Re: TLS fails

2010-09-01 Thread Frederik Bosch
Compiling 2.4.17 with OpenSSL was more succesful than on 2.4.11. I think that's a Debian issue. Anyway, I have my server up and running! Thanks a lot Dieter for answering all my questions. But I have a minor question left. Each time I restart slapd I have to enter the PEM pass phrase. Is

RE: Getting Solaris to use Openldap

2010-09-01 Thread Stuart Cherrington
Just -h 10.2.250.15 -x -b 'dc=ldn,dc=sw,dc=com' ((objectClass=nisDomainObject)(nisDomain=ldn.sw.com)) should match the scripted search. OK - I ran ldapsearch2.4 -h 10.2.250.15 -D cn=proxyagent,ou=profile,dc=ldn,dc=sw,dc=com -w x -x -b 'dc=ldn,dc=sw,dc=com'

Re: TLS fails

2010-09-01 Thread Marc Patermann
Frederik, no TOFU, please. :) Frederik Bosch schrieb am 01.09.2010 10:23 Uhr: Compiling 2.4.17 with OpenSSL was more succesful than on 2.4.11. I think that's a Debian issue. Anyway, I have my server up and running! Thanks a lot Dieter for answering all my questions. But I have a minor

Re: Getting Solaris to use Openldap

2010-09-01 Thread Mark Cave-Ayland
Stuart Cherrington wrote: OK - so I tried ldapsearch2.4 -h 10.2.250.15 -x -b 'dc=ldn,dc=sw,dc=com' # extended LDIF # # LDAPv3 # base dc=ldn,dc=sw,dc=com with scope subtree # filter: (objectclass=*) # requesting: ALL # # search result search: 2 result: 32 No such object # numResponses: 1

Re: Back-ldap configuration and id-assertion.

2010-09-01 Thread Mustafa A. Hashmi
On Wed, Sep 1, 2010 at 11:14 AM, Mustafa A. Hashmi mahas...@gmail.com wrote: On Wed, Sep 1, 2010 at 12:11 AM, Mustafa A. Hashmi mahas...@gmail.com wrote: On Tue, Aug 31, 2010 at 9:31 PM,  masar...@aero.polimi.it wrote: I've uploaded the log file named:

Including schema in directory based config?

2010-09-01 Thread Will Dowling
Hi Guys, Hope this is the right list for this, haven't been lurking here previously so I don't have a feel for things yet. I'm upgrading our OpenLDAP servers to use directory based configuration under Ubuntu/Lucid and am having some problems including the provided Cosine and iNetOrgPerson

Password history configuration for ldap users.

2010-09-01 Thread Meghanand Acharekar
Hello, I have configured openldap server on RHEL 5.4 I also want to enforce strong password policies for my ldap users. for which i configured pam module on each ldap client in following way. (/etc/pam.d/system-auth) #%PAM-1.0 # This file is auto-generated. # User changes will be destroyed the

Re: cn=config and ACL formatting

2010-09-01 Thread Marc Patermann
-b, b...@bitrate.net schrieb am 31.08.2010 16:47 Uhr: some ldap clients/browsers support different editors for different types of data. for example, in my case, i use apache directory studio quite a bit, and was able to configure it so that when editing olcaccess attributes, it uses it's

Re: OID f�r caseExactIA5SubstringsMatch?

2010-09-01 Thread Hallvard B Furuseth
Keutel, Jochen writes: there are 6 matching rules for IA5 strings: - caseExactIA5Match - caseIgnoreIA5Match - caseExactIA5SubstringsMatch - caseIgnoreIA5SubstringsMatch - caseExactIA5OrderingMatch - caseIgnoreIA5OrderingMatch Only three of them are defined in RFC4517: -

Re: Back-ldap configuration and id-assertion.

2010-09-01 Thread masarati
On Wed, Sep 1, 2010 at 11:14 AM, Mustafa A. Hashmi mahas...@gmail.com wrote: On Wed, Sep 1, 2010 at 12:11 AM, Mustafa A. Hashmi mahas...@gmail.com wrote: On Tue, Aug 31, 2010 at 9:31 PM,  masar...@aero.polimi.it wrote: I've uploaded the log file named:

Re: Including schema in directory based config?

2010-09-01 Thread Quanah Gibson-Mount
--On Wednesday, September 01, 2010 1:46 PM +0800 Will Dowling will+lists_openl...@autodeist.com wrote: I hope this makes sense and that someone is able to help me understand directory based configuration a little better. You can't just symlink them. You have to copy them over, and then

Unix authentication in corporate AD

2010-09-01 Thread Edsall, William (WJ)
Hello, Just a few questions regarding authenticating OpenLDAP (centos 5.4) to windows active directory. I'm able to bind, I've confirmed this by changing the bind password, and then the bind attempt fails. However I'm unable to authenticate. My attempt is always as follows: su: user blabla does

Re: Including schema in directory based config?

2010-09-01 Thread Howard Chu
Quanah Gibson-Mount wrote: --On Wednesday, September 01, 2010 1:46 PM +0800 Will Dowling will+lists_openl...@autodeist.com wrote: I hope this makes sense and that someone is able to help me understand directory based configuration a little better. You can't just symlink them. You have to

Re: Unix authentication in corporate AD

2010-09-01 Thread Dan White
On 01/09/10 12:05 -0400, Edsall, William (WJ) wrote: Hello, Just a few questions regarding authenticating OpenLDAP (centos 5.4) to windows active directory. I'm able to bind, I've confirmed this by changing the bind password, and then the bind attempt fails. However I'm unable to authenticate.

custom hostname for openldap/sasl is not working

2010-09-01 Thread Zaar Hai
Good day, dear list! I'm trying to setup SASL GSSAPI authentication for openldap that listens on hostname different from the machine hostname it runs on. openldap runs on server inka.example.com. ldap/inka/example.com principal is added to ldap's keytab file. This command works just fine:  

Re: custom hostname for openldap/sasl is not working

2010-09-01 Thread Bill MacAllister
--On Wednesday, September 01, 2010 11:38:55 PM +0300 Zaar Hai haiz...@haizaar.com wrote: Good day, dear list! I'm trying to setup SASL GSSAPI authentication for openldap that listens on hostname different from the machine hostname it runs on. openldap runs on server inka.example.com.