This file is indexed.

/etc/ldap/ssl/slapd-cert.cnf is in debian-edu-config 1.702.

This file is owned by root:root, with mode 0o644.

The actual contents of the file can be viewed below.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
RANDOM=/dev/random

[ req ]
default_bits = 1024
encrypt_key = yes
distinguished_name = req_dn
x509_extensions = v3_req
prompt = no

[ req_dn ]
C=NO
ST=NA
L=Skolen
O=LDAP server
OU=Automatically-generated LDAP SSL key

###
### run LDAP service on main server (tjener) -> default
### make sure CN is also one of subjectAltName
###
CN=tjener.intern
emailAddress=postmaster@postoffice.intern

[ v3_req ]
nsCertType = server
subjectAltName=DNS:tjener.intern,DNS:tjener,DNS:ldap.intern,DNS:ldap,DNS:localhost

###
### run LDAP service on a separate machine 
### (server's IP must revresolv to ldap.intern)
###
#CN=ldap.intern
#emailAddress=postmaster@postoffice.intern

#[ v3_req ]
#nsCertType = server
#subjectAltName=DNS:ldap.intern,DNS:ldap,DNS:localhost