Help with setting up LDAP Client on Oracle Linux 6.4

Hi,
I'm having problems getting my Oracle Linux server setup as a ldap client and hoping someone can find where I'm going wrong. We have Oracle/Sun Directory Server 7 with Solaris ldap clients already setup with ssl. We are also using crypt for storing passwords. Here are the steps I have done on the Linux server.
yum install -y openldap openldap-clients nss-pam-ldapd pam_ldap
Edited the line FORCELEGACY=no to yes in /etc/sysconfig/authconfig
Copied the CA certs to /etc/openldap/cacerts
Ran: authconfig updateall enableldap enableldapauth ldapserver=zldap1.<domain> ldapbasedn="o=<domain>,o=isp" enableldaptls --enableldapstarttls
Changed pam_password md5 to crypt in /etc/pam_ldap.conf
Restarted /etc/init.d/nslcd and also tried rebooting.
I'm seeing the following errors in messages:
May 21 08:50:01 ryolinux nslcd[1261]: [c79ea8] ldap_start_tls_s() failed: Connect error (uri="ldap://zldap1.<domain>/")
May 21 08:50:01 ryolinux nslcd[1261]: [c79ea8] failed to bind to LDAP server ldap://zldap1.<domain>/: Connect error
May 21 08:50:01 ryolinux nslcd[1261]: [c79ea8] no available LDAP server found
Here is what my /etc/openldap/ldap.conf file looks like:
TLS_CACERTDIR /etc/openldap/cacerts
TLS_REQCERT allow
URI ldap://zldap1.<domain>/
BASE o=<domain>,o=isp
Any help would be appreciated.
Thanks

Copy cacerts to /etc/openldap/cacerts
yum install -y openldap ldap-clients nss-pam-ldapd pam_ldap authconfig sssd
authconfig enablesssd enablesssdauth enablelocauthorize update
authconfig updateall enableldap enableldapauth ldapserver=zldap1.<domain> ldapbasedn="o=<domain>,o=isp" enableldaptls --enableldapstarttls
Add line to /etc/sssd/sssd.conf "ldap_tls_reqcert = allow"
Change /etc/pam_ldap.conf line:
pam_password md5 --> pam_password crypt
service sssd restart

Similar Messages

  • Help with setting up pointing clients to server..

    Okay, here is my situation. We have many macs on the network that currently don't login, open machines. We do have Blue Socket on the wireless, but otherwise the machines are all open. We want to get most, if not all, the macs to authenticate against LDAP or AD (preferrably AD). So I guess we need the Macs clients to go directly to the AD and authenticate, and also have the Macs controlled by the server (privledges, software update, printing, etc).
    Question one:
    Best way to approach this?
    Question two:
    How do you get the clients to point to the server if they are getting their IP's from another DHCP server.
    (would this be done in directory access via ????)
    All the info you can provide would be greatly appreciated.
    Thanks
    Dave

    This might be useful...
    http://www.afp548.com/article.php?story=20040915152755925&query=AD%2BIntegration

  • Can anyone help with setting up AirPrint on my iPhone 4

    Can anyone help with setting up AirPrint on my iPhone 4.  Printer is ready.

    you have a compatable printer correct? http://support.apple.com/kb/ht4356
    if you do may i introduce you to a hassel free app for your mac called printopia i use it also very easy to set up and use
    http://www.udeo.com/mac/printopia/
    hope thats helped
    Goody

  • Purchased extreme to replace modem/router DSL used telephone cord need help with set up

    Prior to purchasing Airport Extreme had a standard modem/ wireless router from ATT for DSL. I have two macbooks both dropped connections while online with older modem.
    Airport Extreme purchased to correct connection issues I need help with set up. The older modem just used telephone cord. I tried to use telephone with extreme it did not work.
    How do I get extreme to work as the modem and router ?

    How do I get extreme to work as the modem and router ?
    you can't. the extreme is only a router. you need a separate modem (or disable the wireless part of your old router and use it as a modem - if that's possible).

  • I need help with setting up time machine for backup

    I would like help with setting up time machine for backup.

