Re: [389-users] Performance tuning OS side

2012-02-01 Thread Mark Reynolds
Hi Marco, This is isn't linux specific, but disabling the logs(access error) can help. If you need the logs, move them to a dedicated FS. I don't know if Linux has a FS cache, but on Solaris I've seen it is sometimes more efficient to turn the DS cache settings all the way down, and allow

Re: [389-users] how to change tiemzone

2012-03-02 Thread Mark Reynolds
: 20120228201328Z What I would like if all above time be my local time, which will a little bit easy for understanding -- Shouben Zhou Science Systems and Applications Inc.(SSAI) 1 Enterprise Pkwy, Hampton, VA 23666 Tel: (757)951-1905 Fax: (757)951-1900 Email: shouben.z...@nasa.gov Mark Reynolds

Re: [389-users] Problems logging in with 389-console

2012-03-16 Thread Mark Reynolds
Hi Michael, see comments below... On 03/16/2012 02:42 PM, Michael Mercier wrote: Hello, I seem to be having problems using the 389-console GUI. I am entering the following information into each of the fields: User ID: cn=Directory Manager Password: password Administration URL:

Re: [389-users] Missing creatorsName/createTimeStamp after migrate from Sun One dir to ds389

2012-04-04 Thread Mark Reynolds
Sam, I could not reproduce the issue with the latest version of 389. After an import it still had the the creatorsName that was present in the ldif file. Check the config in dse.ldif. Make sure nsslapd-lastmod is set to on under cn=config. Regards, Mark On 04/03/2012 11:15 PM, Sam Wen

Re: [389-users] Repair replication

2012-04-23 Thread Mark Reynolds
Hi Herb,/ /While working on a different replication issue I accidentally reproduced your issue. My issue was a typo in the password in the repl agreement. I know you said you passwords were the same, but maybe there is still a mismatch. Also, if the root dn specified in the agreement

Re: [389-users] management console authentication error

2012-04-23 Thread Mark Reynolds
Herb, Do you know which server is hosting the config data for the console(o=netscaperoot)? If you do, please provide the access log output showing the cn=directory manager and admin binds? It might not hurt to restart the admin server. Thanks, Mark On 04/23/2012 04:06 PM, Herb

Re: [389-users] management console authentication error

2012-04-24 Thread Mark Reynolds
-hostname if that is in fact the problem? TIA, Herb On Tue, Apr 24, 2012 at 8:34 AM, Mark Reynolds marey...@redhat.com mailto:marey...@redhat.com wrote: Hi Herb, I wanted to see the logs from the server that wasn't working. According to these logs everything is fine. So, you

Re: [389-users] unhashed#user#password field

2012-05-21 Thread Mark Reynolds
Also see: https://fedorahosted.org/389/ticket/365 This is will be included in a future release. Mark On 05/18/2012 02:13 PM, Alberto Viana wrote: I have a 389 DS server replication agreement whith an AD Server and when I change the password in the windows side it replicates into 389 but via

Re: [389-users] compressed log files

2012-05-21 Thread Mark Reynolds
I think this is a reasonable RFE. We should probably have separate tickets for the core server, and logconv.pl though. Mark On 05/21/2012 11:18 AM, Michael R. Gettes wrote: Hi, I figured I would ask the question here before proceeding with a RFE. I searched TRAC and couldn't locate any

Re: [389-users] Disable unhashed#user#password altogether

2012-05-22 Thread Mark Reynolds
Lucas, A fix was just made to hide it from the audit log: https://fedorahosted.org/389/ticket/365 The following ticket is to hide it all together, but this has not been fixed yet: https://fedorahosted.org/389/ticket/378 Mark On 05/22/2012 05:32 PM, Lucas Sweany wrote: Is there a way to

