<div dir="ltr">What are you using as the var.server parameter... does it match the cert... </div><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Oct 7, 2015 at 2:43 PM, Alon Bar-Lev <span dir="ltr">&lt;<a href="mailto:alonbl@redhat.com" target="_blank">alonbl@redhat.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><br>
Summary:<br>
Using legacy ldaps protocol the user&#39;s expected certificate was retrieved.<br>
Using startTLS a different and a self signed certificate was retrieved.<br>
Two different identities via the two interfaces which should have returned a single identity.<br>
<div class="HOEnZb"><div class="h5"><br>
----- Original Message -----<br>
&gt; From: &quot;Alon Bar-Lev&quot; &lt;<a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a>&gt;<br>
&gt; To: &quot;Steve Dainard&quot; &lt;<a href="mailto:sdainard@spd1.com">sdainard@spd1.com</a>&gt;<br>
&gt; Cc: &quot;users&quot; &lt;<a href="mailto:users@ovirt.org">users@ovirt.org</a>&gt;<br>
&gt; Sent: Wednesday, October 7, 2015 12:01:59 AM<br>
&gt; Subject: Re: [ovirt-users] LDAP authentication with TLS<br>
&gt;<br>
&gt; Hi,<br>
&gt;<br>
&gt; Can you please send me the profile, the keystore you created and the output<br>
&gt; of:<br>
&gt;<br>
&gt; openssl s_client -connect server:636 -showcerts &lt; /dev/null<br>
&gt;<br>
&gt; Thanks!<br>
&gt;<br>
&gt; ----- Original Message -----<br>
&gt; &gt; From: &quot;Steve Dainard&quot; &lt;<a href="mailto:sdainard@spd1.com">sdainard@spd1.com</a>&gt;<br>
&gt; &gt; To: &quot;users&quot; &lt;<a href="mailto:users@ovirt.org">users@ovirt.org</a>&gt;<br>
&gt; &gt; Sent: Tuesday, October 6, 2015 11:50:41 PM<br>
&gt; &gt; Subject: [ovirt-users] LDAP authentication with TLS<br>
&gt; &gt;<br>
&gt; &gt; Hello,<br>
&gt; &gt;<br>
&gt; &gt; Trying to configure Ovirt 3.5.3.1-1.el7.centos for LDAP authentication.<br>
&gt; &gt;<br>
&gt; &gt; I&#39;ve configured the appropriate aaa profile but I&#39;m getting TLS errors<br>
&gt; &gt;  when I search for users to add via ovirt:<br>
&gt; &gt;<br>
&gt; &gt; The connection reader was unable to successfully complete TLS<br>
&gt; &gt; negotiation: javax_net_ssl_SSLHandshakeException:<br>
&gt; &gt; sun_security_validator_ValidatorException: No trusted certificate<br>
&gt; &gt; found caused by sun_security_validator_ValidatorException: No trusted<br>
&gt; &gt; certificate found<br>
&gt; &gt;<br>
&gt; &gt; I added the external CA certificate using keytool as per<br>
&gt; &gt; <a href="https://github.com/oVirt/ovirt-engine-extension-aaa-ldap" rel="noreferrer" target="_blank">https://github.com/oVirt/ovirt-engine-extension-aaa-ldap</a> with<br>
&gt; &gt; appropriate adjustments of course:<br>
&gt; &gt;<br>
&gt; &gt; keytool -importcert -noprompt -trustcacerts -alias myrootca \<br>
&gt; &gt;        -file myrootca.pem -keystore myrootca.jks -storepass changeit<br>
&gt; &gt;<br>
&gt; &gt; I know this certificate works, and can connect to LDAP with TLS as I&#39;m<br>
&gt; &gt; using the same LDAP configuration/certificate with SSSD.<br>
&gt; &gt;<br>
&gt; &gt; Can anyone clarify whether I should be adding the external CA<br>
&gt; &gt; certificate or the LDAP host certificate with keytool or any other<br>
&gt; &gt; suggestions?<br>
&gt; &gt;<br>
&gt; &gt; Thanks,<br>
&gt; &gt; Steve<br>
&gt; &gt; _______________________________________________<br>
&gt; &gt; Users mailing list<br>
&gt; &gt; <a href="mailto:Users@ovirt.org">Users@ovirt.org</a><br>
&gt; &gt; <a href="http://lists.ovirt.org/mailman/listinfo/users" rel="noreferrer" target="_blank">http://lists.ovirt.org/mailman/listinfo/users</a><br>
&gt; &gt;<br>
&gt;<br>
_______________________________________________<br>
Users mailing list<br>
<a href="mailto:Users@ovirt.org">Users@ovirt.org</a><br>
<a href="http://lists.ovirt.org/mailman/listinfo/users" rel="noreferrer" target="_blank">http://lists.ovirt.org/mailman/listinfo/users</a><br>
</div></div></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature"><div dir="ltr">Donny Davis<br><br></div></div>
</div>