CentOS 7: ldap_add: Insufficient access (50)











up vote
0
down vote

favorite












Installed OpenLDAP with this command



# yum -y install openldap openldap-clients openldap-servers


Copied reference data structures:



# cp /usr/share/openldap-servers/DB_CONFIG.example /var/lib/ldap/DB_CONFIG


Generated a password hash for 'test' by:



# slappasswd


In file /etc/openldap/slapd.d/cn=config/olcDatabase={2}hdb.ldif added:



# olcRootPW: {SSHA}5lPFVw19zeh7LT53hQH69znzj8TuBrLv
# olcSuffix: dc=mydomain,dc=com
# olcRootDN: cn=admin,dc=mydomain,dc=com


In file /etc/openldap/slapd.d/cn=config/olcDatabase={1}monitor.ldif added:



# olcAccess: {0}to * by dn.base="gidNumber=0+uidNumber=0,cn=peercred,cn=external ,cn=auth" read by dn.base="cn=admin,dc=mydomain,dc=com" read by * none


In file /etc/openldap/slapd.d/cn=config/olcDatabase={0}config.ldif added:



# olcRootDN: cn=admin,dc=mydomain,dc=com


After all that steps I started service by sudo service slapd start command.



Now I want to add some basic schema:



# ldapadd -f /etc/openldap/schema/core.ldif  -D cn=admin,dc=mydomain,dc=com -w test


And at this step I get an error:



# adding new entry "cn=core,cn=schema,cn=config"
# ldap_add: Insufficient access (50)


Why I actually get this error if I use olcRootDN?










share|improve this question


























    up vote
    0
    down vote

    favorite












    Installed OpenLDAP with this command



    # yum -y install openldap openldap-clients openldap-servers


    Copied reference data structures:



    # cp /usr/share/openldap-servers/DB_CONFIG.example /var/lib/ldap/DB_CONFIG


    Generated a password hash for 'test' by:



    # slappasswd


    In file /etc/openldap/slapd.d/cn=config/olcDatabase={2}hdb.ldif added:



    # olcRootPW: {SSHA}5lPFVw19zeh7LT53hQH69znzj8TuBrLv
    # olcSuffix: dc=mydomain,dc=com
    # olcRootDN: cn=admin,dc=mydomain,dc=com


    In file /etc/openldap/slapd.d/cn=config/olcDatabase={1}monitor.ldif added:



    # olcAccess: {0}to * by dn.base="gidNumber=0+uidNumber=0,cn=peercred,cn=external ,cn=auth" read by dn.base="cn=admin,dc=mydomain,dc=com" read by * none


    In file /etc/openldap/slapd.d/cn=config/olcDatabase={0}config.ldif added:



    # olcRootDN: cn=admin,dc=mydomain,dc=com


    After all that steps I started service by sudo service slapd start command.



    Now I want to add some basic schema:



    # ldapadd -f /etc/openldap/schema/core.ldif  -D cn=admin,dc=mydomain,dc=com -w test


    And at this step I get an error:



    # adding new entry "cn=core,cn=schema,cn=config"
    # ldap_add: Insufficient access (50)


    Why I actually get this error if I use olcRootDN?










    share|improve this question
























      up vote
      0
      down vote

      favorite









      up vote
      0
      down vote

      favorite











      Installed OpenLDAP with this command



      # yum -y install openldap openldap-clients openldap-servers


      Copied reference data structures:



      # cp /usr/share/openldap-servers/DB_CONFIG.example /var/lib/ldap/DB_CONFIG


      Generated a password hash for 'test' by:



      # slappasswd


      In file /etc/openldap/slapd.d/cn=config/olcDatabase={2}hdb.ldif added:



      # olcRootPW: {SSHA}5lPFVw19zeh7LT53hQH69znzj8TuBrLv
      # olcSuffix: dc=mydomain,dc=com
      # olcRootDN: cn=admin,dc=mydomain,dc=com


      In file /etc/openldap/slapd.d/cn=config/olcDatabase={1}monitor.ldif added:



      # olcAccess: {0}to * by dn.base="gidNumber=0+uidNumber=0,cn=peercred,cn=external ,cn=auth" read by dn.base="cn=admin,dc=mydomain,dc=com" read by * none


      In file /etc/openldap/slapd.d/cn=config/olcDatabase={0}config.ldif added:



      # olcRootDN: cn=admin,dc=mydomain,dc=com


      After all that steps I started service by sudo service slapd start command.



      Now I want to add some basic schema:



      # ldapadd -f /etc/openldap/schema/core.ldif  -D cn=admin,dc=mydomain,dc=com -w test


      And at this step I get an error:



      # adding new entry "cn=core,cn=schema,cn=config"
      # ldap_add: Insufficient access (50)


      Why I actually get this error if I use olcRootDN?










      share|improve this question













      Installed OpenLDAP with this command



      # yum -y install openldap openldap-clients openldap-servers


      Copied reference data structures:



      # cp /usr/share/openldap-servers/DB_CONFIG.example /var/lib/ldap/DB_CONFIG


      Generated a password hash for 'test' by:



      # slappasswd


      In file /etc/openldap/slapd.d/cn=config/olcDatabase={2}hdb.ldif added:



      # olcRootPW: {SSHA}5lPFVw19zeh7LT53hQH69znzj8TuBrLv
      # olcSuffix: dc=mydomain,dc=com
      # olcRootDN: cn=admin,dc=mydomain,dc=com


      In file /etc/openldap/slapd.d/cn=config/olcDatabase={1}monitor.ldif added:



      # olcAccess: {0}to * by dn.base="gidNumber=0+uidNumber=0,cn=peercred,cn=external ,cn=auth" read by dn.base="cn=admin,dc=mydomain,dc=com" read by * none


      In file /etc/openldap/slapd.d/cn=config/olcDatabase={0}config.ldif added:



      # olcRootDN: cn=admin,dc=mydomain,dc=com


      After all that steps I started service by sudo service slapd start command.



