Re: ldap auth does not works after openldap upgrade

2011-02-20 Thread masarati
On Sat, Feb 19, 2011 at 10:37 AM, Leonardo Carneiro Hey, it finally worked! I've added the follwing in the cn=config database: olcAccess: {0}to * by * read Since there was no acl rules for this cn or the bdb. I cannot thanks enough everyone that helped me, specially Andrews, Howard and

Re: ldap auth does not works after openldap upgrade

2011-02-20 Thread Leonardo Carneiro
On Sun, Feb 20, 2011 at 2:26 PM, masar...@aero.polimi.it wrote: On Sat, Feb 19, 2011 at 10:37 AM, Leonardo Carneiro Hey, it finally worked! I've added the follwing in the cn=config database: olcAccess: {0}to * by * read Since there was no acl rules for this cn or the bdb. I

Re: ldap auth does not works after openldap upgrade

2011-02-19 Thread Leonardo Carneiro
On Thu, Feb 17, 2011 at 1:03 PM, Pierangelo Masarati masar...@aero.polimi.it wrote: Dieter Kluenter wrote: Am Thu, 17 Feb 2011 11:28:59 -0200 schrieb Leonardo Carneiro chesterma...@gmail.com: On Thu, Feb 17, 2011 at 9:09 AM, Andrew Findlay andrew.find...@skills-1st.co.uk wrote: On

Re: ldap auth does not works after openldap upgrade

2011-02-19 Thread masarati
On Thu, Feb 17, 2011 at 1:03 PM, Pierangelo Masarati masar...@aero.polimi.it wrote: Dieter Kluenter wrote: Am Thu, 17 Feb 2011 11:28:59 -0200 schrieb Leonardo Carneiro chesterma...@gmail.com: On Thu, Feb 17, 2011 at 9:09 AM, Andrew Findlay andrew.find...@skills-1st.co.uk wrote: On

Re: ldap auth does not works after openldap upgrade

2011-02-19 Thread Leonardo Carneiro
On Sat, Feb 19, 2011 at 10:16 AM, masar...@aero.polimi.it wrote: On Thu, Feb 17, 2011 at 1:03 PM, Pierangelo Masarati masar...@aero.polimi.it wrote: Dieter Kluenter wrote: Am Thu, 17 Feb 2011 11:28:59 -0200 schrieb Leonardo Carneiro chesterma...@gmail.com: On Thu, Feb 17, 2011

Re: ldap auth does not works after openldap upgrade

2011-02-19 Thread Leonardo Carneiro
On Sat, Feb 19, 2011 at 10:37 AM, Leonardo Carneiro chesterma...@gmail.comwrote: On Sat, Feb 19, 2011 at 10:16 AM, masar...@aero.polimi.it wrote: On Thu, Feb 17, 2011 at 1:03 PM, Pierangelo Masarati masar...@aero.polimi.it wrote: Dieter Kluenter wrote: Am Thu, 17 Feb 2011 11:28:59

Re: ldap auth does not works after openldap upgrade

2011-02-17 Thread Andrew Findlay
On Wed, Feb 16, 2011 at 04:37:45PM -0200, Leonardo Carneiro wrote: The new slapd.d was created successfully and now i can do searches anonymously. Searches like: ldapsearch -x -h server -D cn=config -w [passwd] -b cn=config ldapsearch -x -h server -b dc=dominio,dc=com,dc=br are working

Re: ldap auth does not works after openldap upgrade

2011-02-17 Thread Buchan Milne
On Wednesday, 16 February 2011 20:37:45 Leonardo Carneiro wrote: On Wed, Feb 16, 2011 at 8:43 AM, Andrew Findlay andrew.find...@skills-1st.co.uk wrote: On Tue, Feb 15, 2011 at 05:08:43PM -0200, Leonardo Carneiro wrote: In the original question: Hello everyone, I upgraded my debian

Re: ldap auth does not works after openldap upgrade

2011-02-17 Thread Leonardo Carneiro
On Thu, Feb 17, 2011 at 7:50 AM, Buchan Milne bgmi...@staff.telkomsa.netwrote: On Wednesday, 16 February 2011 20:37:45 Leonardo Carneiro wrote: On Wed, Feb 16, 2011 at 8:43 AM, Andrew Findlay andrew.find...@skills-1st.co.uk wrote: On Tue, Feb 15, 2011 at 05:08:43PM -0200, Leonardo

