[Samba] Re: Authenticateing DC's on an ldap backend... nobody knows how?

Jim C. jcllings at javahop.com
Thu Sep 30 06:07:24 GMT 2004


> access to dn.subtree="dc=j9starr,dc=net"
>     by group/posixGroup/memberUid="cn=Domain 
> Controllers,ou=Group,dc=j9starr,dc=net"
>     by * read

I pulled that info from faq-o-matic just a minute ago. No dice.  See below.

> access to dn.subtree="dc=j9starr,dc=net"
>     by group/posixGroup/memberUid="cn=Domain Controllers,ou=Group,dc=j9starr,dc=net"
>     by * read
> 
> # Do not enable referrals until AFTER you have a working directory
> # service AND an understanding of referrals.
> #referral       ldap://root.openldap.org
> 
> pidfile         /var/run/ldap/slapd.pid
> argsfile        /var/run/ldap/slapd.args
> 
> modulepath      /usr/lib/openldap
> "slapd.conf" 154L, 5397C written
> [root at enigma 0 openldap]$ slapd -t
> /etc/openldap/slapd.conf: line 47: group "cn=Domain Controllers,ou=Group,dc=j9starr,dc=net": inappropriate syntax: 1.3.6.1.4.1.1466.115.121.1.26

There has to be a way to do this.  I just can't imagine OpenLDAP being 
so lame that it can't.

Jim C.
-- 
-----------------------------------------------------------------
| I can be reached on the following Instant Messenger services: |
|---------------------------------------------------------------|
| MSN: j_c_llings at hotmail.com  AIM: WyteLi0n  ICQ: 123291844 	|
|---------------------------------------------------------------|
| Y!: j_c_llings               Jabber: jcllings at njs.netlab.cz	|
-----------------------------------------------------------------



More information about the samba mailing list