Solutions

Insufficient Access Rights error for dsreplication status after upgrading a replicated server to DS 6.x

Last updated Jul 30, 2018

The purpose of this article is to provide assistance if the dsreplication status command returns "Insufficient Access Rights: You do not have sufficient privileges to read directory server monitoring information" after upgrading to DS 6.x


1 reader recommends this article

Symptoms

Using a dsreplication status command such as the following returns partial or no information: 

$ ./dsreplication status --hostname localhost.localdomain --port 4444 --adminUID admin --adminPassword password --trustAll --no-prompt

Responses:

  • An error similar to the following is shown when you run dsreplication status non-interactively:
    The displayed information might not be complete because the following errors 
    were encountered reading the configuration of the existing servers:
    
    Error on ds1.example.com: An error occurred connecting to the server. 
    Details: Insufficient Access Rights: You do not have sufficient privileges to 
    read directory server monitoring information 
    
  • The following output is shown when you run the command interactively:
    No replication information found.
    

Recent Changes

Upgraded to DS 6.x.

Causes

The required permissions for monitoring dsreplication have changed in DS 6 and need to be updated manually as noted in the Installation Guide › To Upgrade Replicated Servers.

Solution

This issue can be resolved by adding the following required permissions:

  • bypass-lockdown
  • monitor-read
  • server-lockdown

Example

The following example grants the privileges to the default global administrator account, which has DN cn=admin,cn=Administrators,cn=admin data:

$ ./ldapmodify --port 1389 --hostname ds1.example.com --bindDN "cn=admin,cn=Administrators,cn=admin data" --bindPassword password
dn: cn=admin,cn=Administrators,cn=admin data
changetype: modify
add: ds-privilege-name
ds-privilege-name: bypass-lockdown
ds-privilege-name: monitor-read
ds-privilege-name: server-lockdown
-

See Also

Upgrading DS/OpenDJ

Installation Guide › Upgrading a Directory Server

Related Training

N/A

Related Issue Tracker IDs

N/A



Copyright and TrademarksCopyright © 2018 ForgeRock, all rights reserved.
Loading...