From: Xeno Campanoli Date: 2009-06-02T02:30:06+09:00 Subject: Re: Something Not going with my LDAP using SSL Brian Candler wrote: > Xeno Campanoli wrote: >> But when I try to run it with SSL, I get a failure saying "Can't connect >> LDAP >> Server". > My apologies for dropping this before Brian. I just found it in my trash, so I must have knocked it when I was in a hurry. I always appreciate attempts to help, and you were right that I had not yet installed the libopenssl-ruby package in my ubuntu. However, I just did install it, and so far to no avail. I am rebooting, and... after logging in I still get the same problem where I never get to trace 4, but instead have: trace 5 oops, Can't contact LDAP server As to your comment below, I really appreciate that too. However, the script I describe works on other machines, most specifically CentOS and RedHat5, and a RedHat4 I think, with the same port numbers and other specifications, so the main difference appears to be the way the Ruby stuff is installed on Ubuntu. On fellow who was assisting me was also able to do openssl tool checks on my system that showed he could do all the proper functions at that level, so we are apparently left with some combination of Ubuntu and Ruby and OpenSSL that is not functioning properly. That doesn't mean I haven't done something stupid, but I did install a 9.04 OS just to test this problem, and I tried to step though everything I could think of both methodically and minimally and we just don't get it to go on either that system, or the production 8.04 system. I will be able to work on this problem at intervals for the next couple of days because of the potential value of this, so of you can instruct me on other things to try I will try to get them done with fast turnaround. My apologies if I have left any other item off which should be obvious, and thank you once again for all your energies. Sincerely, Xeno > It looks like you are trying to connect to the LDAPS service on port > 636. Are you sure your server implements this? Try: > > telnet myldaphost 636 > > Do you get connection accepted, or rejected? > > If it is accepted, then try > > openssl s_client -connect myldaphost:636 > > Is SSL successfully negotiated? > > The reason I ask is because there is another, completely different way > of doing LDAP with SSL (using the STARTTLS extension on port 389). Maybe > this is what your server implements instead.