SUSE Support

Here When You Need Us

How to set the minimum protocol for openldap client connection

This document (7016403) is provided subject to the disclaimer at the end of this document.

Environment

SUSE Linux Enterprise Server 11

Situation

LDAP server requires a minimum of TLSv1 for a client connection.

Connection is disconnected after openldap client sends an SSLv2 Hello

Some servers do not negotiate to a higher protocol but will immediately close the connection if a lower protocol connection is initiated.

Default openldap client configuration.

Resolution

On SLES 11, the openldap client can set TLS_PROTOCOL_MIN in the /etc/openldap/ldap.conf file.  This setting takes the following values:  a.b   where a=major version and b=minor version.  EX:   if a=2 then SSLv2 and up will be supported.  If a=3 then TLSv1

For more information, see the discussion at http://www.openldap.org/its/index.cgi/Software%20Enhancements?id=5655

Additional Information

Documentation update has been requested to include information about the use of this parameter.

Disclaimer

This Support Knowledgebase provides a valuable tool for SUSE customers and parties interested in our products and solutions to acquire information, ideas and learn from one another. Materials are provided for informational, personal or non-commercial use within your organization and are presented "AS IS" WITHOUT WARRANTY OF ANY KIND.

  • Document ID:7016403
  • Creation Date: 07-Apr-2015
  • Modified Date:18-Oct-2022
    • SUSE Linux Enterprise Server

< Back to Support Search

For questions or concerns with the SUSE Knowledgebase please contact: tidfeedback[at]suse.com

SUSE Support Forums

Get your questions answered by experienced Sys Ops or interact with other SUSE community experts.

Support Resources

Learn how to get the most from the technical support you receive with your SUSE Subscription, Premium Support, Academic Program, or Partner Program.

Open an Incident

Open an incident with SUSE Technical Support, manage your subscriptions, download patches, or manage user access.