Two OpenLDAP TLS gotchas

The scenario: You’re using CentOS 7 or RHEL 7. You’re using OpenLDAP. You have TLS set up on OpenLDAP. You are trying to perform a query against the server using ldapsearch. Problem #1: You get: ldap_start_tls: Can’t contact LDAP server (-1) ldap_sasl_bind(SIMPLE): Can’t contact LDAP server (-1) Possible solution: You’re using the -Z option (along with -h and -p) to specify the host and port and request TLS.…

