Re: idassert-bind seems to ignore binddn

In addition to ancient version, and according to reported configuration you are missed idassert-authzFrom setting. more details in slapd.conf(5).
Without this parameter you may have this issue.


I've setup a simple proxy so that local LDAP clients can get access to
protected attributes on a remote server. My proxy is slapd 2.4.31 with

What am I doing wrong? Any advice is greatly appreciated!

The first thing you're doing wrong is running a version of OpenLDAP that
is so ancient.

OpenLDAP 2.4.31 Release (2012/04/21)

I.e., it's over 3 years old.

There have been multiple fixes to slapd-ldap since that release.  This
one in particular may be related:

OpenLDAP 2.4.33 Release (2012/10/10)
        Fixed slapd-ldap idassert bind handling (ITS#7403)



