Dear Peter
Thanks for your updates. I am still unable to fix this issue.
When the acl setup is as follows:
root@geopc:/etc/ldap/slapd.d/cn=config# ldapsearch -Q -LLL -Y
EXTERNAL -H ldapi:/// -b cn=config '(olcDatabase={1}hdb)'
olcAccess
dn: olcDatabase={1}hdb,cn=config
olcAccess: {0}to attrs=userPassword,shadowLastChange by self
write by anonymous auth by dn="cn=admin,dc=ds,dc=geo,dc=com"
write by * none
olcAccess: {1}to dn.base="" by * read
olcAccess: {2}to dn.sub="ou=People,dc=prime,dc=ds,dc=geo,dc=com"
attrs=userPassword by self write by * auth
olcAccess: {3}to dn.sub="ou=People,dc=prime,dc=ds,dc=geo,dc=com"
filter="( allowedService=zabbix)" attrs=uid,objectClass by
dn.exact="cn=zabbix,
ou=Applications,ou=Groups,dc=prime,dc=ds,dc=geo,dc=com" read by
self read
dn: olcDatabase={2}hdb,cn=config
root@geopc:/etc/ldap/slapd.d/cn=config#
No user can able to login. We tried various option we
interchanged rules but still getting same result.
Please see the error log:
May 14 14:06:14 geopc slapd[4456]: conn=1002 fd=22 ACCEPT from
IP=
192.168.1.210:49776
(IP=
0.0.0.0:636)
May 14 14:06:14 geopc slapd[4456]: conn=1002 fd=22 TLS
established tls_ssf=256 ssf=256
May 14 14:06:14 geopc slapd[4456]: conn=1002 op=0 BIND
dn="cn=zabbix,ou=Applications,ou=Groups,dc=prime,dc=ds,dc=geo,dc=com"
method=128
May 14 14:06:14 geopc slapd[4456]: conn=1002 op=0 RESULT tag=97
err=49 text=
May 14 14:06:14 geopc slapd[4456]: conn=1002 op=1 SRCH base=""
scope=0 deref=0 filter="(objectClass=*)"
May 14 14:06:14 geopc slapd[4456]: conn=1002 op=1 SRCH
attr=namingContexts supportedLdapVersion altServer
supportedControl supportedExtension supportedFeatures
supportedSASLMechanisms
May 14 14:06:14 geopc slapd[4456]: conn=1002 op=1 ENTRY dn=""
May 14 14:06:14 geopc slapd[4456]: conn=1002 op=1 SEARCH RESULT
tag=101 err=0 nentries=1 text=
May 14 14:06:14 geopc slapd[4456]: conn=1002 op=2 SRCH
base="dc=prime,dc=ds,dc=geo,dc=com" scope=2 deref=0
filter="(uid=user1)"
May 14 14:06:14 geopc slapd[4456]: conn=1002 op=2 SEARCH RESULT
tag=101 err=32 nentries=0 text=
May 14 14:06:14 geopc slapd[4456]: conn=1002 fd=22 closed
(connection lost)
Can you please have a check. Fedup with this. can you please
help to configure it.
Thanks in advance.
Geo