Re: Patching openldap?

On Sat, Oct 8, 2011 at 4:54 AM, Christian Manal
<moenoel@informatik.uni-bremen.de> wrote:
> Here's an example of an ldapclient invocation that works for me:
> ldapclient manual \
> Â-a authenticationMethod="tls:simple" \
> Â-a credentialLevel="proxy" \
> Â-a defaultSearchBase="dc=example,dc=org" \
> Â-a defaultSearchScope="sub" \
> Â-a defaultServerList="ldap1.example.org,ldap2.example.org" \
> Â-a domainName="example.org" \
> Â-a preferredServerList="ldap1.example.org,ldap2.example.org" \
> Â-a serviceSearchDescriptor="passwd:ou=People,dc=example,dc=org" \
> Â-a serviceSearchDescriptor="group:ou=Group,dc=example,dc=org" \
> Â-a serviceSearchDescriptor="netgroup:ou=Netgroup,dc=example,dc=org" \
> Â-a
> serviceSearchDescriptor="auto_home:ou=auto_home,ou=Mounts,dc=example,dc=org"
> \
> Â-a attributeMap="auto_home:automountMapName=ou" \
> Â-a attributeMap="auto_home:automountKey=cn" \
> Â-a proxyDN="uid=proxyauth,ou=people,dc=example,dc=org" \
> Â-a proxyPassword="foobar"
> Before you invoke that, you need to modify /etc/nsswitch.ldap to your
> needs (ldapclient will copy that to /etc/nsswitch.conf). You also need
> to put your TLS certs into /var/ldap in NSS format (you can
> generate/convert them with certutil[1]) and edit /etc/pam.conf for LDAP
> authentication.
> Regards,
> Christian Manal
> [1] http://www.mozilla.org/projects/security/pki/nss/tools/certutil.html


I will try your command. Since you used ldapclient manual and not
ldapclient init I don't need to add a profile of proxy ldif file to
the ldap server, right? I have been using examples like the one you
just gave me and I can only get the info from the server. The password
seems to not work. I get the same erros on the prompt that I would get
if the password or username where wrong. Though I have not tried the
command with the serviceSearchDescriptor before maybe this is what I'm

 I'm also not using TLS or automount can I leave these out, for now?
Sotls:simple would be simple, right. Also could Solaris 10 not want to
work because I'm not using TLS?

Anyway thanks for your time. I will let you know if it works.