Re: [389-users] Disable unhashed#user#password altogether

2012-05-22 Thread Mark Reynolds
stored in the database, not just in memory. Do you think the latest ticket will address that as well? -Lucas On Tue, May 22, 2012 at 2:37 PM, Mark Reynolds marey...@redhat.com mailto:marey...@redhat.com wrote: Lucas, A fix was just made to hide it from the audit log: https

Re: [389-users] GSSAPI authentication between 1.2.10 and 1.2.11

2012-05-30 Thread Mark Reynolds
error. Are there any known bugs / changes that could possible cause this to happen? Edward -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users -- Mark Reynolds Senior Software Engineer Red Hat, Inc mreyno...@redhat.com -- 389

Re: [389-users] password expiration warnings

2012-05-30 Thread Mark Reynolds
/Monitoring_DS_Using_SNMP.html Mark Josh -- Joshua Ellsworth System Administrator, Primatics Financial Phone: 571.765.7528 jellswo...@primaticsfinancial.com -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users -- Mark Reynolds Senior

Re: [389-users] GSSAPI authentication between 1.2.10 and 1.2.11

2012-05-30 Thread Mark Reynolds
://admin.fedoraproject.org/mailman/listinfo/389-users -- Mark Reynolds Senior Software Engineer Red Hat, Inc mreyno...@redhat.com -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users

Re: [389-users] dse.ldif errors with a reboot

2012-07-23 Thread Mark Reynolds
-- Mark Reynolds Senior Software Engineer Red Hat, Inc mreyno...@redhat.com -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users

Re: [389-users] Delete users from different groups

2012-08-08 Thread Mark Reynolds
://admin.fedoraproject.org/mailman/listinfo/389-users -- Mark Reynolds Senior Software Engineer Red Hat, Inc mreyno...@redhat.com -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users

Re: [389-users] What to do about windows sync when AD entries move out of scope

2012-08-22 Thread Mark Reynolds
if it is marked or not, we would know what to do with it. -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users -- Mark Reynolds Senior Software Engineer Red Hat, Inc mreyno...@redhat.com -- 389 users mailing list 389-users

Re: [389-users] What to do about windows sync when AD entries move out of scope

2012-08-22 Thread Mark Reynolds
On 08/22/2012 04:23 PM, Rich Megginson wrote: On 08/22/2012 02:18 PM, Mark Reynolds wrote: On 08/22/2012 04:09 PM, Rich Megginson wrote: Let's say you have a windows sync agreement AD: cn=Users,dc=example,dc=com DS: ou=People,dc=example,dc=com Let's say you also have another user

Re: [389-users] Fwd: Allow to add a user (userpassword)

2012-09-24 Thread Mark Reynolds
=ldap:///uid=my.appuid,ou=test,dc=test,dc=com;;) Thanks -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users -- Mark Reynolds Red Hat, Inc mreyno...@redhat.com -- 389 users mailing list 389-users@lists.fedoraproject.org https

Re: [389-users] pwdUpdateTime when password policies are applied.

2012-09-28 Thread Mark Reynolds
-- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users -- Mark Reynolds Red Hat, Inc mreyno...@redhat.com -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman

Re: [389-users] pwdUpdateTime when password policies are applied.

2012-09-28 Thread Mark Reynolds
ubtree/user policies if you so desire. Regards, Mark On 09/28/2012 11:14 AM, Mark Reynolds wrote: Juan, I did reproduce the problem.  If you setup a subtree policy through the console, it doesn't pull in the config setting.  I'll

Re: [389-users] Password + anything works ?

2012-11-12 Thread Mark Reynolds
between the client and the server, I have tried to get TLS to run a few times but could not get it to run so far. Am I right about the assumption that I need encryption between the server and the clients for password change to work ? Regards On Mon, Nov 12, 2012 at 8:56 PM, Mark Reynolds marey

[389-users] request for access logs...

