[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: Error 80 with ldapmodify



Christian Schmidt wrote:
Hi all,

we're running Debian Jessie with slapd-2.4.40+dfsg-1+deb8u2
and ldap-utils-2.4.40+dfsg-1+deb8u2. No special modifications have been
taken to slapd's configuration and/or the directory itself , and trying
to add the following ldif file...

This error isn't tripping anything familiar for me. Try again with debug -1; if that doesn't show more info then we would need to use gdb to see what actually failed.

dn: cn=config
changetype: modify
add: olcTLSCertificateKeyFile
olcTLSCertificateKeyFile: /etc/ldap/ssl/ldap.gnutls.key
-
add: olcTLSCertificateFile
olcTLSCertificateFile: /etc/ldap/ssl/ldap.gnutls.crt
-
add: olcTLSCACertificateFile
olcTLSCACertificateFile: /etc/ldap/ssl/intermediate.pem

...results in error 80:

# ldapmodify -Y EXTERNAL -H ldapi:/// -f ./ssl.ldif
SASL/EXTERNAL authentication started
SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth
SASL SSF: 0
modifying entry "cn=config"
ldap_modify: Other (e.g., implementation specific) error (80)

All the files are readable for the user slapd is running as. Invoking
slapd with debug level 255 shows:

[..]
56e2e677 => slap_access_allowed: add access granted by manage(=mwrscxd)
56e2e677 => access_allowed: add access granted by manage(=mwrscxd)
56e2e677 oc_check_required entry (cn=config), objectClass "olcGlobal"
56e2e677 oc_check_allowed type "objectClass"
56e2e677 oc_check_allowed type "cn"
56e2e677 oc_check_allowed type "olcArgsFile"
56e2e677 oc_check_allowed type "olcLogLevel"
56e2e677 oc_check_allowed type "olcPidFile"
56e2e677 oc_check_allowed type "olcToolThreads"
56e2e677 oc_check_allowed type "structuralObjectClass"
56e2e677 oc_check_allowed type "entryUUID"
56e2e677 oc_check_allowed type "creatorsName"
56e2e677 oc_check_allowed type "createTimestamp"
56e2e677 oc_check_allowed type "olcTLSCertificateKeyFile"
56e2e677 oc_check_allowed type "olcTLSCertificateFile"
56e2e677 oc_check_allowed type "olcTLSCACertificateFile"
56e2e677 oc_check_allowed type "entryCSN"
56e2e677 oc_check_allowed type "modifiersName"
56e2e677 oc_check_allowed type "modifyTimestamp"
56e2e677 send_ldap_result: conn=1002 op=1 p=3
56e2e677 send_ldap_result: err=80 matched="" text=""
56e2e677 send_ldap_response: msgid=2 tag=103 err=80   <---- Error 80
ber_flush2: 14 bytes to sd 12
   0000:  30 0c 02 01 02 67 07 0a  01 50 04 00 04 00
0....g...P....
ldap_write: want=14, written=14
   0000:  30 0c 02 01 02 67 07 0a  01 50 04 00 04 00
0....g...P....
56e2e677 conn=1002 op=1 RESULT tag=103 err=80 text=
[..]

What's wrong there? I couldn't find anything useful to feed
$SEARCHENGINE with.

Thanks & Regards,
Christian



--
  -- Howard Chu
  CTO, Symas Corp.           http://www.symas.com
  Director, Highland Sun     http://highlandsun.com/hyc/
  Chief Architect, OpenLDAP  http://www.openldap.org/project/