/etc/ldap/ssl/slapd-cert.cnf is in debian-edu-config 1.702.
This file is owned by root:root, with mode 0o644.
The actual contents of the file can be viewed below.
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 | RANDOM=/dev/random
[ req ]
default_bits = 1024
encrypt_key = yes
distinguished_name = req_dn
x509_extensions = v3_req
prompt = no
[ req_dn ]
C=NO
ST=NA
L=Skolen
O=LDAP server
OU=Automatically-generated LDAP SSL key
###
### run LDAP service on main server (tjener) -> default
### make sure CN is also one of subjectAltName
###
CN=tjener.intern
emailAddress=postmaster@postoffice.intern
[ v3_req ]
nsCertType = server
subjectAltName=DNS:tjener.intern,DNS:tjener,DNS:ldap.intern,DNS:ldap,DNS:localhost
###
### run LDAP service on a separate machine
### (server's IP must revresolv to ldap.intern)
###
#CN=ldap.intern
#emailAddress=postmaster@postoffice.intern
#[ v3_req ]
#nsCertType = server
#subjectAltName=DNS:ldap.intern,DNS:ldap,DNS:localhost
|