Re: best way to debug slapd

Christine Place-Sweet (cplace@tigger.cc.binghamton.edu)
Thu, 8 Aug 1996 09:05:20 -0400 (EDT)

I am having problems also. I have installed slapd, (ldap-3.3) on a
SPARC4 running solaris2.5 with gdbm 1.7.3 as a backend database. I have
problems authenticating using kerberos. I also have web500gw-2.0b
installed and can't authenticate from there either. I have verified my
contents of srvtab file, and all corresponding files. I had talked with
Gordon Good he said to verify you have a correct krbName attribute in your
entry. I had correct entries however I still get the message "krb_mk_req
failed (Can't send request (send_to_kdc)) Ldap_bind: Invalid credentials.

The other possible problem Gordon thought of was that maybe our kerberos
severs didn't know about these two principals. Doing a klist after doing
a ldapsearch or ldapmodify did not show me the necessary tickets; for
ldapserver and x500dsa. I was told by the people maintaining our kerberos
servers that it does recognize the principals by using
/usr/bin/ksrvtgt/name instance [ [realm] srvtab]
However if I do this I only get one
ticket at a time, i.e. if I ask for ldapserver I will get it, but when I
ask for x500dsa I will get x500dsa and lose ldapserver. Even when I have
a ldapserver ticket I can not authenticate to do any modifications or
searches binded. The only way I can modify is by binding as rootdn
also. Does anyone have any input? I really need the ability to
authenticate. Any help would be greatly appreciated. Thanks!

Chris

On Wed, 7 Aug 1996, Chris Irwin wrote:

> I am having all kinds of trouble with user authentication ( I keep
> getting "ldap_modify: Insufficient access" when trying to modify
> entries using ldapmodify. What is the best way to find out why this
> message is being sent back when I know that I am sending in the correct
> userPassword for the binding DN. The only way that I can modify is by
> binding as the rootdn.
>
> Any help is greatly appreciateed.
>
> Chris
> --
> Christopher S. Irwin
> Concept Five Technologies, Inc. Phone: 703-610-1920
> 7525 Colshire Drive Fax: 703-610-1853
> McLean Virginia 22102-7400 Email: cirwin@concept5.com
>