<div dir="ltr">Yea you can do anonymous auth, you would need to setup an ACL on the database to allow this.<div><br></div><div><a href="http://www.zytrax.com/books/ldap/ch15/">http://www.zytrax.com/books/ldap/ch15/</a> .<br>
</div></div><div class="gmail_extra"><br><br><div class="gmail_quote">On Mon, Jun 30, 2014 at 8:40 PM, Hendry, Chris <span dir="ltr"><<a href="mailto:Chris.Hendry@turner.com" target="_blank">Chris.Hendry@turner.com</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Thanks for responding.....<br>
<br>
As I was alluding, it is an external LDAP server and I do not know the password.<br>
<div class="">Isn't there a way to set this up with READ-ONLY?<br>
Examples on the internet only talk about where you have admin rights.<br>
<br>
</div>Chris<br>
<br>
<br>
<br>
> Message: 3<br>
> Date: Sun, 29 Jun 2014 20:36:23 +0000<br>
> From: Shawn <<a href="mailto:taaj.shawn@gmail.com">taaj.shawn@gmail.com</a>><br>
> To: Atlanta Linux Enthusiasts <<a href="mailto:ale@ale.org">ale@ale.org</a>><br>
> Subject: Re: [ale] Samba - external LDAP<br>
> Message-ID:<br>
> <CADSjncRXA+eymaki-29TMkRjbckFuGCOyWfJ5-<br>
> <a href="mailto:SW3jJLkfphow@mail.gmail.com">SW3jJLkfphow@mail.gmail.com</a>><br>
> Content-Type: text/plain; charset="utf-8"<br>
<div class="im HOEnZb">><br>
> ldapsearch -x -H ldap://fqdn -D cn=Manager,dc=xxx,dc=xxx,dc=com -W<br>
><br>
> sorry forgot the password prompt thingy<br>
><br>
><br>
> On Sun, Jun 29, 2014 at 8:35 PM, Shawn <<a href="mailto:taaj.shawn@gmail.com">taaj.shawn@gmail.com</a>> wrote:<br>
><br>
> > Looks like your bind dn creds are wrong<br>
> ><br>
> > ldapsearch -x -H ldap://fqdn -D cn=Manager,dc=xxx,dc=xxx,dc=com<br>
> ><br>
> > is that successful?<br>
> ><br>
> ><br>
> > On Sat, Jun 28, 2014 at 8:48 PM, Hendry, Chris<br>
> > <<a href="mailto:Chris.Hendry@turner.com">Chris.Hendry@turner.com</a>><br>
> > wrote:<br>
> ><br>
> >><br>
> >><br>
> >><br>
> >> I'm trying to set up a SAMBA share using an external LDAP server for<br>
> >> authentication that I have no control over.<br>
> >><br>
> >> I do not have any admin abilities on the LDAP server, only need read<br>
> >> ability.<br>
> >><br>
> >><br>
> >><br>
> >> Cannot set smbpasswd -w <admin password>, thus get in log:<br>
> >><br>
> >> failed to bind to server ldap://<a href="http://xxx-xxx.xxx.com/" target="_blank">xxx-xxx.xxx.com/</a> with<br>
> >> dn="cn=Manager,dc=xxx,dc=xxx,dc=com" Error: Invalid credentials<br>
> >><br>
> >> (unknown)<br>
> >><br>
> >><br>
> >><br>
> >> Isn't there a way to set this up with READ-ONLY?<br>
> >> Examples on the internet only talk about where you have admin rights.<br>
> >><br>
> >> Thanks for any advise<br>
> >><br>
<br>
<br>
</div><div class="HOEnZb"><div class="h5">_______________________________________________<br>
Ale mailing list<br>
<a href="mailto:Ale@ale.org">Ale@ale.org</a><br>
<a href="http://mail.ale.org/mailman/listinfo/ale" target="_blank">http://mail.ale.org/mailman/listinfo/ale</a><br>
See JOBS, ANNOUNCE and SCHOOLS lists at<br>
<a href="http://mail.ale.org/mailman/listinfo" target="_blank">http://mail.ale.org/mailman/listinfo</a><br>
</div></div></blockquote></div><br><br clear="all"><div><br></div>-- <br><b><i>- Shawn Taaj</i></b><br>
</div>