e4ff3b
#
e4ff3b
# LDAP Defaults
e4ff3b
#
e4ff3b
e4ff3b
# See ldap.conf(5) for details
e4ff3b
# This file should be world readable but not world writable.
e4ff3b
e4ff3b
#BASE	dc=example,dc=com
e4ff3b
#URI	ldap://ldap.example.com ldap://ldap-master.example.com:666
e4ff3b
e4ff3b
#SIZELIMIT	12
e4ff3b
#TIMELIMIT	15
e4ff3b
#DEREF		never
e4ff3b
e4ff3b
# When no CA certificates are specified the Shared System Certificates
e4ff3b
# are in use. In order to have these available along with the ones specified
e4ff3b
# by TLS_CACERTDIR one has to include them explicitly:
e4ff3b
#TLS_CACERT	/etc/pki/tls/cert.pem
e4ff3b
e4ff3b
# System-wide Crypto Policies provide up to date cipher suite which should
e4ff3b
# be used unless one needs a finer grinded selection of ciphers. Hence, the
e4ff3b
# PROFILE=SYSTEM value represents the default behavior which is in place
e4ff3b
# when no explicit setting is used. (see openssl-ciphers(1) for more info)
e4ff3b
#TLS_CIPHER_SUITE PROFILE=SYSTEM
e4ff3b
e4ff3b
# Turning this off breaks GSSAPI used with krb5 when rdns = false
e4ff3b
SASL_NOCANON	on
e4ff3b