2013-01-09 Thread Mark Reynolds
and bases. If anyone is interested in helping me out, please email me directly. Thanks, Mark -- Mark Reynolds Red Hat, Inc mreyno...@redhat.com -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users

Re: [389-users] request for access logs... Thanks

2013-01-09 Thread Mark Reynolds
Ok, thanks for those who responded. I have what I need. Thanks, Mark On 01/09/2013 03:28 PM, Mark Reynolds wrote: I'm working on some improvements to the logconv.pl script (access log analyzer) - particularly memory usage. I would be greatly interested in getting some real world access logs

Re: [389-users] Can't create DSInstances as user (uid !=0) with 389-ds-base-1.3.0.2-1.fc18.x86_64 on FC18

2013-02-10 Thread Mark Reynolds
- 20133 Milano (MI) Italy. Phone: +39 02 26600525 Mobile: +39 3346220663  -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users -- Mark Reynolds Red Hat, Inc mreyno...@redhat.com -- 389 users mailing list 389-users

Re: [389-users] documentation on creating/using roles

2013-03-12 Thread Mark Reynolds
accounts if i can avoid it. thanks - Elizabeth J -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users -- Mark Reynolds Red Hat, Inc mreyno...@redhat.com -- 389 users mailing list 389-users@lists.fedoraproject.org https

[389-users] Announcing 389 Directory Server version 1.2.11.19

2013-03-13 Thread Mark Reynolds
messages encountered when using POSIX winsync Ticket 576 - DNA: use event queue for config update only at the start up Ticket 572 - PamConfig schema not updated during upgrade Bug 906005 - Valgrind reports memleak in modify_update_last_modified_attr Mark Reynolds (4): bump

[389-users] Announcing 389 Directory Server version 1.3.0.4

2013-03-13 Thread Mark Reynolds
, file it in our Trac instance: https://fedorahosted.org/389 Detailed Changelog since 1.3.0.3 Mark Reynolds (3): bump version to 1.3.0.4 Ticket 570 - DS returns error 20 when replacing values of a multi-valued attribute (only when replication is enabled) Ticket 590 - ns-slapd

Re: [389-users] console vs nsslapd-allow-anonymous-access

2013-04-09 Thread Mark Reynolds
-- Mark Reynolds Red Hat, Inc mreyno...@redhat.com -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users

Re: [389-users] clean ruv error

2013-04-22 Thread Mark Reynolds
for it and I only read about internal state. Thanks in advance. Moses. -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users -- Mark Reynolds Red Hat, Inc mreyno...@redhat.com -- 389 users mailing list 389-users

Re: [389-users] How do I restrict groups

2013-07-09 Thread Mark Reynolds
@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users -- Mark Reynolds Red Hat, Inc mreyno...@redhat.com -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users

Re: [389-users] Question about lastlogintime

2013-07-26 Thread Mark Reynolds
@lists.fedoraproject.org _https://admin.fedoraproject.org/mailman/listinfo/389-users_ -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users -- Mark Reynolds Red Hat, Inc mreyno...@redhat.com -- 389 users mailing list 389-users@lists.fedoraproject.org

Re: [389-users] ACI to permit user create his own subentry?

2014-02-06 Thread Mark Reynolds
-- Mark Reynolds 389 Development Team Red Hat, Inc mreyno...@redhat.com -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users

Re: [389-users] intermittent issues with the DNA plugin

2014-03-05 Thread Mark Reynolds
a question Ive noticed that when the plugin updates the value of dnanextvalue it only does it on the local server not all of them is there any way to get these fields to replicate. -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users -- Mark

Re: [389-users] Importing Pre-Hashed Passwords

2014-03-10 Thread Mark Reynolds
389server (FreeIPA) server? Steven Crothers steven.croth...@gmail.com -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users -- Mark Reynolds 389 Development Team Red Hat, Inc mreyno...@redhat.com -- 389 users mailing list 389-users

Re: [389-users] Importing Pre-Hashed Passwords

2014-03-10 Thread Mark Reynolds
” feature myself. If you have the information on hand, that would be greatly appreciated. :) Thanks for setting me in the right direction! On Mar 10, 2014, at 10:25 AM, Mark Reynolds marey...@redhat.com wrote: Steven, What version of 389 are you using? You can import it using the ldif2db

Re: [389-users] Importing database to new server

2014-03-11 Thread Mark Reynolds
trying to restore? What do you mean it turns into ldap2? What is the exact problem as it sounds like the import is working? thanks, EJ -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users -- Mark Reynolds 389 Development Team

Re: [389-users] Serious write-performance problems on RHEL6 - CoS cache repeatedly rebuilding?