    You will need an external hard drive (formatted for a Mac).
    Then you plug it in and go to system preferences>time machine and select the external HD and turn it on.
    The backups are automatic.
    Barry

  • I need help with setting up my Sun Java Studio Creator

    Hello all, i need help with setting up the Studio Creator, i"m new to all that staff so is there anyone to help me just a little with all that if yes email me at [email protected] or get me on AOL Instant Messanger with the screen name: wretch17
    thanks :-)

    Hi,
    Welcome to the Creator community! Thanks for your interst in Sun Java Studio Creator. Please feel free to post any question related to creator on this forum .
    Take a look the creator website at
    http://developers.sun.com/prodtech/javatools/jscreator/
    CreatorTeam

  • Reg: SVN client for oracle linux

    Hi,
    can u plz provide some link to download and instal SVN CLIENT in ORACLE LINUX.
    Thanks,
    Nitesh

    They have installed the wrong Linux distro on that desktop.
    A server o/s does not provide default support for desktop h/w (like webcams, touchpads, latest video chipsets, etc). Instead, it provides support for server h/w and server environments.
    What you should be looking at is Ubuntu 12.10 or 13.04 (see http://www.ubuntu.com/). It is arguably the best Linux desktop distro. I have been using it for over 10 years now doing development and support. Prior to that I used Fedora, but it never did provide a smooth install and out-of-the-box driver support for desktop h/w. And I doubt that this has changed to be better than what Ubuntu supports and provides.
    If you do use Ubuntu, consider the 64bit version if your are developing s/w for 64bit Linux - makes development and deployment easier as there are some differences between the 32bit and 64bit kernels.
    You will also be able to install 64bit Oracle XE on your desktop (if you do get to that stage and need assistance in getting the XE Redhat RPM installed, post a message on the database general questions forum).

  • Issue with creating Web Service Client using Oracle JDeveloper

    Hi All,
    I am trying to create a Web Service Client using Oracle JDeveloper. I set the Project compiler property to JRE 1.4
    When I run the web service client, it throws me bunch of errors saying:
    'Error(32,2): annotations are not supported in -source 1.4'
    I am wondering why JDeveloper is using annotations even after I set the compiler property to 1.4
    I am following this link to create the webservice client:
    http://www.oracle.com/technetwork/developer-tools/forms/webservices-forms-11g-094111.html
    Any help in this regard would be greatly appreciated.
    Thanks,
    Scott.

    Dear Shay,
    Thanks for your prompt response.
    You are right. JDeveloper 11g uses JDK 6 style annotations for the clients it creates. But you can change the JRE Version used at compile time by following these steps:
    1. In the Applications Navigator, right-click the Project Nanem node and select Project Properties... from the context menu.
    2. Select the Compiler node and check the Source Files and Generated Class Files dropdown lists. You may change these versions depending on the version of the JRE you are using with Forms to ensure that the compiled
    classes from JDeveloper can be read by the JRE used by Form.
    So I selected JDK version 1.4 there.
    Sorry that I did not mention that we are using Oracle Forms 10g. That is the reason I selected JDK 1.4
    Thank you.
    Scott.

  • Problem while creating an OU from LDAP client, in Oracle Virtual Directory

    Hi,
    1. I have created a Custom Adapter with root (i.e. dc=mycompany,dc=co,dc=in)
    2. Trying to create an "OU" under these above root (i.e. ou=test,dc=mycompany,dc=co,dc=in) using the LDAP client.
    I have given following inputs for the second step:
    Dn: ou=test,dc=mycompany,dc=co,dc=in
    ou=test
    objectClass: top
    objectClass: organizationalunit
    When I try to perform second step with above inputs its gives following error
    "LDAP Error 32 : No Such Object"
    Same inputs is valid for SunONE directory server.
    Is the above approach is valid for Oracle Virtual Directory?
    Does any one faced same problem before?
    Regards,
    Hardew