Re: ldap auth does not works after openldap upgrade

2011-02-17 Thread Andrew Findlay
On Wed, Feb 16, 2011 at 03:29:45PM -0800, Howard Chu wrote: Similarly I cannot find anything that clearly describes the use of SASL EXTERNAL with ldapi. http://tools.ietf.org/html/draft-chu-ldap-ldapi-00 Excellent, thanks. That one is remarkably hard to find without a direct pointer. Could

Re: ldap auth does not works after openldap upgrade

2011-02-17 Thread Leonardo Carneiro
On Thu, Feb 17, 2011 at 9:09 AM, Andrew Findlay andrew.find...@skills-1st.co.uk wrote: On Wed, Feb 16, 2011 at 03:29:45PM -0800, Howard Chu wrote: Similarly I cannot find anything that clearly describes the use of SASL EXTERNAL with ldapi.

Re: ldap auth does not works after openldap upgrade

2011-02-17 Thread Andrew Findlay
On Thu, Feb 17, 2011 at 11:28:59AM -0200, Leonardo Carneiro wrote: Here is the search that Apache is doing. Note that usuarios in the search means users in portuguese. It doesn't seems even to check if the user really does part of the group defined in the apache config. That is a simple

Re: ldap auth does not works after openldap upgrade

2011-02-17 Thread Dieter Kluenter
Am Thu, 17 Feb 2011 11:28:59 -0200 schrieb Leonardo Carneiro chesterma...@gmail.com: On Thu, Feb 17, 2011 at 9:09 AM, Andrew Findlay andrew.find...@skills-1st.co.uk wrote: On Wed, Feb 16, 2011 at 03:29:45PM -0800, Howard Chu wrote: [...] Here is the search that Apache is doing. Note

Re: ldap auth does not works after openldap upgrade

2011-02-17 Thread Pierangelo Masarati
Dieter Kluenter wrote: Am Thu, 17 Feb 2011 11:28:59 -0200 schrieb Leonardo Carneiro chesterma...@gmail.com: On Thu, Feb 17, 2011 at 9:09 AM, Andrew Findlay andrew.find...@skills-1st.co.uk wrote: On Wed, Feb 16, 2011 at 03:29:45PM -0800, Howard Chu wrote: [...] Here is the search that

Re: ldap auth does not works after openldap upgrade

2011-02-16 Thread Andrew Findlay
On Tue, Feb 15, 2011 at 05:08:43PM -0200, Leonardo Carneiro wrote: fileserver:/etc/ldap# /usr/sbin/slapd -h ldapi:/// ldap:/// -g openldap -u openldap -F /etc/ldap/slapd.d -d 128 Aha! Your server is using LDAP-based config so it is ignoring the config file entirely. Does these changes that

Re: ldap auth does not works after openldap upgrade

2011-02-16 Thread Howard Chu
Andrew Findlay wrote: On Tue, Feb 15, 2011 at 05:08:43PM -0200, Leonardo Carneiro wrote: fileserver:/etc/ldap# /usr/sbin/slapd -h ldapi:/// ldap:/// -g openldap -u openldap -F /etc/ldap/slapd.d -d 128 Aha! Your server is using LDAP-based config so it is ignoring the config file entirely.

Re: ldap auth does not works after openldap upgrade

2011-02-16 Thread Andrew Findlay
On Wed, Feb 16, 2011 at 02:51:19AM -0800, Howard Chu wrote: I also suspect that there may not be a valid password set on the cn=config suffix, so you will not be able to manage the server through LDAP either. Since it's starting on ldapi:/// he should just do a SASL EXTERNAL bind on

Re: ldap auth does not works after openldap upgrade

2011-02-16 Thread Leonardo Carneiro
On Wed, Feb 16, 2011 at 8:51 AM, Howard Chu h...@symas.com wrote: Andrew Findlay wrote: On Tue, Feb 15, 2011 at 05:08:43PM -0200, Leonardo Carneiro wrote: fileserver:/etc/ldap# /usr/sbin/slapd -h ldapi:/// ldap:/// -g openldap -u openldap -F /etc/ldap/slapd.d -d 128 Aha! Your server is