      Now I want to add some basic schema:



      # ldapadd -f /etc/openldap/schema/core.ldif  -D cn=admin,dc=mydomain,dc=com -w test


      And at this step I get an error:



      # adding new entry "cn=core,cn=schema,cn=config"
      # ldap_add: Insufficient access (50)


      Why I actually get this error if I use olcRootDN?







      linux centos openldap






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Mar 23 '17 at 14:34









      Serbin

      1011




      1011






















          1 Answer
          1






          active

          oldest

          votes

















          up vote
          0
          down vote













          It is also required to change in /etc/openldap/slapd.d/cn=config/olcDatabase={0}config.ldif file next lines:



           # olcAccess: {0}to * by dn.base="gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth" manage by dn.base="cn=admin,dc=mydomain,dc=com" manage by * none


          There is also added manage by dn.base="cn=admin,dc=mydomain,dc=com".






          share|improve this answer





















            Your Answer








            StackExchange.ready(function() {
            var channelOptions = {
            tags: "".split(" "),
            id: "106"
            };
            initTagRenderer("".split(" "), "".split(" "), channelOptions);

            StackExchange.using("externalEditor", function() {
            // Have to fire editor after snippets, if snippets enabled
            if (StackExchange.settings.snippets.snippetsEnabled) {
            StackExchange.using("snippets", function() {
            createEditor();
            });
            }
            else {
            createEditor();
            }
            });

            function createEditor() {
            StackExchange.prepareEditor({
            heartbeatType: 'answer',
            convertImagesToLinks: false,
            noModals: true,
            showLowRepImageUploadWarning: true,
            reputationToPostImages: null,
            bindNavPrevention: true,
            postfix: "",
            imageUploader: {
            brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
            contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
            allowUrls: true
            },
            onDemand: true,
            discardSelector: ".discard-answer"
            ,immediatelyShowMarkdownHelp:true
            });


            }
            });














            draft saved

            draft discarded


















            StackExchange.ready(
            function () {
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f353350%2fcentos-7-ldap-add-insufficient-access-50%23new-answer', 'question_page');
            }
            );

            Post as a guest















            Required, but never shown

























            1 Answer
            1






            active

            oldest

            votes








            1 Answer
            1






            active

            oldest

            votes









            active

            oldest

            votes






            active

            oldest

            votes








            up vote
            0
            down vote













            It is also required to change in /etc/openldap/slapd.d/cn=config/olcDatabase={0}config.ldif file next lines:



             # olcAccess: {0}to * by dn.base="gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth" manage by dn.base="cn=admin,dc=mydomain,dc=com" manage by * none


            There is also added manage by dn.base="cn=admin,dc=mydomain,dc=com".






            share|improve this answer

























              up vote
              0
              down vote













              It is also required to change in /etc/openldap/slapd.d/cn=config/olcDatabase={0}config.ldif file next lines:



               # olcAccess: {0}to * by dn.base="gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth" manage by dn.base="cn=admin,dc=mydomain,dc=com" manage by * none


              There is also added manage by dn.base="cn=admin,dc=mydomain,dc=com".






              share|improve this answer























                up vote
                0
                down vote










                up vote
                0
                down vote









                It is also required to change in /etc/openldap/slapd.d/cn=config/olcDatabase={0}config.ldif file next lines:



                 # olcAccess: {0}to * by dn.base="gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth" manage by dn.base="cn=admin,dc=mydomain,dc=com" manage by * none


                There is also added manage by dn.base="cn=admin,dc=mydomain,dc=com".






                share|improve this answer












                It is also required to change in /etc/openldap/slapd.d/cn=config/olcDatabase={0}config.ldif file next lines:



                 # olcAccess: {0}to * by dn.base="gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth" manage by dn.base="cn=admin,dc=mydomain,dc=com" manage by * none


                There is also added manage by dn.base="cn=admin,dc=mydomain,dc=com".







                share|improve this answer












                share|improve this answer



                share|improve this answer










                answered Mar 24 '17 at 6:18









                Serbin

                1011




                1011






























                    draft saved

                    draft discarded




















































                    Thanks for contributing an answer to Unix & Linux Stack Exchange!


                    • Please be sure to answer the question. Provide details and share your research!

                    But avoid



                    • Asking for help, clarification, or responding to other answers.

                    • Making statements based on opinion; back them up with references or personal experience.


                    To learn more, see our tips on writing great answers.





                    Some of your past answers have not been well-received, and you're in danger of being blocked from answering.


                    Please pay close attention to the following guidance:


                    • Please be sure to answer the question. Provide details and share your research!

                    But avoid



                    • Asking for help, clarification, or responding to other answers.

                    • Making statements based on opinion; back them up with references or personal experience.


                    To learn more, see our tips on writing great answers.




                    draft saved


                    draft discarded














                    StackExchange.ready(
                    function () {
                    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f353350%2fcentos-7-ldap-add-insufficient-access-50%23new-answer', 'question_page');
                    }
                    );

                    Post as a guest















                    Required, but never shown





















































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown

































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown







                    Popular posts from this blog

                    Accessing regular linux commands in Huawei's Dopra Linux

                    Can't connect RFCOMM socket: Host is down

                    Kernel panic - not syncing: Fatal Exception in Interrupt