Emmanuel Dreyfus email@example.com wrote:
Read the slapd.conf(5) or slapd-config(5) manpage. You must configure the TLSDHParamFile.
It works fine. I thought I had a problem with MacOS X machines causing "TLS negotiation faied" messages, but they also do it without the change. It seems each time I type "id some_user" in MacOS X's shell, it will always attempt a first TCP connexion to the LDAP server, fail TLS without sending anything, and then attempt a second TCP connexion with TLS.
Weird. I don't ask for an answer on this question but just post it for future reference in case someone has the same behavior: this TLS negotiation failure is not a failure.