Skip to content

Commit ba69ea1

Browse files
committed
always install ldap ca
seems to be needed for replication, which makes sense.
1 parent 28c1e32 commit ba69ea1

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

ldap/ldap/start-ldap.sh

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,9 +25,12 @@ DEBIAN_FRONTEND=noninteractive dpkg -i /slapd*.deb
2525

2626
echo "Installing slapd configuration"
2727

28+
cat << _EOF_ >> /etc/ldap/slapd.d/cn=config.ldif
29+
olcTLSCACertificateFile: ${CA:?}
30+
_EOF_
31+
2832
if [ ! -z "${KEYFILE:-}" ]; then
2933
cat << _EOF_ >> /etc/ldap/slapd.d/cn=config.ldif
30-
olcTLSCACertificateFile: ${CA:?}
3134
olcTLSVerifyClient: never
3235
olcTLSCertificateFile: ${CERTFILE:?}
3336
olcTLSCertificateKeyFile: ${KEYFILE:?}

0 commit comments

Comments
 (0)