Re: ldap auth does not works after openldap upgrade

2011-02-16 Thread Andrew Findlay
On Wed, Feb 16, 2011 at 10:22:58AM -0200, Leonardo Carneiro wrote: As far as i'm concerned, i didn't have the need to use SASL, and it seems that all this SASL mechanism was auto-introduced in my setup after the upgrade. Is it safe to edit /etc/defaults/slapd and remove the ldapi:///

Re: ldap auth does not works after openldap upgrade

2011-02-16 Thread Quanah Gibson-Mount
--On Wednesday, February 16, 2011 12:16 PM + Andrew Findlay andrew.find...@skills-1st.co.uk wrote: I don't have a Debian Squeeze server at present so I cannot check that. Where is this documented? I am having great trouble finding any clear description of how to actually access cn=config

Re: ldap auth does not works after openldap upgrade

2011-02-16 Thread Quanah Gibson-Mount
--On Wednesday, February 16, 2011 4:34 PM + Andrew Findlay andrew.find...@skills-1st.co.uk wrote: (2) Using ldapi: - particularly with SASL EXTERNAL, which is almost essential if you want to do a file-free bootstrap. I don't get where you're getting this idea from. I've

Re: ldap auth does not works after openldap upgrade

2011-02-16 Thread Leonardo Carneiro
On Wed, Feb 16, 2011 at 8:43 AM, Andrew Findlay andrew.find...@skills-1st.co.uk wrote: On Tue, Feb 15, 2011 at 05:08:43PM -0200, Leonardo Carneiro wrote: fileserver:/etc/ldap# /usr/sbin/slapd -h ldapi:/// ldap:/// -g openldap -u openldap -F /etc/ldap/slapd.d -d 128 Aha! Your server is

Re: ldap auth does not works after openldap upgrade

2011-02-16 Thread Howard Chu
Andrew Findlay wrote: On Wed, Feb 16, 2011 at 02:51:19AM -0800, Howard Chu wrote: I also suspect that there may not be a valid password set on the cn=config suffix, so you will not be able to manage the server through LDAP either. Since it's starting on ldapi:/// he should just do a SASL

Re: ldap auth does not works after openldap upgrade

2011-02-16 Thread Howard Chu
Leonardo Carneiro wrote: On Wed, Feb 16, 2011 at 8:51 AM, Howard Chu h...@symas.com mailto:h...@symas.com wrote: Andrew Findlay wrote: On Tue, Feb 15, 2011 at 05:08:43PM -0200, Leonardo Carneiro wrote: fileserver:/etc/ldap# /usr/sbin/slapd -h ldapi:/// ldap:/// -g

Re: ldap auth does not works after openldap upgrade

2011-02-15 Thread Andrew Findlay
On Mon, Feb 14, 2011 at 12:37:24PM -0200, Leonardo Carneiro wrote: I upgraded my debian machine from lenny to squeeze (the new stable) that comes with samba 3.5.6 and openldap 2.4.23. this machines works primarily as a PDC. these services do bind to the server, but it cannot find the users.

Re: ldap auth does not works after openldap upgrade

2011-02-15 Thread Leonardo Carneiro
On Tue, Feb 15, 2011 at 10:24 AM, Andrew Findlay andrew.find...@skills-1st.co.uk wrote: It sounds as if there is no data in the LDAP server. Debian Lenny seems to use OpenLDAP 2.4.11 with db4.2 I suspect that Squeeze uses later versions of both, so it is very unlikely to be able to read the

Re: ldap auth does not works after openldap upgrade

2011-02-15 Thread Andrew Findlay
On Tue, Feb 15, 2011 at 11:13:03AM -0200, Leonardo Carneiro wrote: The ldapsearch you gave me returned the following output: chester@reploid:~$ ldapsearch -h ldap.server -x -LLL -b '' -s base '(objectclass=*)' namingcontexts dn: namingContexts: dc=dominio,dc=com,dc=br I think It's ok,

