Skip to content

Commit

Permalink
Remove LDAP_TLS_PROTOCOL_MIN as it does not take effect
Browse files Browse the repository at this point in the history
  • Loading branch information
jgehrcke committed Jul 20, 2016
1 parent aa8d557 commit c7cdcbb
Show file tree
Hide file tree
Showing 8 changed files with 4 additions and 10 deletions.
4 changes: 4 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
# Changelog

## 1.1.4
Remove TLS environment variable LDAP_TLS_PROTOCOL_MIN, see #69


## 1.1.3
Merge pull request :
- Use mdb over hdb #50
Expand Down
1 change: 0 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -254,7 +254,6 @@ TLS options:
- **LDAP_TLS_CA_CRT_FILENAME**: Ldap ssl CA certificate filename. Defaults to `ca.crt`
- **LDAP_TLS_ENFORCE**: Enforce TLS. Defaults to `false`
- **LDAP_TLS_CIPHER_SUITE**: TLS cipher suite. Defaults to `SECURE256:-VERS-SSL3.0`
- **LDAP_TLS_PROTOCOL_MIN**: TLS min protocol. Defaults to `3.1`
- **LDAP_TLS_VERIFY_CLIENT**: TLS verify client. Defaults to `demand`

Help: http://www.openldap.org/doc/admin24/tls.html
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,6 @@ LDAP_TLS_CA_CRT_FILENAME: ca.crt

LDAP_TLS_ENFORCE: false
LDAP_TLS_CIPHER_SUITE: SECURE256:-VERS-SSL3.0
LDAP_TLS_PROTOCOL_MIN: 3.1
LDAP_TLS_VERIFY_CLIENT: never

# Replication
Expand Down
2 changes: 0 additions & 2 deletions example/kubernetes/simple/ldap-rc.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -55,8 +55,6 @@ spec:
value: "false"
- name: LDAP_TLS_CIPHER_SUITE
value: "SECURE256:-VERS-SSL3.0"
- name: LDAP_TLS_PROTOCOL_MIN
value: "3.1"
- name: LDAP_TLS_VERIFY_CLIENT
value: "demand"
- name: LDAP_REPLICATION
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,6 @@ LDAP_TLS_CA_CRT_FILENAME: ca.crt

LDAP_TLS_ENFORCE: false
LDAP_TLS_CIPHER_SUITE: SECURE256:-VERS-SSL3.0
LDAP_TLS_PROTOCOL_MIN: 3.1
LDAP_TLS_VERIFY_CLIENT: never

# Replication
Expand Down
1 change: 0 additions & 1 deletion image/environment/default.yaml.startup
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,6 @@ LDAP_TLS_CA_CRT_FILENAME: ca.crt

LDAP_TLS_ENFORCE: false
LDAP_TLS_CIPHER_SUITE: SECURE256:-VERS-SSL3.0
LDAP_TLS_PROTOCOL_MIN: 3.1
LDAP_TLS_VERIFY_CLIENT: demand

# Replication
Expand Down
3 changes: 0 additions & 3 deletions image/service/slapd/assets/config/tls/tls-enable.ldif
Original file line number Diff line number Diff line change
Expand Up @@ -3,9 +3,6 @@ changetype: modify
replace: olcTLSCipherSuite
olcTLSCipherSuite: {{ LDAP_TLS_CIPHER_SUITE }}
-
replace: olcTLSProtocolMin
olcTLSProtocolMin: {{ LDAP_TLS_PROTOCOL_MIN }}
-
replace: olcTLSCACertificateFile
olcTLSCACertificateFile: {{ LDAP_TLS_CA_CRT_PATH }}
-
Expand Down
1 change: 0 additions & 1 deletion image/service/slapd/startup.sh
Original file line number Diff line number Diff line change
Expand Up @@ -242,7 +242,6 @@ EOF
sed -i "s|{{ LDAP_TLS_DH_PARAM_PATH }}|${LDAP_TLS_DH_PARAM_PATH}|g" ${CONTAINER_SERVICE_DIR}/slapd/assets/config/tls/tls-enable.ldif

sed -i "s|{{ LDAP_TLS_CIPHER_SUITE }}|${LDAP_TLS_CIPHER_SUITE}|g" ${CONTAINER_SERVICE_DIR}/slapd/assets/config/tls/tls-enable.ldif
sed -i "s|{{ LDAP_TLS_PROTOCOL_MIN }}|${LDAP_TLS_PROTOCOL_MIN}|g" ${CONTAINER_SERVICE_DIR}/slapd/assets/config/tls/tls-enable.ldif
sed -i "s|{{ LDAP_TLS_VERIFY_CLIENT }}|${LDAP_TLS_VERIFY_CLIENT}|g" ${CONTAINER_SERVICE_DIR}/slapd/assets/config/tls/tls-enable.ldif

ldapmodify -Y EXTERNAL -Q -H ldapi:/// -f ${CONTAINER_SERVICE_DIR}/slapd/assets/config/tls/tls-enable.ldif 2>&1 | log-helper debug
Expand Down

0 comments on commit c7cdcbb

Please sign in to comment.