If your client is RHEL4 or newer, try adding this line to /etc/ldap.conf: debug 1 This will spit a lot of debugging output to your console whenever you do any lookup through nss_ldap. Maybe it will shed some light. -----Original Message----- From: fedora-directory-users-bounces at redhat.com [mailto:fedora-directory-users-bounces at redhat.com] On Behalf Of Philip Kime Sent: Friday, June 30, 2006 2:42 PM To: fedora-directory-users at redhat.com Subject: Re: Referrals break everything ... > PADL (usually in /etc/ldap.conf): > referrals yes Many thanks for both replies ... This looked good but I tried it and I still get the same error in syslog. Hmm. The binds are all anonymous and work fine so there doesn't seem to be a bind DN issue. http://www.redhat.com/docs/manuals/dir-server/deploy/7.1/dit.html#100588 9 Ah - this is more what I wanted but it appears that you can't do Virtual DITs from roots - has to be from an OU, for example, which is annoying since that means I have to create a new datbase for the old dc=x,dc=y and create an OU so I can create a virtual DIT view. What a game! I just want to redirect all queries for one thing somewhere else ... -- Fedora-directory-users mailing list Fedora-directory-users at redhat.com https://www.redhat.com/mailman/listinfo/fedora-directory-users