2014-04-01 Thread Mark Reynolds
-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users -- Mark Reynolds 389 Development Team Red Hat, Inc mreyno...@redhat.com -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users

Re: [389-users] Failed to send extended operation: LDAP error -1 (Can't contact LDAP server)

2014-05-05 Thread Mark Reynolds
On 05/05/2014 12:13 PM, Graham Leggett wrote: On 05 May 2014, at 5:41 PM, Rich Megginson rmegg...@redhat.com wrote: See https://fedorahosted.org/389/ticket/47606 This bug looks quite consistent with the OP's symptoms and the presence of a large group entry, but he should be seeing Incoming

Re: [389-users] Failed to send extended operation: LDAP error -1 (Can't contact LDAP server)

2014-05-05 Thread Mark Reynolds
On 05/05/2014 12:46 PM, Graham Leggett wrote: On 05 May 2014, at 6:18 PM, Mark Reynolds marey...@redhat.com wrote: nsslapd-maxbersize: 0 0 tells the server to use the default value of 2mb, you need to set it higher(5mb?). You're kidding. Zero actually means 2MB. Intuitive. I agree, I don't

Re: [389-users] Password too similar to old one

2014-05-28 Thread Mark Reynolds
On 05/28/2014 04:06 PM, John Trump wrote: Haven't been able to come up with a solution yet. Hopefully someone on the list has a suggestion. On Fri, May 23, 2014 at 12:42 PM, John Trump trum...@gmail.com mailto:trum...@gmail.com wrote: I would like to relax the password policy for

Re: [389-users] Password too similar to old one

2014-05-28 Thread Mark Reynolds
log(/var/log/dirsrv/slapd-INSTANCE/access) output showing the failed password attempt? On Wed, May 28, 2014 at 4:14 PM, Mark Reynolds marey...@redhat.com mailto:marey...@redhat.com wrote: On 05/28/2014 04:06 PM, John Trump wrote: Haven't been able to come up with a solution yet

Re: [389-users] last login

2014-05-30 Thread Mark Reynolds
On 05/30/2014 10:29 AM, Elizabeth Jones wrote: I'm trying to figure out if 389 supports a way to track users last login. I found this page http://directory.fedoraproject.org/wiki/Account_Policy_Design#Logging Does anyone know of any other documentation on implementing this?

Re: [389-users] new to 389DS - have Q's

2014-07-15 Thread Mark Reynolds
On 07/15/2014 12:48 PM, Isabella Ghiurea wrote: Hi Gurus, I'm new to 389 DS reading the RH DS docbefore start implementing, have Q's trying tohave system with high performance cfg Q1: Bellow in black is from RH DS documentation, I was expecting just creating the indexes in GUI DS

Re: [389-users] Replication doubts

2014-08-04 Thread Mark Reynolds
On 08/04/2014 01:19 PM, Alberto Viana wrote: Hi, I want to enable a replication to a specific subtree on my directory, how do I proceed? For example: I have my root suffix dc=homolog,dc=rnp And just want do enable replication for ou=teste,dc=homolog,dc=rnp Is that possible? Not

Re: [389-users] Replication error after initializing consumer

2014-08-19 Thread Mark Reynolds
Shilen, A few things, you should not be adding a prehashed password (e.g. {SSHA}DMK4S6PK6+rKSLNOL1Hl01mVJmgGi5jH) - but that should not break replication. Can you confirm that only prehashed passwords are causing the issue? If so, please files a ticket with a reproducible testcase:

