Hello,
After Renewing the complete SSL chain sdb.univention.de/content/15/332 … chain.html and changing the hostname of the server; the server started to throw the following errors on listener.log
====
{‘info’: ‘TLS: hostname does not match CN in peer certificate’, ‘desc’: ‘Connect error’}
UNIVENTION_DEBUG_END : uldap.__open host=mail port=7389 base=dc=airesistemas,dc=com
29.07.15 09:10:01.676 DEBUG_INIT
UNIVENTION_DEBUG_BEGIN : uldap.__open host=mail port=7389 base=dc=airesistemas,dc=com
29.07.15 09:10:01.687 LISTENER ( ERROR ) : ox-groups: handler failed: dn=‘cn=Printer-Admins,cn=g roups,dc=airesistemas,dc=com’
Traceback (most recent call last):
File “/usr/lib/pymodules/python2.6/univention/ox/listener_tools.py”, line 176, in process
result = func(dn, entry.new, entry.old, entry.action)
File “/usr/lib/univention-directory-listener/system/ox-groups.py”, line 78, in handler
ldapCon = univention.uldap.getMachineConnection(ldap_master=False)
File “/usr/lib/pymodules/python2.6/univention/uldap.py”, line 109, in getMachineConnection
lo=access(host=ucr[‘ldap/server/name’], port=port, base=ucr[‘ldap/base’], binddn=ucr[‘ldap/hostdn’ ], bindpw=bindpw, start_tls=start_tls, decode_ignorelist=decode_ignorelist, reconnect=reconnect)
File “/usr/lib/pymodules/python2.6/univention/uldap.py”, line 184, in init
self.__open(ca_certfile)
File “/usr/lib/pymodules/python2.6/univention/uldap.py”, line 231, in __open
self.lo.start_tls_s()
File “/usr/lib/python2.6/dist-packages/ldap/ldapobject.py”, line 784, in start_tls_s
res = SimpleLDAPObject.start_tls_s(self)
File “/usr/lib/python2.6/dist-packages/ldap/ldapobject.py”, line 526, in start_tls_s
return self._ldap_call(self._l.start_tls_s)
File “/usr/lib/python2.6/dist-packages/ldap/ldapobject.py”, line 96, in _ldap_call
result = func(*args,**kwargs)
CONNECT_ERROR: {‘info’: ‘TLS: hostname does not match CN in peer certificate’, ‘desc’: ‘Connect error’ }
=========
Same happened to all the services like postfix
==========
Jul 29 09:24:27 mail postfix/pickup[4688]: warning: BBB25104993: message has been queued for 12 days
Jul 29 09:24:27 mail postfix/pickup[4688]: BBB25104993: uid=0 from=
Jul 29 09:24:27 mail postfix/cleanup[26509]: error: dict_ldap_connect: Unable to set STARTTLS: -11: Connect error
Jul 29 09:24:27 mail postfix/cleanup[26509]: warning: BBB25104993: virtual_alias_maps map lookup problem for root@mail.airesistemas.com
I am unable to check license and or import licensing. Please, we need to know step by step changes required to do on the system services ( cyrus, postfix, listener.. etc) to get a functional server after changing hostname or Certificate on UCS.
Full univention-support-info upload_0aAty2.bz2
Rolando Riley