[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: updatedn from another suffix : is it possible ?



On Friday 28 July 2006 17:04, Marc Chantreux wrote:
> Hi all,
>
> I've too backends with 2 prefixes.  say
> - o=local and
> - o=example
>
> I've one admin per backend. say
> - cn=admin,o=local and
> - cn=admin,o=example
>
> is it possible that my cn=admin,o=local to write in o=example ?

Yes.

>
> i wrote those ACL for the o=example backend :
>
> access to attrs=userPassword
>         by dn="cn=admin,o=local" write
>         by anonymous auth
>         by self write
>         by * none
>
> access to dn.base="" by * read
>
> access to *
>         by dn="cn=admin,o=local" write
>         by * read
>
> and slapd restarted normaly but when i try to modify an o=example entry
> with cn=admin,o=local, this message appears :
>
> ldap_modify: Server is unwilling to perform (53)
>         additional info: shadow context; no update referral
>
> same message in the slapd logfile. So i wonder if i can solve my problem.

I suspect this has nothing to do with your ACLs, but with your replication 
configuration, which I can't comment on as you haven't provided enough 
configuration information.

Regards,
Buchan

-- 
Buchan Milne
ISP Systems Specialist
B.Eng,RHCE(803004789010797),LPIC-2(LPI000074592)

Attachment: pgpNm7mNELWhq.pgp
Description: PGP signature