Re: Bind using a user other than organizationalRole user

Owen Marshall <[email protected]> Wed, 07 Apr 2010 09:42:50 -0400
Newsgroups gmane.network.openldap.general
Organization FacilityONE
Message-ID <1270647770.27600.7.camel@c2ltomarshall>
On Tue, 2010-04-06 at 13:28 -0500, Marcelo de Moraes Serpa wrote:
> Or maybe some ACL configuration I am missing that is somehow affecting
> the read access to userPassword for the specific DN.

I'd bet this is the case.

In general: if you haven't explicitly defined an ACL, OpenLDAP is
configured to allow anonymous reads -- this is *not* sufficient to auth.
You will want to allow anonymous auth to the appropriate DNs.

Use ACL debugging (olcLogLevel 128) to verify. Also, slapacl is a useful
tool you can use to verify your ACL setup.

Some worked ACL examples can be found here:
http://www.zytrax.com/books/ldap/ch6/#access

-- 
Owen Marshall
FacilityONE
[email protected] | (502) 805-2126
signature.asc (application/pgp-signature, 197 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEABECAAYFAku8i9YACgkQcoY1cxL6GH2rtQCfYSu4m739XgUoo7eb74ku3hrb
HoMAn3BEyt0BaxJzbtC/Gde9gtubz1lh
=hclX
-----END PGP SIGNATURE-----