<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP-UX Client Configuration in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-client-configuration/m-p/5042850#M433189</link>
    <description>Have you set the paramter enable_starttls = 1 in /etc/opt/ldapux/ldapux_client.conf ?&lt;BR /&gt;</description>
    <pubDate>Thu, 26 Apr 2007 18:13:14 GMT</pubDate>
    <dc:creator>Sameer_Nirmal</dc:creator>
    <dc:date>2007-04-26T18:13:14Z</dc:date>
    <item>
      <title>LDAP-UX Client Configuration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-client-configuration/m-p/5042847#M433186</link>
      <description>Hello!&lt;BR /&gt;&lt;BR /&gt;I am attempting to configure the LDAP-UX client on an 11iv1 host with LDAP-UX 4.10 and using an existing OpenLDAP 2.3.34 LDAP server.  I am having trouble getting TLS/SSL working.  The client works great without SSL/TLS.&lt;BR /&gt;&lt;BR /&gt;Here's the low down:&lt;BR /&gt;&lt;BR /&gt;* I run through the setup utility and everything goes well, I get the same results if I select TLS or SSL and the respective settings that apply -- I can watch the logs on my LDAP server and see that the appropriate HPUX profile is downloaded successfully each time.&lt;BR /&gt;&lt;BR /&gt;* If I run /opt/ldapux/config/get_profile_entry -s nss, it also downloads the profile successfully using SSL/TLS.&lt;BR /&gt;&lt;BR /&gt;This makes it appear as if everything is going to work...even the command line ldapsearch works great.  Once I exit the setup utility, SSL/TLS connections will not work.  Any attempt to login via console or ssh fails and user/group enumeration via pwget grget fails also.  The logs on the LDAP server indicate a TLS Negotiation failure, but I can connect using the ldapsearch utility specifying -Z for SSL...&lt;BR /&gt;&lt;BR /&gt;Any ideas why there would be this disconnect and the LDAP-UX setup utility and ldapsearch can successfully negotiate an SSL/TLS connection while user/group operations cannot?&lt;BR /&gt;&lt;BR /&gt;TIA,</description>
      <pubDate>Thu, 26 Apr 2007 17:27:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-client-configuration/m-p/5042847#M433186</guid>
      <dc:creator>Joshua M. Miller</dc:creator>
      <dc:date>2007-04-26T17:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP-UX Client Configuration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-client-configuration/m-p/5042848#M433187</link>
      <description>Just to clarify one more thing, my nsswitch.conf and pam.conf are setup properly -- user/group operations succeed when not using TLS/SSL.&lt;BR /&gt;&lt;BR /&gt;Thanks!</description>
      <pubDate>Thu, 26 Apr 2007 17:28:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-client-configuration/m-p/5042848#M433187</guid>
      <dc:creator>Joshua M. Miller</dc:creator>
      <dc:date>2007-04-26T17:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP-UX Client Configuration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-client-configuration/m-p/5042849#M433188</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;Has a ssl certificate been generated or installed on the server side. If so, is the server configured correctly?&lt;BR /&gt;&lt;BR /&gt;This may be an LDAP certificate issues.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 26 Apr 2007 17:59:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-client-configuration/m-p/5042849#M433188</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2007-04-26T17:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP-UX Client Configuration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-client-configuration/m-p/5042850#M433189</link>
      <description>Have you set the paramter enable_starttls = 1 in /etc/opt/ldapux/ldapux_client.conf ?&lt;BR /&gt;</description>
      <pubDate>Thu, 26 Apr 2007 18:13:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-client-configuration/m-p/5042850#M433189</guid>
      <dc:creator>Sameer_Nirmal</dc:creator>
      <dc:date>2007-04-26T18:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP-UX Client Configuration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-client-configuration/m-p/5042851#M433190</link>
      <description>Hi Steven,&lt;BR /&gt;&lt;BR /&gt;The LDAP server has the proper SSL certs and is serving over 100 Linux hosts via SSL so I don't think it's a server configuration issue, although I'm open to anything at this point.&lt;BR /&gt;&lt;BR /&gt;I wonder if the client is too strict in checking the server cert at this point and I'm trying to verify that I have the proper names and IP mappings in DNS.&lt;BR /&gt;&lt;BR /&gt;And Sameer,&lt;BR /&gt;&lt;BR /&gt;I have tried using TLS with 'enable_starttls 1' in the ldapux_client.conf and that has not worked for me either.</description>
      <pubDate>Thu, 26 Apr 2007 18:28:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-client-configuration/m-p/5042851#M433190</guid>
      <dc:creator>Joshua M. Miller</dc:creator>
      <dc:date>2007-04-26T18:28:34Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP-UX Client Configuration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-client-configuration/m-p/5042852#M433191</link>
      <description>The problem here was with my profile in the LDAP directory -- I did not add an attribute for 'authenticationMethod' and when the ldapux client was restarted it would download the profile and this setting would be set to 'simple'.  The proper setting for my TLS environment is 'tls:simple'.  Once I updated my profile to reflect this change, everything is working great!&lt;BR /&gt;&lt;BR /&gt;Sanitized working profile (currently in my production directory):&lt;BR /&gt;&lt;BR /&gt;dn: cn=uxprofile,ou=Profiles,dc=example,dc=com&lt;BR /&gt;cn: uxprofile&lt;BR /&gt;objectClass: DUAConfigProfile&lt;BR /&gt;defaultSearchBase: dc=example,dc=com&lt;BR /&gt;defaultSearchScope: one&lt;BR /&gt;profileTTL: 3600&lt;BR /&gt;credentialLevel:: &lt;XXXX...&gt;&lt;BR /&gt;serviceSearchDescriptor: passwd:OU=People,DC=example,DC=com&lt;BR /&gt;serviceSearchDescriptor: group:OU=Group,DC=example,DC=com&lt;BR /&gt;authenticationMethod: tls:simple&lt;BR /&gt;defaultServerList: example.com:389 example.com:389&lt;/XXXX...&gt;</description>
      <pubDate>Mon, 30 Apr 2007 11:46:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ldap-ux-client-configuration/m-p/5042852#M433191</guid>
      <dc:creator>Joshua M. Miller</dc:creator>
      <dc:date>2007-04-30T11:46:04Z</dc:date>
    </item>
  </channel>
</rss>