    You're going to have to install the Oracle client on the Win2000 box before doing anything else. Once you've done that, simply add a TNS name that points to the database on the Solaris box (the Net8 Configuration Assistant) can walk you through this. Finally, you'll go to the ODBC Data Source Administrator and create a new DSN.
    Note that if you install the latest ODBC driver, the 'service name' text box that you have to fill in when you actually create the DSN has been replaced with a combo box, which should make the process a little easier.
    Justin

  • Need Help with Setting Up E-Mail on My BlackBerry Q-10

    This is my first "not basic" cell phone so I'm struggling in setting it up (there are things that just are not covered at all in the on-line User's Manual). The BlackBerry Q-10 apparently doesn't display the full-on "compose" e-mail screen unless an e-mail account is set up. The e-mail account I have is what I access on my desktop computer; and because I get so, so many unimportant e-mails on it every day, I don't want to be getting all these e-mails on my cell phone (but I "do" want access on my cell phone to ALL the e-mail screens and options). Is there a way I can use my existing desktop computer e-mail address to set up the e-mail account on my BlackBerry Q-10 but then somehow turn the "incoming" e-mail function on the cell phone off completely (so I only get the e-mails on my computer)? Also, what does it mean when it asks if I want to "sync" my e-mails? Any help would be greatly appreciated!
    Solved!
    Go to Solution.

    Two or three thoughts.
    My BlackBerry handset has become my exclusive email tool. I think if you get used to the idea of accessing email from different machines, with the BlackBerry being one of them, it will begin to make sense.
    If you haven't enabled a junk email filter at the server level on your email service, do it. Filtered email will not be sync'd with the BlackBerry email client.
    Set up your email as IMAP. If you are using Outlook.com, setup as EAS. Create folders for email you don't want sync'd to the inbox on the BlackBerry. Setup rules to move that email to the appropriate folder as it arrives. You will be able to view those folders and their contents on the BlackBerry when you want, but they will not be sync'd automatically unless you turn that on.
    As far as your last question, what is the context? Generally speaking, the email can be automatically synchronized. If IMAP or EAS, the folders on the device and other devices and the servers are synchronized. Read an email one place and it is marked read everywhere. Ditto deletes and moves.
    - Ira

  • Need Help with setting up this Filter

    Hi,
    I need help making a filter sound like the one used in this youtube song.
    I tried setting it up but I've had no success; even though I know for a fact that this filter was made in Logic Pro 9 according to the maker of this song.
    I think there might be a bit of 'Fuzz-Wah' in there too but I've never really used that effect so any tips on that would be great, too.
    Link: http://www.youtube.com/watch?v=tf017M8SZZE&feature=plcp
    Any help with this would be widely appreciated.
    Thank you :-)

    It sounds like a simple hi Q filter sweep to me but getting close to the original synth sound that it is being used on is the challenge. It might well be that it is the filter on the synth itself is what is being swept. Either way, turn up the filter resonance on a band pass filter and sweep it with the lfo or adsr to modulate the filter cutoff if its the synth filter, or automate the filter frequency  sweep if you use the channel filter.

  • Need help with Set-ADUser command

    I need a little help with the following command. Im new to PS and I have found this command but it is only one user at a time. I need to be able to update ALL users in AD.
    My goal is this. Someone before me set all Users Home numbers to 1234567899 and I need to remove that and leave it blank. The command below allows me to do that but only one user at a time by entering their SAMID.
    Is there a way to do this for everyone in AD ?
    Set-AdUser –Identity SAMID –HomePhone $NULL

    Yeah sure - 
    Get-Aduser -filter * -properties SamaccountName | Select SamAccountName | % {Set-Aduser -identity $_.SamaccountName -HomePhone $null}

