On 27.10.2016. 17:15, COMBES Julien - SG/SPSSI/CPII/DOSE/ET/PNE ANNUAIRE ET MESSAGERIE wrote:
Due to a decision of our IT Departement, I have to change the domain name of ours openldap servers and by extention all of their certificates.
[...]
I have tried a solution with stunnel which listens on an other IP address with a new certificate. But, as the connection from the stunnel to the ldap server comes from localhost and not from the original client
You could try the transparent source mode of stunnel if your kernel supports it.
Regards,