Hope I am not reinventing the wheel, apologies if that is the case.
We have installed Teaming on a SLES 10.2 server, with an LDAP connection to
a NetWare 6.5 sp7 eDir 8.7.3.9.
Our tree has multiple organizations of which 4 need to be searched as part
of authenticating users for the Teaming access. The NetWare server holds
the Master copy for 3 of the Organizations and a read/write for the 4th.

If we leave out the search DN (it does say it is optional) on the LDAP
config no users can authenticate, instead we get -779 and -601 errors on
the dstrace log.

We can put one search dn Org level entry in the LDAP config (both Teaming
and LifeRay) and this allows users in that org and below only to log in.

Thanks in advance.

R

DSTrace portion of error is attached. teamingcs is the pricipal access ID.

New cleartext connection 0x7fb7fc40 from 10.168.133.30:24841, monitor =
0x866, index = 6
[2008/06/23 13:32:09] DoBind on connection 0x7fb7fc40
[2008/06/23 13:32:09] Bind name:cn=teamingcs,ou=its,o=edm, version:3,
authentication:simple
[2008/06/23 13:32:09] 1 GlobalGetSEV.
[2008/06/23 13:32:09] 4 GlobalGetSEV succeeded.
[2008/06/23 13:32:09] [0001e2a7] <.teamingcs.ITS.EDM.CS_JUSTICE.>
LocalLoginRequest. Error success, conn: 1065.
[2008/06/23 13:32:09] Sending operation result 0:"":"" to connection
0x7fb7fc40
[2008/06/23 13:32:09] Operation 0x1:0x60 on connection 0x7fb7fc40 completed
in 0 seconds
[2008/06/23 13:32:09] DoSearch on connection 0x7fb7fc40
[2008/06/23 13:32:09] Search request:
base: ""
scope:2 dereference:3 sizelimit:1 timelimit:0 attrsonly:0
filter: "(cn=hammerk)"
no attributes
[2008/06/23 13:32:09] Empty attribute list implies all user attributes
[2008/06/23 13:32:09] Sending search result entry "cn=HammerK,ou=ITS,o=EDM"
to connection 0x7fb7fc40
[2008/06/23 13:32:09] DoSearch on connection 0x7fb7fc40
[2008/06/23 13:32:09] Search request:
base: "cn=HammerK,ou=ITS,o=EDM"
scope:0 dereference:3 sizelimit:0 timelimit:0 attrsonly:0
filter: "(objectClass=*)"
no attributes
[2008/06/23 13:32:09] Empty attribute list implies all user attributes
[2008/06/23 13:32:09] Sending search result entry "cn=HammerK,ou=ITS,o=EDM"
to connection 0x7fb7fc40
[2008/06/23 13:32:09] Sending operation result 0:"":"" to connection
0x7fb7fc40
[2008/06/23 13:32:09] Operation 0x3:0x63 on connection 0x7fb7fc40 completed
in 0 seconds
[2008/06/23 13:32:09] New cleartext connection 0x7e5e2b60 from
10.168.133.30:21641, monitor = 0x866, index = 16
[2008/06/23 13:32:09] DoBind on connection 0x7e5e2b60
[2008/06/23 13:32:09] Bind name:cn=HammerK,ou=ITS,o=EDM,, version:3,
authentication:simple
[2008/06/23 13:32:09] <0x4> LocalLoginRequest. Error cannot go remote
(-779), conn: -1.
[2008/06/23 13:32:09] Failed to resolve full context on connection
0x7e5e2b60, err = no such entry (-601)
[2008/06/23 13:32:09] Failed to authenticate full context on connection
0x7e5e2b60, err = no such entry (-601)
[2008/06/23 13:32:09] Sending operation result 32:"":"NDS error: no such
entry (-601)" to connection 0x7e5e2b60
[2008/06/23 13:32:09] Operation 0x1:0x60 on connection 0x7e5e2b60 completed
in 0 seconds.