Topic: Centos 7 Yum Updated OpenLdap not running anymore
==== REQUIRED BASIC INFO OF YOUR IREDMAIL SERVER ====
- iRedMail version (check /etc/iredmail-release): 0.9.7
- Linux/BSD distribution name and version: centos-release-7-5.1804.el7.centos.2.x86_64
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): LDAP
- Web server (Apache or Nginx): Nginx
- Manage mail accounts with iRedAdmin-Pro? Yes
- [IMPORTANT] Related original log or error message is required if you're experiencing an issue.
====
I am planning to upgrade my iredmail 0.9.7 to 0.9.8.
Hence, i do a yum update for my centos first.
After yum update completed, i reboot my centos, i found that my iredadmin-Pro, SOGo both unable to login.
It's showing incorrect password for both websites.
For your information, i am using Let's Encrypt SSL cert and follow iredmail guidelines to create a symbolic link to the above paths.
I am able to use https to browse iredadmin-Pro and SOGo pages, login etc before i do the yum update.
I found that my ldap service is not running by running 'systemctl status slapd'
I turned on debug mode (loglevel 256) for openldap, checked the error code and found this:
Jun 20 22:07:27 testmail2 slapd[14036]: @(#) $OpenLDAP: slapd 2.4.44 (May 16 2018 09:55:53) $#012#011mockbuild@c1bm.rdu2.centos.org:/builddir/build/BUILD/openldap-2.4.44/openldap-2.4.44/servers/slapd
Jun 20 22:07:27 testmail2 slapd[14036]: main: TLS init def ctx failed: -1
Jun 20 22:07:27 testmail2 slapd[14036]: slapd stopped.
Jun 20 22:07:27 testmail2 slapd[14036]: connections_destroy: nothing to destroy.
After did a search in iredmail forum, seems like it's related to SSL cert issue.
I comment out below lines in slapd.conf then restart the slapd service:
# TLS files.
TLSCACertificateFile /etc/pki/tls/certs/iRedMail.crt
TLSCertificateFile /etc/pki/tls/certs/iRedMail.crt
TLSCertificateKeyFile /etc/pki/tls/private/iRedMail.key
slapd service is active now, and i am able to login iredadmin-Pro, SOGo.
Please may i know is it okay if i keep comment out those 3 lines?
Any clue what's going on to my mail server?
Can i proceed on to upgrade my iredmail 0.9.7 to 0.9.8 follow the official guidelines?
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.