[LDAP-interop] Bad DN starting slapd

Todd Lyons tlyons at ivenue.com
Mon Nov 14 12:30:02 EST 2005


Max Alberto León wanted us to know:

>But the line where I grant access for the dn root to specific attrs 
>keeps giving me this error:

This is from 'man slapd.access':

  It is  perfectly useless to  give any access privileges to a DN that
  exactly matches the rootdn of the database the ACLs apply to, because
  it implicitly possesses write privileges for the entire tree of that
  database.

That is from an OpenLDAP 2.2.x install.  It doesn't have that same
verbage in a 2.1.x install, but I am pretty sure it also applies there.

In other words, your root dn already has write access to that directory
tree, so no need to explicitly assign it in your access rules.
-- 
Regards...		Todd
we're off on the usual strange tangents.  next will be whether
it is ethical to walk in your neighbor's open house if they're
running ipv6:-).                                  --Randy Bush
Linux kernel 2.6.12-12mdksmp   2 users,  load average: 1.32, 1.40, 1.75
_______________________________________________
LDAP-interop mailing list
LDAP-interop at fini.net
http://lists.fini.net/mailman/listinfo/ldap-interop



More information about the LDAP-interop mailing list