1

Topic: LDAP Problem

Hi there,

got some troubles with starting slapd. Recently I tried to configure all services with let´s encrypt ssl certificate.

root@mail:/var/log# cat /etc/iredmail-release
0.9.8 OPENLDAP edition.
# Get professional support from iRedMail Team: https://www.iredmail.org/support.html

Ubuntu 18.04.1
LDAP
Nginx
IredAdmin normal

root@mail:/var/log# systemctl status slapd.service
● slapd.service - LSB: OpenLDAP standalone server (Lightweight Directory Access Protocol)
   Loaded: loaded (/etc/init.d/slapd; generated)
   Active: failed (Result: exit-code) since Sat 2018-12-22 18:10:00 UTC; 36s ago
     Docs: man:systemd-sysv-generator(8)
  Process: 23339 ExecStart=/etc/init.d/slapd start (code=exited, status=1/FAILURE)

Dec 22 18:10:00 mail slapd[23366]: @(#) $OpenLDAP: slapd  (Ubuntu) (Oct 23 2018 13:01:47) $
                                           Debian OpenLDAP Maintainers <pkg-openldap-devel@lists.alioth.debian.org>
Dec 22 18:10:00 mail slapd[23366]: main: TLS init def ctx failed: -1
Dec 22 18:10:00 mail slapd[23366]: DIGEST-MD5 common mech free
Dec 22 18:10:00 mail slapd[23366]: DIGEST-MD5 common mech free
Dec 22 18:10:00 mail slapd[23366]: slapd stopped.
Dec 22 18:10:00 mail slapd[23366]: connections_destroy: nothing to destroy.
Dec 22 18:10:00 mail slapd[23339]:    ...fail!
Dec 22 18:10:00 mail systemd[1]: slapd.service: Control process exited, code=exited status=1
Dec 22 18:10:00 mail systemd[1]: slapd.service: Failed with result 'exit-code'.
Dec 22 18:10:00 mail systemd[1]: Failed to start LSB: OpenLDAP standalone server (Lightweight Directory Access Protocol)

----

Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.

2

Re: LDAP Problem

- How did you configure letsencrypt cert? We have a tutorial for you: https://docs.iredmail.org/letsencrypt.html
- Does OpenLDAP daemon user have privilege to access letsencrypt cert?
- If openldap is only serving local requests, it's better to disable ssl cert in /etc/ldap/slapd.conf.