- Sep 06, 2011
-
-
-
Quanah Gibson-Mount authored
-
In tlsm_auth_cert_handler, we get the peer's cert from the socket using SSL_PeerCertificate. This value is allocated and/or cached. We must destroy it using CERT_DestroyCertificate.
-
Quanah Gibson-Mount authored
-
add hex timestamp to lutil_debug() output Fix LASTMOD race condition in accesslog.c Set refreshInterval even if using refreshAndPersist, since fallbacks will use refresh params
-
-
-
-
-
-
-
-
-
Quanah Gibson-Mount authored
-
-
-
- Sep 02, 2011
-
-
Quanah Gibson-Mount authored
-
- Jun 30, 2011
-
- Jun 28, 2011
-
-
Quanah Gibson-Mount authored
-
Howard Chu authored
-
- Jun 27, 2011
-
-
-
Quanah Gibson-Mount authored
Merge branch 'OPENLDAP_REL_ENG_2_4' of ssh://git-master.openldap.org/~git/git/openldap into OPENLDAP_REL_ENG_2_4
-
-
-
-
- Jun 25, 2011
-
-
Howard Chu authored
-
- Jun 24, 2011
-
-
Howard Chu authored
-
Howard Chu authored
-
- Jun 23, 2011
-
-
- Jun 22, 2011
-
-
Quanah Gibson-Mount authored
-
-
track a CSN per SID in the log->sl_mincsn
-
-
Quanah Gibson-Mount authored
-
Should SLAP_AUTH_DN be #defined in release now?
-
Quanah Gibson-Mount authored
ITS#6975
-
-
OpenLDAP built with OpenSSL allows most any value of cacertdir - directory is a file, directory does not contain any CA certs, directory does not exist - users expect if they specify TLS_REQCERT=never, no matter what the TLS_CACERTDIR setting is, TLS/SSL will just work. TLS_CACERT, on the other hand, is a hard error. Even if TLS_REQCERT=never, if TLS_CACERT is specified and is not a valid CA cert file, TLS/SSL will fail. This patch makes CACERT errors hard errors, and makes CACERTDIR errors "soft" errors. The code checks CACERT first and, even though the function will return an error, checks CACERTDIR anyway so that if the user sets TRACE mode they will get CACERTDIR processing messages.
-
- Jun 21, 2011
-
-
Quanah Gibson-Mount authored
-
-