Re: [389-users] Turn off anonymous bind

2011-11-10 Thread Rich Megginson
ailto:msau...@redhat.com] *Sent:* Thursday, November 10, 2011 2:01 PM *To:* General discussion list for the 389 Directory server project. *Cc:* David Hoskinson *Subject:* Re: [389-users] Turn off anonymous bind so we should have under cn=config nsslapd-allow-anonymous-access: off nss

Re: [389-users] Turn off anonymous bind

2011-11-10 Thread David Hoskinson
10, 2011 2:01 PM To: General discussion list for the 389 Directory server project. Cc: David Hoskinson Subject: Re: [389-users] Turn off anonymous bind so we should have under cn=config nsslapd-allow-anonymous-access: off nsslapd-allow-unauthenticated-binds: off ( see http://docs.redhat.com/

Re: [389-users] Turn off anonymous bind

2011-11-10 Thread Marc Sauton
so we should have under cn=config nsslapd-allow-anonymous-access: off nsslapd-allow-unauthenticated-binds: off ( see http://docs.redhat.com/docs/en-US/Red_Hat_Directory_Server/8.2/html/Administration_Guide/configuring-special-binds.html ) Review the ns-slapd error log, may be it is falling back to

[389-users] Turn off anonymous bind

2011-11-10 Thread David Hoskinson
We want to restrict all queries to authenticated queries. As our system sits now I can anonymously query and return ntlmpassword and see the hash as well as most other entries. We would like this to not be the case, and requires directory manager and pass or a similar approved user to do ldap