Sascha Wilde <wilde at intevation.de> writes: [...] > But this doesn't work: I can't even bind as > cn=manager,cn=internal,dc=foo,dc=bar I suppose because the user is an > child of "internal", and so anonymous isn't allowed to access the > object for authentication. For the records: my analysis of the problem was wrong. It _is_ possible to bind as an object which is not world readable. My problems were caused by an specific client, so this is an non issue. Sorry for the noise. sascha -- Sascha Wilde OpenPGP key: 4BB86568 Intevation GmbH, Osnabr?ck http://www.intevation.de/~wilde/ Amtsgericht Osnabr?ck, HR B 18998 http://www.intevation.de/ Gesch?ftsf?hrer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 188 bytes Desc: not available Url : http://lists.fedoraproject.org/pipermail/389-users/attachments/20070608/1d1274e0/attachment.bin