Re: OpenLdap from OpenCSW installation

2013-07-23 Thread Dieter Klünter
Am Mon, 22 Jul 2013 18:26:24 +0200 schrieb michał kępkowski michal.kepkow...@gmail.com: Hey, Has anyone of you install OpenLdap from OpenCSW repositories on Solaris? I've try to install using pkgutils: pkgutil -yi CSWopenldap than I read something more an add pkgutil -iy berkeleydb48

undocumented TLSProtocolMin

2013-07-23 Thread Manuel Gaupp
Hi, OpenLDAP seems to support an undocumented configuration parameter TLSProtocolMin when linked against OpenSSL. It allows to set the minimum SSL/TLS protocol version: * TLSProtocolMin 768 # (3 8) disables SSLv2 * TLSProtocolMin 769 # ((3 8)+1) disables SSLv2 and SSLv3 As there's no

Re: cn=config chaining or authzTo Strong(er) authentication required (8)

2013-07-23 Thread Manuel Gaupp
espe...@oreillyauto.com wrote: I am working on setting up a provider/consumer setup for openLDAP version 2.4.28. Everything seems to be working other than referrals. I can query the consumers, I can write directly to the provider. But I get the following when I try to sent a ldapmadify to

RE: need help interpreting Error: ldap_back_is_proxy_authz returned 0, misconfigured URI?

2013-07-23 Thread Steve Eckmann
Thanks, Liam. I will look more carefully at our schema and the search. I thought I had included definitions of all the AD attributes we use, but possibly not, and that would be an easy fix. Regards, Steve -Original Message- From: Liam Gretton [mailto:liam.gret...@leicester.ac.uk]

Re: undocumented TLSProtocolMin

2013-07-23 Thread Quanah Gibson-Mount
--On Tuesday, July 23, 2013 1:11 PM +0200 Manuel Gaupp mga...@googlemail.com wrote: Hi, OpenLDAP seems to support an undocumented configuration parameter TLSProtocolMin when linked against OpenSSL. It allows to set the minimum SSL/TLS protocol version: * TLSProtocolMin 768 # (3 8)

Re: undocumented TLSProtocolMin

2013-07-23 Thread Philip Guenther
On Tue, 23 Jul 2013, Quanah Gibson-Mount wrote: --On Tuesday, July 23, 2013 1:11 PM +0200 Manuel Gaupp mga...@googlemail.com wrote: OpenLDAP seems to support an undocumented configuration parameter TLSProtocolMin when linked against OpenSSL. It allows to set the minimum SSL/TLS protocol

Re: root cannot change user password with command passwd, sssd, pam, openldap

2013-07-23 Thread Augustin Wolf
Answer: you cannot change password using passwd, as sssd doesn't support such feature. There might be change to sss_ldap.so to prompt for ldap admin DN and password, but ldapasswd and kpasswd are considered sufficient tools. For more info see this thread: