From aec5adac17c4253ff92a9e55e27710bc86a8b93e Mon Sep 17 00:00:00 2001 From: Howard Chu Date: Wed, 2 Feb 2011 20:06:28 +0000 Subject: [PATCH] ITS#6711 use idassert TLS conf for priv connection if aclbind not set --- servers/slapd/back-ldap/bind.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/servers/slapd/back-ldap/bind.c b/servers/slapd/back-ldap/bind.c index 42e9504925..c67152b7f7 100644 --- a/servers/slapd/back-ldap/bind.c +++ b/servers/slapd/back-ldap/bind.c @@ -710,7 +710,12 @@ ldap_back_prepare_conn( ldapconn_t *lc, Operation *op, SlapReply *rs, ldap_back_ #ifdef HAVE_TLS if ( LDAP_BACK_CONN_ISPRIV( lc ) ) { - sb = &li->li_acl; + /* See "rationale:" comment in ldap_back_getconn() */ + if ( BER_BVISNULL( &li->li_acl_authcDN ) && + !BER_BVISNULL( &li->li_idassert_authcDN ) ) + sb = &li->li_idassert.si_bc; + else + sb = &li->li_acl; } else if ( LDAP_BACK_CONN_ISIDASSERT( lc ) ) { sb = &li->li_idassert.si_bc; -- 2.39.5