  • Help with set(index, object) please / new to java

    private static void setDobject(Rectangle [] setrect)
              LinkedList<Rectangle> rects = new LinkedList<Rectangle>();
              Rectangle myrectangle = new Rectangle(9.0,9.0);                                                                  
                 rects.set(1,myrectangle);
              for(Rectangle x : setrect)
                   System.out.print("Rectangle: ");
                   System.out.println(x.getLength() + " by " + x.getWidth());
              }  //End of for loop
         }  //End of unsorted
         }  the other previous code works, i have used the add(object) and it works here is the code for that:
    private static void addDobject(Rectangle [] addrect)
              LinkedList<Rectangle> rects = new LinkedList<Rectangle>();
              Rectangle myrectangle = new Rectangle(9.0,9.0);                                                                  
                 rects.add(myrectangle);
                 for(Rectangle x : rects)
                   System.out.print("Rectangle: ");
                   System.out.println(x.getLength() + " by " + x.getWidth());
              }  //End of for loop
              System.out.println();
         }  //End of unsorted
    this is the output error it is giving me :
    Part 1 : An Array List of Rectangles
    Enter length or 999 to exit: 3
    Enter width: 2
    Enter length or 999 to exit: 1
    Enter width: 2
    Enter length or 999 to exit: 10
    Enter width: 20
    Enter length or 999 to exit: 999
    Rectangle: 3.0 by 2.0
    Rectangle: 1.0 by 2.0
    Rectangle: 10.0 by 20.0
    Display Object with added item
    Rectangle: 3.0 by 2.0
    Rectangle: 1.0 by 2.0
    Rectangle: 10.0 by 20.0
    Rectangle: 9.0 by 9.0
    Displaying Objects with SET item
    Exception in thread "main" java.lang.IndexOutOfBoundsException: Index: 1, Size:
    0
    at java.util.LinkedList.entry(LinkedList.java:365)
    at java.util.LinkedList.set(LinkedList.java:328)
    at Lab11.setDobject(Lab11.java:129)
    at Lab11.main(Lab11.java:78)
    Press any key to continue...
    finally here is the Rectangle class i'm using:
    public class Rectangle
        private double length;     // Instance variables
        private double width;
        public Rectangle(double l, double w)  // Constructor method
            length = l;
            width = w;
        } // end Rectangle constructor
        public double getLength()             // getter 
             return length;
        } // end getLength
         public double getWidth()             // getter 
             return width;
        } // end getWidth
        public void setLength(double l)      // setter 
             length = l;
        } // end setLength
         public void setWidth(double w)     // setter 
             width = w;
        } // end setWidth
         public double calculateArea()         // calculation method
            return length * width;
        } // end calculateArea
        public void displayRectangle()         // display method
            System.out.println("Rectangle Length = " + length);
            System.out.println("Rectangle Width = " + width);               
        } // end displayRectangle
    } // Rectangle ClassHope you can help guys! thanks!

    LinkedList<Rectangle> rects = new LinkedList<Rectangle>();rects is an empty LinkedList at this point. It has no elements added to it.
    rects.set(1,myrectangle);So you can't set the item at index 1 (the 2nd element in the list) because it doesn't even exist. You need to add items to it.

  • New computer ~ Help with setting up

    Hi everyone, Newbie here!
    I am going to set my new computer up tomorrow. The computer I am using at present was installed and set up by someone else so this will be a great learning curve for me. Also I had Infinity installed by the engineer.
    Is everything I need to install relating to my broadband available to download? What do I need altogether? I spoke to a BT chap on the phone and he said he would help by remote access. I am a bit nervous of this!
    I need to ensure my computer is safe and secure and it all seems technically daunting. Norton security came with  my Microsoft Office package. Is this better than McAfee (Net Protect Plus), do I need both? What about a key code scrambler  (someone mentioned this to me). As you can see I need reassurance and help arghhhhhhh.
    A step by step guide would be great!
    Thanks
    Solved!
    Go to Solution.

