could not config n-way multi-master because insufficient access

2010-06-07 Thread owen nirvana
my env is Debian squeeze, OpenLDAP 2.4.17( from packages.debian.org) I create an OpenLDAP Server, and try to config N-Wat multi-master, according to OpenLDAP Admin Guide. i adding init.ldif file on the server , the following is the content *dn: cn=config objectClass: olcGlobal cn: config

Re: Bidirectional sync using openldap and active directory

2010-06-07 Thread Benjamin MONTHOUEL
Thanks for response. I've already found LSC project, but I wasn't sure that LSC is compatible with Kerberos tokens and users' process of changing his own password. Benjamin MONTHOUËL Systems Administrator Assistant NETASQ France - We Secure IT Villeneuve d'Ascq Le 04/06/2010 13:17, Jonathan

Re: how to get DIT structure info

2010-06-07 Thread Покотиленко Костик
В Птн, 04/06/2010 в 21:09 +0800, owen nirvana пишет: hi, I have a question. I want to manage some data by OpenLDAP, and I hope show them by tree structure when I list. So I want to get the DIT structure info and create the corresponding nodes in my treeview. so , how to do? What API are you

Re: LDAP C API

2010-06-07 Thread Покотиленко Костик
В Чтв, 03/06/2010 в 18:10 -0700, Quanah Gibson-Mount пишет: --On Thursday, June 03, 2010 6:56 PM +0300 Покотиленко Костик cas...@meteor.dp.ua wrote: Did this message hit the list? Hi there, I'm writing GTK application for managing LDAP directory, a kind of GTK variant of

RE: User restriction

2010-06-07 Thread Stuart Cherrington
Date: Sat, 5 Jun 2010 11:39:22 -0700 From: h...@symas.com To: bgmi...@staff.telkomsa.net CC: openldap-technical@openldap.org; jonat...@phillipoux.net; stuart_cherring...@hotmail.co.uk Subject: Re: User restriction Buchan Milne wrote: On Friday, 4 June 2010 13:47:42 Jonathan Clarke

Re: Pam password authentication

2010-06-07 Thread Buchan Milne
On Saturday, 5 June 2010 22:52:10 Siddhartha Jain wrote: I came across a similar bug where enabling chaining between a master and slave allows invalid passwords to be accepted by pam_ldap. Unfortunately, no word from OpenLDAP or pam_ldap maintainers on the issue. Did you file an ITS? I

Re: pam_ldap doesn't bind SIMPLE for anonymous auth?

2010-06-07 Thread Buchan Milne
On Friday, 4 June 2010 23:50:26 Jo Rhett wrote: I'm seeing a problem where I can authenticate as a user using the ldap tools (ie ldapsearch) but I am unable to login using PAM. Comparing debug on the server shows that ldapsearch is doing a new BIND, where's PAM is not: Jun 4 14:58:52

Re: [SOLVED] Pam password authentication

2010-06-07 Thread Indexer
I have solved this issue, unfortunately i don't think i sent it back to the mailing list. It was to do with my combination of required and sufficient, and i lacked pam_deny.so I replaced it with authsufficient pam_opie.so no_warn no_fake_prompts auth

Re: ldap with squid auth helper

2010-06-07 Thread Buchan Milne
On Friday, 4 June 2010 21:05:26 Gerardo Herzig wrote: Hi all. Im triyng to use squid with the squid_ldap_group auth helper. The schema looks like o=Company -Groups |-ProxyUsers | |-Managers |-Sales Managers and Sales are OrganizationalUnit, ProxyUsers is

Re: LDAP C API

2010-06-07 Thread Quanah Gibson-Mount
--On Monday, June 07, 2010 11:17 AM +0300 Покотиленко Костик cas...@meteor.dp.ua wrote: So, I need to have a way to know whether each attibute is RDN or Required or Structural, etc Then you need to parse the schema. --Quanah -- Quanah Gibson-Mount Principal Software Engineer Zimbra, Inc

Re: smbk5pwd: ldappassword hangs

2010-06-07 Thread Quanah Gibson-Mount
--On Monday, June 07, 2010 11:56 AM +0200 Frank Van Damme frank.vanda...@gmail.com wrote: 2010/5/31 Frank Van Damme frank.vanda...@gmail.com: Hi list, I installed and configured the smbk5pwd overlay as described on http://student.physik.uni-mainz.de/~reiffert/smbk5pwd.html#smbk5pwd. This

Re: Pam password authentication

2010-06-07 Thread Indexer
This is more of a pam config problem than openldap related... but your account section probably needs either ldap or unix to be required/sufficient rather than optional. As it is now it will check that there is no nologin file, and then check through your pam login.access file, it will

Re: LDAP C API

2010-06-07 Thread Покотиленко Костик
В Пнд, 07/06/2010 в 08:47 -0700, Quanah Gibson-Mount пишет: --On Monday, June 07, 2010 11:17 AM +0300 Покотиленко Костик cas...@meteor.dp.ua wrote: So, I need to have a way to know whether each attibute is RDN or Required or Structural, etc Then you need to parse the schema. Thanks.

Re: smbk5pwd: ldappassword hangs

2010-06-07 Thread Marco Göbel
Hi - On Mon, 7 Jun 2010 11:56:48 +0200, Frank Van Damme frank.vanda...@gmail.com wrote: 2010/5/31 Frank Van Damme frank.vanda...@gmail.com: Hi list, I installed and configured the smbk5pwd overlay as described on http://student.physik.uni-mainz.de/~reiffert/smbk5pwd.html#smbk5pwd. This