AW: problem with olcAccess - can not change own userPassword field

2015-06-18 Thread Stefan Bauer
Hi Ryan, thank you. Stefan -Ursprüngliche Nachricht- Von: Ryan Tandy  Gesendet: Son 14 Juni 2015 00:59 An: Stefan Bauer CC: openldap-technical@openldap.org Betreff: Re: problem with olcAccess - can not change own userPassword field On Thu, Jun 11, 2015 at 02:12:19PM +0200, Stefa

open ldap meta backend empty search

2015-06-18 Thread Pierluca Marino
Hi, I have a problem with meta backend feature. I need to get data from two different LDAP under a unique dn. The two ldap are an active directory and another ldap that should be on the same Open LDAP instance of the meta backend. Actually to test the solution I'm usind Open LDAP Windows version

RE: proxy to AD does not work during login client machine

2015-06-18 Thread Leo Xiao
Hi Dan, Appreciate it very much for your help! I'm using rhel6.6 (both ldap server and client machine), and what I want to archive is login rhel with AD users (on rhel login UI). Is it mean that my ldap proxy configuration works well? Because I can run command: >>$ldapsearch -x -h localhost -LL

authentication with SSL

2015-06-18 Thread Bharath K
i am trying to accesses on specific web pages and use LDAP users for authentication with SSL connection.but i am getting error like my username which is stored in ldap database user name:cdac password:cdac123 but when i authenticate i am getting below error user cdac: authentication failure for "

RE: proxy to AD does not work during login client machine

2015-06-18 Thread Leo Xiao
Hi Dan, Thanks a lot for the comments. I want to authenticate anonymously, Not with SASL. Is there any pam configuration needed for this scenario? Could you share some link/doc to me? Thanks so much. When I use openldap user login, just run authconfig-gtk(modified the /etc/openldap/ldap.conf)

best attr for multiple fields in one TAB-separated field ..

2015-06-18 Thread lejeczek
.. which would be mail related, can somebody recommend? many thanks. P.

Re: does slapd store/cache TLS certs

2015-06-18 Thread lejeczek
On 17/06/15 16:32, Quanah Gibson-Mount wrote: --On Wednesday, June 17, 2015 4:05 PM +0100 lejeczek wrote: hi everybody, I could not connect to slapd, command would fail with infamous: TLS: error: connect - force handshake failure: errno 0 - moznss error The moznnss code was written and

Re: group email addresses

2015-06-18 Thread brendan kearney
I am using postfix. is there a benefit to the group based expansion piece you speak of? Postfix is already tied to my ldap instances for user aliases, etc. Andrew Findlay wrote: > Adding the mail attribute is quite simple: define an AUXILIARY object > class that permits the attribute, add that to

Re: group email addresses

2015-06-18 Thread Michael Ströder
Andrew Findlay wrote: > Adding the mail attribute is quite simple: define an AUXILIARY object > class that permits the attribute, add that to the group entries, and > you can then add the mail attribute. That's what object class 'mailboxRelatedObject' [1] is for. [1] https://tools.ietf.org/html/d

Re: group email addresses

2015-06-18 Thread Andrew Findlay
On Wed, Jun 17, 2015 at 04:37:36PM -0400, Brendan Kearney wrote: > i have done some reading, and it seems that no official standard > exists for group email addresses. to that end, i am looking to > enlighten myself about what is done to provide mail addresses for > groupOfNames groups. Are you