[Madlug] ldap self-signed cert

John Heim jheim at math.wisc.edu
Tue Oct 23 15:54:56 CDT 2007


So for my next trick, I intend to set up an ldap server. But I am confused 
about self-signed certificates. I've created self-signed certs for a 
development apache server and for dovecot. I used the same self-signed cert 
for both of those services. I would imagine I could use it for ldap too. But 
why do all the howtos out there explain how to generate a cert for each 
service?

For example, most of the apache howtos show how to generate a cert in 
/etc/apache2/ssl/. And for ldap they tend to show a process of generating it 
in /etc/ldap/.  Even if people tend to have just one such service on a 
machine, you'd think there'd be a standard, application-neutral place to 
generate self-signed certs.

So I'm wondering if generally people use different certs for each service or 
if all these howtos are kind of wrong (in a very small way).


--
John Heim
jheim at math.wisc.edu / 608-263-4189
"An operator of a vehicle shall stop the vehicle before approaching closer 
than 10 feet to a pedestrian who is using a service animal"
-- Wisconsin Statute 2005 Act 354,



More information about the Madlug mailing list