD_SERVICES="\(.*\)"|SLAPD_SERVICES="ldap:/// ldapi:/// ldaps:///"|' /etc/default/slapd
105
+
106
sudo adduser openldap ssl-cert
107
sudo chgrp ssl-cert /etc/ssl/private/ldap01_slapd_key.pem
108
sudo chmod g+r /etc/ssl/private/ldap01_slapd_key.pem
0 commit comments