-
Bug
-
Resolution: Unresolved
-
Major
-
rhel-10.2
-
None
-
None
-
None
-
rhel-idm-ds
-
None
-
False
-
False
-
-
None
-
None
-
None
-
None
-
Unspecified
-
Unspecified
-
Unspecified
-
None
For post-quantum cryptography migration, it is expected that a deployment might be in a transitional state where some clients will understand PQC algorithms and some aren't yet. Therefore, 389-ds LDAP server needs to be able to negotiate LDAPS or LDAP+startTLS with both types of clients by providing both ML-DSA and RSA/EC certificates.
This is already possible when configured manually but dsconf tool hardcodes a certificate name (CN) to Server-Cert, making it impossible to add multiple certificates through the dsconf tool.