1 |
#BASE dc=example, dc=com |
2 |
#HOST ldap.example.com ldap-master.example.com |
3 |
#URI ldap://ldap.example.com ldap://ldap-master.example.com:666 |
4 |
|
5 |
#SIZELIMIT 12 |
6 |
#TIMELIMIT 15 |
7 |
#DEREF never |
8 |
|
9 |
# SSL/TSL configuration. With CA-signed certs, TLS_REQCERT should be |
10 |
# "demand", with the CA certificate accessible |
11 |
#TLS_REQCERT ([demand],never,allow,try) |
12 |
# We ship with allow by default as some LDAP clients (e.g. evolution) have |
13 |
# no interactive SSL configuration |
14 |
|
15 |
TLS_REQCERT allow |
16 |
|
17 |
# CA Certificate locations |
18 |
# Use the default self-signed cert generated by openldap-server postinstall |
19 |
# by default |
20 |
#TLS_CACERT /etc/pki/tls/certs/ldap.pem |
21 |
#TLS_CACERT /etc/ssl/openldap/ldap.mageia.org.pem |
22 |
|
23 |
# If requiring support for certificates signed by all CAs (noting risks |
24 |
# pam_ldap if doing DNS-based suffix lookup etc. |
25 |
#TLS_CACERTDIR /etc/pki/tls/rootcerts |
26 |
|