From: Xeno Campanoli Date: 2009-06-02T04:45:45+09:00 Subject: Re: Something Not going with my LDAP using SSL Xeno Campanoli wrote: > Brian Candler wrote: >> Xeno Campanoli wrote: >>> 11:11:51.716923 IP 192.168.141.130.44841 > 192.168.139.157.636: R >>> 3432003446:3432003446(0) win 0 >>> 0x0000: 4500 0028 0000 4000 4006 a05f c0a8 8d82 E..(..@.@.._.... >>> 0x0010: c0a8 8b9d af29 027c cc90 3776 0000 0000 .....).|..7v.... >>> 0x0020: 5004 0000 5fc3 0000 P..._... >> >> Odd, I think this shows it was the client (on dynamic port 44841) >> which closes the connection by sending a RST to the server. But why >> not a normal FIN? >> >> I suspect this is not a certificate problem - a lot of negotiation has >> taken place since the server sent its certificate - but I cannot be >> sure of that. >> >> What about openssl s_client -connect 192.168.139.157:636 ? What does >> that show? >> > STDOUT ends with the following... > > SSL-Session: > Protocol : TLSv1 > Cipher : RC4-MD5 > Session-ID: > 46AEE896A3CB7B0C0044D1169EA9672E769D7BF64194F96D8378D08D750D60AA > Session-ID-ctx: > Master-Key: > FEADCD684F8CCEEA674C2D725D6BB5E4C1716B877C2B6B176E1C5BD0590D0CDFA28CC93BEB07548C997BD6B2FAB7009F > > Key-Arg : None > Start Time: 1243885042 > Timeout : 300 (sec) > Verify return code: 19 (self signed certificate in certificate chain) > > I think we had a different response Friday. Is it possible that install of libopenssl-ruby has changed the cert location?