How To Browse the WebLogic Embedded LDAP With User ID Other Than CN=ADMIN From an External LDAP Browser

(Doc ID 1347745.1)

Last updated on DECEMBER 11, 2017

Applies to:

Oracle WebLogic Server - Version 10.3.2 and later
Information in this document applies to any platform.

Goal

Assigning administrator privilege to a particular branch (ou) of the LDAP to an LDAP user id is very common in LDAP configuration. The objective is to allow a user "uid=LdapAdmin,ou=people,ou=myrealm,dc=First_domain1" to add new LDAP people to ou=people,ou=myrealm,dc=First_Domain

The steps are detailed at https://docs.oracle.com/cd/E12840_01/wls/docs103/secmanage/ldap.html#wp1102244:

  1. Add the following line to WL_HOME/server/lib/acls.prop:
  2. Restart AdminServer.

However, the LDAP browser can only see the ou=people,ou=myrealm,dc=First_domain object. No attribute nor children objects can be seen.

Solution

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms