[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: kadmin: kadm5_create_principa: ldap_add_s: Can't contact LDAPserver
Lara Adianto írta:
>I followed your documentation, to start slapd as
>follows:
>shell% slapd -h "ldapi:/// ldap:///" -d -1
>-- snap --
>slapd startup: initiated.
>bdb_db_open: ou=KPrincipals,dc=laras,dc=com
>bdb_db_open: dbenv_open(/var/lib/ldap)
>slapd starting
>daemon: added 6r
>daemon: added 7r
>daemon: select: listen=6 active_threads=0 tvp=NULL
>daemon: select: listen=7 active_threads=0 tvp=NULL
>
>It looks like it's running but when I tried to init
>the REALM, it says can't contact ldap server.
>
>ps aux | grep slapd shows that slapd -h "ldapi:///
>ldap:///" -d -1 is running.
>
>-lara-
>
>Belos is my krb5.conf and slapd.conf:
>/etc/openldap/slapd.conf:
>-------------------------
>[logging]
> default = FILE:/var/log/hldap_krb5lib.log
> kdc = FILE:/var/log/hldap_krb5kdc.log
> admin_server = FILE:/var/log/hldap_kadmind.log
>
>[libdefaults]
> default_realm = LARAS.COM
>
>[realms]
> ADIANTO.COM = {
> kdc = kerberos.laras.com
> admin_server = kerberos.laras.com
> }
>
>[domain_realm]
> .laras.com = LARAS.COM
> laras.com = LARAS.COM
>
>[kdc]
> database = {
> dbname = ldap:ou=KPrincipals,dc=laras,dc=com
> mkey_file = /var/heimdal/m-key
>}
>
>/etc/krb5.conf:
>---------------
>include /usr/local/etc/openldap/schema/core.schema
>include /usr/local/etc/openldap/schema/cosine.schema
>include
>/usr/local/etc/openldap/schema/inetorgperson.schema
>include /usr/local/etc/openldap/schema/nis.schema
>include
>/usr/local/etc/openldap/schema/krb5-kdc.schema
>
>loglevel 256
>pidfile /usr/local/var/slapd.pid
>argsfile /usr/local/var/slapd.args
>
>#######################################################################
># ldbm database definitions
>#######################################################################
>
>database bdb
>password-hash {CLEARTEXT}
>suffix "ou=KPrincipals,dc=laras,dc=com"
>rootdn "cn=Manager,ou=KPrincipals,dc=laras,dc=com"
>directory "/var/lib/ldap"
>
>index objectClass eq
>index cn pres,eq
>index uid pres,eq
>
>access to *
> by sockurl="^ldapi:///$" write
> by * write
> by * auth
> by * read
>
>--- Luke Howard <lukeh@PADL.COM> wrote:
>
>
>>Did you start slapd with -h ldapi://
>>
>>-- Luke
>>
>>
>>
>
>
>=====
>------------------------------------------------------------------------------------
>La vie, voyez-vous, ca n'est jamais si bon ni si mauvais qu'on croit
> - Guy de Maupassant -
>------------------------------------------------------------------------------------
>
>__________________________________
>Do you Yahoo!?
>Yahoo! Small Business $15K Web Design Giveaway
>http://promotions.yahoo.com/design_giveaway/
>
>
Recent openldap client software wants to auth by sasl by default. Please
disble it specifying the -x flag.
ldapsearch -H 'ldapi:///' -x
Cheers
Geza