Quoting Craig White <craigwhite at azapple.com>: > This is basic stuff and I could do it easily with openldap and I can see > I am close. I can get what I need from command line ldapsearch and it > works fine. > > RHEL 4 - have run authconfig and my pam.d/system-auth looks like wiki > page for FDS with PAM > > I can tell that the padl stuff (nsswitch.conf and /etc/ldap.conf) is > working because the logs show me that 'cn=Directory Manager' is > attempting to bind but it always returns error=32 (obviously no such > object...which by the way is a lousy error report because obviously this > is about invalid credentials and should return error=49) Is "cn=Directory Manager" really your directory manager account? With OpenLDAP, I've always seen rootdn's like "cn=directory manager, dc=azapple,dc=com", for instance, so depending on how you converted your data, and setup your rootdn in FDS, error=32 is likely correct. Kevin -- Kevin M. Myer Senior Systems Administrator Lancaster-Lebanon Intermediate Unit 13 http://www.iu13.org