Is TLSv1.3 required on PBS 3.1 for LDAP authentication?

f4242

Well-Known Member
Dec 19, 2016
101
4
58
Quebec, QC
Hello,

I upgraded my first PBS server to 3.1 today. LDAP authentication is failing with that error :

Feb 6 15:35:40 backup-pbs backup-pbs proxmox-backup-api[762]: authentication failure; rhost=[::ffff:10.x.x.x]:44696 user=myuser@ldap msg=native TLS error: error:0A000152:SSL routines:final_renegotiate:unsafe legacy renegotiation disabled:../ssl/statem/extensions.c:893:

The LDAP backend is Samba on Ubuntu 16.04 ESM (yeah, I know, it needs upgrade!). Samba is logging: "A TLS fatal alert has been received".

I wonder if PBS 3.x now requires TLSv1.3. Is there a way to configure it to allow the use of TLSv1.2 until we upgrade our DCs? I looked inside /etc/proxmox-backup-server but didn't find anything.

Thanks.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!