Re: slapd access to private key owned by root

2023-03-05 Thread Andy Smith
Hello, On Sun, Mar 05, 2023 at 09:08:57AM +0800, jeremy ardley wrote: > The problem is when I try and configure private keys for ldap TLS the > permissions are checked and if it's not owned by openldap and permissions > 400 or 600 the configuration fails. > > Is there a known solution to this pro

slapd access to private key owned by root

2023-03-04 Thread jeremy ardley
I think the problem is probably unsolvable but I thought I'd ask. I understand slapd starts as user root and reads config etc and then changes to user openldap This means that it could potentially read a private key owned by root during startup? The problem is when I try and configure priva