Topic: Fails to configure LDAP over TLS
==== Required information ====
- iRedMail version (check /etc/iredmail-release): 0.9.5.-1
- Linux/BSD distribution name and version: Ubuntu 14.04
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): LDAP
- Web server (Apache or Nginx): Nginx
- Manage mail accounts with iRedAdmin-Pro? No
- Related log if you're reporting an issue:
====
Hi!
Is there a need in the address book access LDAP from outside the network. Use LetsEncrypt SSL certificate.
Trying to configure in accordance with this instruction: http://www.iredmail.org/docs/use.a.boug … cate.html.
In /etc/ldap/slapd.conf made the following changes:
TLSCACertificateFile /etc/letsencrypt/live/mail.mydomain.ru/fullchain.pem
TLSCertificateFile /etc/letsencrypt/live/mail.mydomain.ru/cert.pem
TLSCertificateKeyFile /etc/letsencrypt/live/mail.mydomain.ru/privkey.pem
After these changes, slapd does not start.
In the logs appears the next error:
....
Sep 4 16:14:05 mail slapd[1016]: main: TLS init def ctx failed: -1
Sep 4 16:14:05 mail slapd[1016]: slapd destroy: freeing system resources.
Sep 4 16:14:05 mail slapd[1016]: slapd stopped.
Sep 4 16:14:05 mail slapd[1016]: connections_destroy: nothing to destroy.
What am I doing wrong?
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.