    It is best not to install any of the BT software, just connect your computer to the BT Home hub using an Ethernet cable, or by using the wireless key, if its a wireless connected computers.
    See http://bt.custhelp.com/app/answers/detail/a_id/14964/~/getting-started-with-wireless
    Using a direct cable connection is best, if you want to get maximum speed.
    I would not allow anyone remote access, but if you have no choice, and cannot resolve the issue any other way, then make sure that it is as a direct result of you ringing BT, and not some random person ringing you at home, pretending to be from BT or even Microsoft.
    Many people have been caught out by that type of call, and had their computer infected with spyware.
    If you already have a trial version of Norton Security, then by all means use it until it expires, then uninstall it.
    After that, you have the choice of using the free Microsoft Security Essentials, which is preferred by many forum members, or using BTs Netprotect which is free with some broadband packages. This has been known to make computers run more slowly though.
    That is all you need.
    If you have any problems, then please return here.
    If you have any problems with BT Infinity, then please visit the Infinity board on this forum.
    There are some useful help pages here, for BT Broadband customers only, on my personal website.
    BT Broadband customers - help with broadband, WiFi, networking, e-mail and phones.

  • Help with setting a MDX goal expression in SSAS

    Our data is updated monthly and the last date of available data can be anywhere from 45-75 days behind.  For example, data is current through 6/30/2014
    as of 8/25/2014.
    I have a Time dimension hierarchy named [Calendar] with [Year]>[Half Year]>[Quarter]>[Month]>[Date] 
    I have a measure, [Measures].[Fatalities] set as a calculated member.
    I have a KPI with [Measures].[Fatalities] set as the Value Expression. My issue is with setting up the goal expression.
    I am trying to set a goal expression that is a percent reduction for a 5-year baseline average (Year-7:Year-3). So for the current year (2014, with data through
    June 2014), the goal would be a 20% reduction of the average of the Jan-Jun 2007, Jan-Jun 2008,Jan-Jun 2009,Jan-Jun 2010,Jan-Jun 2011.
    I have set up the following MDX as the goal expression:
    .8*((
    ([Measures].[Fatalities],
    PARALLELPERIOD([Time].[Calendar].[Year],7,[Time].[Calendar].CurrentMember))
    +
    ([Measures].[Fatalities],
    PARALLELPERIOD([Time].[Calendar].[Year],6,[Time].[Calendar].CurrentMember))
    +
    ([Measures].[Fatalities],
    PARALLELPERIOD([Time].[Calendar].[Year],5,[Time].[Calendar].CurrentMember))
    +
    ([Measures].[Fatalities],
    PARALLELPERIOD([Time].[Calendar].[Year],4,[Time].[Calendar].CurrentMember))
    +
    ([Measures].[Fatalities],
    PARALLELPERIOD([Time].[Calendar].[Year],3,[Time].[Calendar].CurrentMember))
    )/5
    The problem is that the goal is taking the entire year average at the year level of the Calendar hierarchy.  For example, in the attached screenshot, the
    Fatalities Goal would be empty when the fatalities is empty, and more importantly, the goal at the Year level of the Calendar hierarchy would only be the sum of Jan-Jun goal.  The Fatalities Goal in this example should read 549.28 at the Calendar 2014
    Year level and the status would still be green.
    http://i.imgur.com/peHD9Wl.png

    you might find this app interesting: http://ivolume.en.softonic.com/mac.

Maybe you are looking for

  • Moved my itunes folder to new drive, now can't see my music in itune

    I transferred my itunes over to an external drive per the step-by-step instructions on the Apple site, which assures that all playlists will be maintained. iTunes Properties shows the correct location of the new folder, which, judging by its size, do

  • Attach Terms and Condition in PDF to Script

    Hi Experts, I have a requirement to include the Terms and conditons ( 4 pages  -  2 columnwise ) in PDF document. Now they want to include it to already existing script. I just first thought of inlcuding the Terms and conditions using Include Text. B

  • Using PGP on a BlackBerry 9790, how-to?

    I want to install the PGP Package on my 9790 to encrypt and decrypt emails from my emailbox to another using the public and private keys; is this possible? Does this only work with the applications provided by PGP Corporation, or with the free GPGToo

  • About variables in query designer

    what is the difference between replacement path and cmod in query designer? illustrate with an example? Regards, Bhavya K

  • RFIDYYWT / 1099 reporting / include doc type AB?

    We are preparing to use SAP's 1099 Misc reporting functionality for the 2011 tax year, and have managed to resolve most issues. However, we can't figure out how to get miscellaneous journal entries (doc type AB) included in the reporting. I've confir