[Fedora-directory-users] Re: SubjectAltName how does it work?

Alex magobin at gmail.com
Tue Apr 11 19:52:37 UTC 2006


 
> You are doing a couple of odd things:
> 
> 1. Why does nodo1 get it's own nickname but nodo2 is named 
> Alt-Cert? As I've said before, the nicknames aren't 
> important, but you should have some sort of naming policy.
> 2. You may need to fully qualify the cn in the certificates: 
> nodo1.domain.example.com. This alone could explain the -12276 
> error. I don't know if NSS will reconstitute the domain from 
> it's dc components.
> 
> Does ldapsearch work against each fully-qualified host? Get 
> ldapsearch working for the CN and for the alt subject first 
> before trying to do MMR.
> 
> rob
> 
Alt-Cert is only for tips from you
...tomorrow I'll try to make a certificate for nodo2 as
nodo2.domain.example.com
Sincerely I still don't understand where is the problem; At this point I
think that I explained in bad way what is my goal. I follow your tip,
assuming that -n Alt-Cert was something more that only a nickname for cert.

Plus....in my last post I used fqdn for nodo1 and Alt-Cert for reason above,
do U think that all problems are from an error about -n statement?


Susan....I explained why floating ip...give me another solution that permit
to have 2 DS in Replication where clients can query/authenticate in encrypt
mode on both server...even if a server is shutted or crashed...of
course...say me how to implement too ;-)

At this point I think that we are very (how do you say vicino??....closed??)
to the solution....when finally DS replicating and client can authenticate
with ssl on both server...other problem such as postfix integration and
samba integration is only a time issue! 

Thanks for your support
Alex





More information about the Fedora-directory-users mailing list