[ldapvi] ldapvi - How to edit acl-entries within the cn=config backend

Axel Birndt towerlexa at gmx.de
Thu May 20 20:54:12 CEST 2010


Hi Ulrich,

Ulrich Spörlein schrieb:
> On Thu, 20.05.2010 at 19:05:19 +0200, Axel Birndt wrote:

> This looks like a permission denied problem. NB the admin account for
> dc=2axels-company,dc=de does not necessarly have read/write access for
> the cn=config tree. This must usually be done by cn=admin,cn=config
> 
> This is how I do it:
> ldapvi -D cn=admin,cn=config -b cn=config

Yes, i think you are right. Thank you very much for your help.

Now it is working!

Maybe you could do a little explaining, why it is working now?

What is the difference between "cn=admin,cn=config" and 
"cn=admin,dc=2axels-company,dc=de"?

Why does the user "cn=admin,dc=2axels-company,dc=de" have not sufficient 
rights to access the ACL's ?

Is this a expected behavior?

Thanks and sorry for my question, but it's really difficult for me to 
understand all this, and for the newly released cn=config Backend. My 
problem is, that i don't use the slapd.conf file, because this is not 
activated in Ubuntu 9.10.

I think, it is better to use the cn=config Backend as it is. I wouldn't 
use the slapd.conf and the cn=config together.

So for this this in my personal thinking, and my own problems ;-)

But i'am happy that i resolv my issues step by step, anyhow this is the 
difficultest way to do all this. So i hope i'am able to setup a clean 
running produktiv system later.

-- 


Gruß Axel

------------------------------

=> einen Server härten? google mal nach Stahl härten oder was meinst Du 
mit härten?

Aus:
http://www.administrator.de/index.php?content=69906

------------------------------

http://www.tty1.net/smart-questions_de.html



More information about the ldapvi mailing list