--- "Tay, Gary" <Gary_Tay at platts.com> wrote: > I think you should put "objectclass=*" (search filter) at the end, see > "man ldapsearch" > > If you need to do anything and are not familar with LDAP command tools, > use the admin server to do it. > > IIRC all your LDAP data should have baseDN dc=composers,dc=foo,dc=com, > if your nisdomain (LDAP domain) is set as composers.foo.com. I changed it: # foo.com, foo.com dn: nisdomain=foo.com,dc=foo,dc=com objectClass: top objectClass: nisdomainobject nisDomain: foo.com bash-2.03# ldaplist -l ldaplist: Object not found (LDAP ERROR (50): Insufficient access.) Gary, sorry for being dense but where's the baseDN? I need to check what it is... __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com