Re: ldap auth does not works after openldap upgrade

2011-02-15 Thread Leonardo Carneiro
On Tue, Feb 15, 2011 at 11:24 AM, Andrew Findlay andrew.find...@skills-1st.co.uk wrote: On Tue, Feb 15, 2011 at 11:13:03AM -0200, Leonardo Carneiro wrote: The ldapsearch you gave me returned the following output: chester@reploid:~$ ldapsearch -h ldap.server -x -LLL -b '' -s base

Re: ldap auth does not works after openldap upgrade

2011-02-15 Thread Andrew Findlay
On Tue, Feb 15, 2011 at 11:37:59AM -0200, Leonardo Carneiro wrote: fileserver:/var/log# ldapsearch -h 127.0.0.1 -x -b dc=dominio,dc=com,dc=br '(objectclass=*)' # extended LDIF # # LDAPv3 # base dc=dominio,dc=com,dc=br with scope subtree # filter: (objectclass=*) # requesting: ALL # #

Re: ldap auth does not works after openldap upgrade

2011-02-15 Thread Andrew Findlay
On Tue, Feb 15, 2011 at 02:13:40PM -0200, Leonardo Carneiro wrote: To: Andrew Findlay andrew.find...@skills-1st.co.uk Please keep replies on the list so that other people can benefit from the discussion in future. Aha! How many entries did that search return? Was is about the same number

Re: ldap auth does not works after openldap upgrade

2011-02-15 Thread Leonardo Carneiro
On Tue, Feb 15, 2011 at 2:30 PM, Andrew Findlay andrew.find...@skills-1st.co.uk wrote: On Tue, Feb 15, 2011 at 02:13:40PM -0200, Leonardo Carneiro wrote: To: Andrew Findlay andrew.find...@skills-1st.co.uk Please keep replies on the list so that other people can benefit from the discussion

Re: ldap auth does not works after openldap upgrade

2011-02-15 Thread Andrew Findlay
On Tue, Feb 15, 2011 at 02:52:19PM -0200, Leonardo Carneiro wrote: ### # Specific Directives for database #1, of type bdb: # Database specific directives apply to this databasse until another # 'database' directive occurs

Re: ldap auth does not works after openldap upgrade

2011-02-15 Thread Leonardo Carneiro
On Tue, Feb 15, 2011 at 4:40 PM, Andrew Findlay andrew.find...@skills-1st.co.uk wrote: On Tue, Feb 15, 2011 at 04:04:57PM -0200, Leonardo Carneiro wrote: Hmm, still did not worked. If i do a ldapsearch specifying '-D cn=root,dc=dominio,dc=com,dc=br and the password, the search goes

Re: ldap auth does not works after openldap upgrade

2011-02-15 Thread Leonardo Carneiro
On Tue, Feb 15, 2011 at 5:08 PM, Leonardo Carneiro chesterma...@gmail.comwrote: On Tue, Feb 15, 2011 at 4:40 PM, Andrew Findlay andrew.find...@skills-1st.co.uk wrote: On Tue, Feb 15, 2011 at 04:04:57PM -0200, Leonardo Carneiro wrote: Hmm, still did not worked. If i do a ldapsearch

ldap auth does not works after openldap upgrade

2011-02-14 Thread Leonardo Carneiro
Hello everyone, I upgraded my debian machine from lenny to squeeze (the new stable) that comes with samba 3.5.6 and openldap 2.4.23. this machines works primarily as a PDC. i have 3 services authenticating on ldap: samba, apache and redmine. samba is acting very weird, but it's kinda working,

Re: ldap auth does not works after openldap upgrade

2011-02-14 Thread Leonardo Carneiro
On Mon, Feb 14, 2011 at 12:37 PM, Leonardo Carneiro chesterma...@gmail.com wrote: Hello everyone, I upgraded my debian machine from lenny to squeeze (the new stable) that comes with samba 3.5.6 and openldap 2.4.23. this machines works primarily as a PDC. i have 3 services authenticating on

Re: ldap auth does not works after openldap upgrade

2011-02-14 Thread Dan White
On 14/02/11 12:37 -0200, Leonardo Carneiro wrote: Hello everyone, I upgraded my debian machine from lenny to squeeze (the new stable) that comes with samba 3.5.6 and openldap 2.4.23. this machines works primarily as a PDC. i have 3 services authenticating on ldap: samba, apache and redmine.