Le 25/04/2023 à 17:04, Quanah Gibson-Mount a écrit :
--On Tuesday, April 25, 2023 4:00 PM +0200 Benjamin Renard brenard@easter-eggs.com wrote:
Hello,
You'r right, 2.5 is available in backports, but I still preferred to used stable version for fast delivery of security update. The next release of Debian is coming soon, I will update my installations at this time.
Deliver of what security updates? OpenLDAP 2.4 is dead and hasn't been updated for 2 years. If you think Debian's backporting the security fixes going into 2.5 and 2.6, I think you'll find that's not the case.
The Debian security team always maintain the 2.4 version, even if there have not been many security updates since the switch to 2.4 :
https://metadata.ftp-master.debian.org/changelogs//main/o/openldap/openldap_...
I'll look further into the chaining configs when I have a bit more time.
Many thanks !