[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: kadmin: kadm5_create_principa: ldap_add_s: Can't contact LDAPserver



Lara Adianto írta:

>I followed your documentation, to start slapd as
>follows:
>shell% slapd -h "ldapi:/// ldap:///" -d -1
>-- snap --
>slapd startup: initiated.
>bdb_db_open: ou=KPrincipals,dc=laras,dc=com
>bdb_db_open: dbenv_open(/var/lib/ldap)
>slapd starting
>daemon: added 6r
>daemon: added 7r
>daemon: select: listen=6 active_threads=0 tvp=NULL
>daemon: select: listen=7 active_threads=0 tvp=NULL
>
>It looks like it's running but when I tried to init
>the REALM, it says can't contact ldap server.
>
>ps aux | grep slapd shows that slapd -h "ldapi:///
>ldap:///" -d -1 is running.
>
>-lara-
>
>Belos is my krb5.conf and slapd.conf:
>/etc/openldap/slapd.conf:
>-------------------------
>[logging]
> default = FILE:/var/log/hldap_krb5lib.log
> kdc = FILE:/var/log/hldap_krb5kdc.log
> admin_server = FILE:/var/log/hldap_kadmind.log
>
>[libdefaults]
> default_realm = LARAS.COM
>
>[realms]
> ADIANTO.COM = {
>  kdc = kerberos.laras.com
>  admin_server = kerberos.laras.com
> }
>
>[domain_realm]
> .laras.com = LARAS.COM
> laras.com = LARAS.COM
>
>[kdc]
> database = {
>	dbname = ldap:ou=KPrincipals,dc=laras,dc=com
>	mkey_file = /var/heimdal/m-key
>}
>
>/etc/krb5.conf:
>---------------
>include		/usr/local/etc/openldap/schema/core.schema
>include		/usr/local/etc/openldap/schema/cosine.schema
>include	
>/usr/local/etc/openldap/schema/inetorgperson.schema
>include 	/usr/local/etc/openldap/schema/nis.schema
>include	
>/usr/local/etc/openldap/schema/krb5-kdc.schema
>
>loglevel	256
>pidfile		/usr/local/var/slapd.pid
>argsfile	/usr/local/var/slapd.args
>
>#######################################################################
># ldbm database definitions
>#######################################################################
>
>database        bdb
>password-hash	{CLEARTEXT}
>suffix		"ou=KPrincipals,dc=laras,dc=com"
>rootdn	"cn=Manager,ou=KPrincipals,dc=laras,dc=com"
>directory	"/var/lib/ldap"
>
>index	objectClass	eq
>index   cn		pres,eq
>index   uid		pres,eq
>
>access to *
>	by sockurl="^ldapi:///$" write
>	by * write
>	by * auth
>	by * read
>
>--- Luke Howard <lukeh@PADL.COM> wrote:
>  
>
>>Did you start slapd with -h ldapi://
>>
>>-- Luke
>>
>>    
>>
>
>
>=====
>------------------------------------------------------------------------------------ 
>La vie, voyez-vous, ca n'est jamais si bon ni si mauvais qu'on croit
>                                                                        - Guy de Maupassant -
>------------------------------------------------------------------------------------
>
>__________________________________
>Do you Yahoo!?
>Yahoo! Small Business $15K Web Design Giveaway 
>http://promotions.yahoo.com/design_giveaway/
>  
>
Recent openldap client software wants to auth by sasl by default. Please 
disble it specifying the -x flag.

ldapsearch -H 'ldapi:///' -x

Cheers

Geza