доигрался... =(( не удалить не добавить через альтератор
ldap_bind: Invalid credentials (49)
сделал slappasswd -s мойпароль
сделал smbpasswd -w мойпароль
конфиг slapd-kmk.conf
database hdb
suffix "dc=kmk"
rootdn "cn=root,dc=kmk"
rootpw secret
directory /var/lib/ldap/bases/kmk
index objectClass eq
index uid eq
index cn eq
index uidNumber eq
index gidNumber eq
access to attrs=userPassword,sambaLMPassword,sambaNTPassword
<------>by self write
<------>by anonymous auth
<------>by * none
access to dn.subtree="ou=kdcroot,dc=kmk"
by dn.exact="cn=kdc,ou=kdcroot,dc=kmk" read
by dn.exact="cn=kadmin,ou=kdcroot,dc=kmk" write
by * none
access to dn.subtree="cn=KMK,cn=kerberos,ou=kdcroot,dc=kmk"
by dn.exact="cn=kdc,ou=kdcroot,dc=kmk" read
by dn.exact="cn=kadmin,ou=kdcroot,dc=kmk" write
by * none
....
access to *
by * read