Re: Bind using a user other than organizationalRole user
Owen Marshall <[email protected]> Wed, 07 Apr 2010 09:42:50 -0400
| Newsgroups | gmane.network.openldap.general |
|---|---|
| Organization | FacilityONE |
| Message-ID | <1270647770.27600.7.camel@c2ltomarshall> |
On Tue, 2010-04-06 at 13:28 -0500, Marcelo de Moraes Serpa wrote: > Or maybe some ACL configuration I am missing that is somehow affecting > the read access to userPassword for the specific DN. I'd bet this is the case. In general: if you haven't explicitly defined an ACL, OpenLDAP is configured to allow anonymous reads -- this is *not* sufficient to auth. You will want to allow anonymous auth to the appropriate DNs. Use ACL debugging (olcLogLevel 128) to verify. Also, slapacl is a useful tool you can use to verify your ACL setup. Some worked ACL examples can be found here: http://www.zytrax.com/books/ldap/ch6/#access -- Owen Marshall FacilityONE [email protected] | (502) 805-2126
signature.asc
(application/pgp-signature, 197 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEABECAAYFAku8i9YACgkQcoY1cxL6GH2rtQCfYSu4m739XgUoo7eb74ku3hrb HoMAn3BEyt0BaxJzbtC/Gde9gtubz1lh =hclX -----END PGP SIGNATURE-----