--On Tuesday, August 20, 2024 10:06 AM +0000 c.venugopal521@gmail.com wrote:
Thank you for update.
Have few queries on this. Could you please clarify them?
- Is there any reason for dropping Mozilla NSS support with latest
versions of OpenLDAP?
RedHat had a project at one point where they were going to try and unify everything on MozNSS. MozNSS was already abandonware for good reason, but RH persisted with this effort despite being warned it was not a great idea. Eventually it fell apart as expected and they dropped this effort. The code was only added to OpenLDAP to support RH's effort. After RH realized the futility of the idea and abandoned it, the code was removed from OpenLDAP.
- Can we compile OpenLDAP 2.6.8 by taking 'tls_m.c' module from OpenLDAP
2.4.59 (where OpenLDAP support NSS) and use NSS certdb for TLS communication? Is it possible to use seamlessly?
No.
--Quanah