[prev in list] [next in list] [prev in thread] [next in thread] 

List:       pamldap
Subject:    [pamldap] Re: Why "ldap_sasl_interactive_bind_s: No such attribute"?
From:       bj () zuto ! de (Rainer Clasen)
Date:       2002-11-12 9:22:37
[Download RAW message or body]

hbgui wrote:
> I use ldapmodify cann't bind to ldap server.
> messsage is:
> cvs:~# ldapmodify -h 127.0.0.1 -D cn=laomao,dc=net,dc=dlut,dc=edu,dc=cn -w test123 -v   
> ldap_init( 127.0.0.1, 0 )
> ldap_sasl_interactive_bind_s: No such attribute
> 
> But I can success change it by use -x option.what's wrong with it?
> I use pam_ldap cann't change password too.

on a sasl bind clients first try to retrieve a list of allowed mechs.
Your ACLs seem to be too restrictive.

Put something like this in your slapd config:
# allow ldapsearch -x -s base -b "" supportedSASLMechanisms
access to dn.base="" supportedSASLMechanisms
        by * +rscx stop


Rainer

-- 
KeyID=759975BD fingerprint=887A 4BE3 6AB7 EE3C 4AE0  B0E1 0556 E25A 7599 75BD
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic