TLSMC: MozNSS compatibility interception begins message

Arran Cudbard-Bell a.cudbardb at
Tue Jun 5 12:03:01 CEST 2018

> On Jun 5, 2018, at 2:30 PM, Chris Howley <C.P.Howley at> wrote:
> Alan,
> Thank you for the link:
> The server is using PEAP-MSCHAPv2 and LDAP not LDAPS. The messages are generated only when the server is started.
> Am I correct in assuming that I can safely ignore the messages?

If you're not using LDAP over SSL or the Start TLS extension it's probably OK.  If you want to be absolutely sure
use the OpenLDAP LTB packages which are built against OpenSSL.

> If I want to use LDAPS in the future, is the FR message below telling me that the server has been built
> with the correct libraries?

It's telling you that the libldap library is provided by OpenLDAP, and it's version 2.4.44, but doesn't tell you which
SSL provider its built against.


More information about the Freeradius-Users mailing list