Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 05-06-2010, 12:27 PM
Active Member
 
Posts: 36
Default Zimbra Ldap and TLS

Hello, i am facing a problem with the TLS authentication in my Zimbra Server. When i try to make a 'normal' bind in Zimbra ldap, its goes ok. But if i use the tls option, it's give me this error :

Quote:
May 6 11:30:30 ubuntu getent: nss-ldap: do_open: do_start_tls failed:stat=-1
May 6 11:32:27 ubuntu getent: nss-ldap: do_open: do_start_tls failed:stat=-1
May 6 11:36:56 ubuntu getent: nss-ldap: do_open: do_start_tls failed:stat=-1
My ldap.conf :

Quote:
host marechal
base dc=marechal,dc=saude,dc=al,dc=gov,dc=br
binddn uid=zimbra,cn=admins,cn=zimbra
bindpw MYPASSWD
rootbinddn uid=zimbra,cn=admins,cn=zimbra
port 389
bind_policy soft
nss_reconnect_tries 2
uri ldap://marechal/
ssl start_tls
tls_cacertdir /opt/ca
tls_checkpeer no
I copied the files from my Zimbra Server ( /opt/zimbra/conf/ca ) to my other machine ( /opt/ca ) and i put a chmod 777 in the directory.

Someone its the same problem or maybe know how i can fix this.

Thanks
Reply With Quote
  #2 (permalink)  
Old 05-10-2010, 05:54 AM
Active Member
 
Posts: 36
Default

sorry the double post, but anyone have some idea how i can fix this problem, i really need this to make my integrations with success specially with Samba, and posts here goes down really fast ...
Reply With Quote
  #3 (permalink)  
Old 05-10-2010, 06:57 AM
Moderator
 
Posts: 1,209
Default

More often than not this is caused by a certificate issue.

There is a certificate SSL troubleshooting wiki article that may help.

I would also check bugzilla, and the forums here searching for terms like "secure interprocess communications".

Hope that helps get you started,
Mark
__________________
___________________________________
L. Mark Stone, CIO


"Uptime. All the time."

477 Congress Street | Portland, ME 04101-3431 | (207) 772-5678

proactive maintenance and monitoring | technology consulting
Zimbra groupware | EMR implementations | private cloud hosting
Reply With Quote
  #4 (permalink)  
Old 10-18-2010, 10:56 AM
Trained Alumni
 
Posts: 336
Default

did you ever solve this?
happening the same here.
thanks
__________________
YetOpen S.r.l. ~ Your open source partner
Lecco (LC) - ITALY
http://www.yetopen.it
Reply With Quote
  #5 (permalink)  
Old 10-18-2010, 11:01 AM
Active Member
 
Posts: 36
Default

no, i'm using without TLS at the moment. If anyone know how i use the tls with success, please, let me know too.
Reply With Quote
  #6 (permalink)  
Old 10-18-2010, 11:07 AM
Trained Alumni
 
Posts: 336
Default

I did more than one install of Z+AD, most on Debian and Ubuntu 8.04, and never got this warning.
Now the latest install was on 10.04, and even tough I can fetch user data from ldap (users, groups...) I get this annoying message flooding in syslog
__________________
YetOpen S.r.l. ~ Your open source partner
Lecco (LC) - ITALY
http://www.yetopen.it
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.