Founded another issue: when doing `sudo' as ldap user, SSL still doesn't work:
ldapuser@myhost:~$ sudo ls LDAP Config Summary =================== uri ldaps://ldap.aldu.net/ ldap_version 3 sudoers_base ou=sudoers,dc=aldu,dc=net binddn (anonymous) bindpw (anonymous) ssl (no) =================== ldap_set_option(LDAP_OPT_X_TLS_CACERTFILE,"/etc/ssl/certs/AlduNetworkCA.pem") ldap_initialize(ld,ldaps://ldap.aldu.net/) ldap_set_option(LDAP_OPT_PROTOCOL_VERSION,0x03) ldap_simple_bind_s()=81 : Can't contact LDAP server
While the same as local user:
localuser@host:~$ sudo ls LDAP Config Summary =================== uri ldaps://ldap.aldu.net/ ldap_version 3 sudoers_base ou=sudoers,dc=aldu,dc=net binddn (anonymous) bindpw (anonymous) ssl (no) =================== ldap_set_option(LDAP_OPT_X_TLS_CACERTFILE,"/etc/ssl/certs/AlduNetworkCA.pem") ldap_initialize(ld,ldaps://ldap.aldu.net/) ldap_set_option(LDAP_OPT_PROTOCOL_VERSION,0x03) ldap_bind() ok
Permissions on CA certificate are ok, ldapsearches too. If I do `sudo' as ldap user with `ldap' instead of `ldaps' it runs fine again.
Founded another issue: when doing `sudo' as ldap user, SSL still doesn't work:
ldapuser@myhost:~$ sudo ls /ldap.aldu. net/ dc=aldu, dc=net option( LDAP_OPT_ X_TLS_CACERTFIL E,"/etc/ ssl/certs/ AlduNetworkCA. pem") (ld,ldaps: //ldap. aldu.net/ ) option( LDAP_OPT_ PROTOCOL_ VERSION, 0x03) bind_s( )=81 : Can't contact LDAP server
LDAP Config Summary
===================
uri ldaps:/
ldap_version 3
sudoers_base ou=sudoers,
binddn (anonymous)
bindpw (anonymous)
ssl (no)
===================
ldap_set_
ldap_initialize
ldap_set_
ldap_simple_
While the same as local user:
localuser@host:~$ sudo ls /ldap.aldu. net/ dc=aldu, dc=net option( LDAP_OPT_ X_TLS_CACERTFIL E,"/etc/ ssl/certs/ AlduNetworkCA. pem") (ld,ldaps: //ldap. aldu.net/ ) option( LDAP_OPT_ PROTOCOL_ VERSION, 0x03)
LDAP Config Summary
===================
uri ldaps:/
ldap_version 3
sudoers_base ou=sudoers,
binddn (anonymous)
bindpw (anonymous)
ssl (no)
===================
ldap_set_
ldap_initialize
ldap_set_
ldap_bind() ok
Permissions on CA certificate are ok, ldapsearches too. If I do `sudo' as ldap user with `ldap' instead of `ldaps' it runs fine again.