Re: [389-users] Replication error after initializing consumer

2014-08-19 Thread Mark Reynolds
! -- Shilen From: Mark Reynolds marey...@redhat.com mailto:marey...@redhat.com Reply-To: mreyno...@redhat.com mailto:mreyno...@redhat.com mreyno...@redhat.com mailto:mreyno...@redhat.com Date: Tuesday, August 19, 2014 2:58 PM To: General discussion list for the 389 Directory server project

Re: [389-users] secure replication failing

2014-08-20 Thread Mark Reynolds
On 08/20/2014 03:58 PM, Elizabeth Jones wrote: additional info - I increased logging on my supplier and see this error now - TLS: hostname does not match CN in peer certificate When I created the replication agreement, it is giving me a default consumer, I don't know why. The default is

Re: [389-users] secure replication failing

2014-08-25 Thread Mark Reynolds
On 08/25/2014 10:21 AM, Elizabeth Jones wrote: On 08/22/2014 10:34 AM, Elizabeth Jones wrote: On 08/20/2014 03:58 PM, Elizabeth Jones wrote: additional info - I increased logging on my supplier and see this error now - TLS: hostname does not match CN in peer certificate When I created the

[389-users] Announcing the revised port389.org wiki

2014-08-25 Thread Mark Reynolds
We are pleased to announce the launch of our new wiki http://www.port389.org The site has been significantly revised, and moved to a more stable environment. The layout, content, and organization has all been improved. Please note, you will need to revise any old bookmarks you may have, as the

Re: [389-users] [389-announce] Announcing the revised port389.org wiki

2014-08-27 Thread Mark Reynolds
, Thanks for the feedback! I'm not sure if this is available on the new site(run on OpenShift using ruby MarkDown), but I will look into it and get back to you. Thanks, Mark 2014-08-25 21:59 GMT+02:00 Mark Reynolds marey...@redhat.com mailto:marey...@redhat.com: We are pleased to announce

Re: [389-users] [389-announce] Announcing the revised port389.org wiki

2014-08-27 Thread Mark Reynolds
. All you need to do is create an account on http://openshift.com, send me your username(usually an email address) so I can grant you access, and then I will send out the rest of the instructions. Regards, Mark Thanks again for the good job! 2014-08-25 21:59 GMT+02:00 Mark Reynolds marey

Re: [389-users] Windows console download link

2014-09-02 Thread Mark Reynolds
On 08/30/2014 08:01 PM, Chase Miller wrote: Is broke HI Chase, Sorry about that, there was case issue with the link: http://www.port389.org/binaries/389-console-1.1.6-i386.msi http://www.port389.org/binaries/389-console-1.1.6-x86_64.msi should of been:

Re: [389-users] [389-announce] Announcing the revised port389.org wiki - What's New page added

2014-09-02 Thread Mark Reynolds
when the site changed and what new pages were added or modified. It allowed me to stay informed and in without clicking on all the links of the site. Is it possible to bring back that sort of feature? Thanks again for the good job! 2014-08-25 21:59 GMT+02:00 Mark Reynolds marey...@redhat.com

Re: [389-users] Upgrading DS 389 via RPM

2014-09-11 Thread Mark Reynolds
Hi Chris, You still need to run the 389 setup scripts afterwards, check out this link: http://www.port389.org/docs/389ds/download.html#directory-server-11-and-later Regards, Mark On 09/11/2014 02:15 PM, Chris Taylor wrote: I was actually going to use yum update so I am not sure if that

Re: [389-users] How to get password expiration working?

2014-09-19 Thread Mark Reynolds
On 09/19/2014 12:16 PM, Paul Tobias wrote: Hi guys, We need to implement password expiration because of some policy. The problem is users are not able to bind to ldap anymore, after I switch on password expiration for our ou=People subtree . The ldap command line tools and 389-console both

Re: [389-users] 389DS memeberof plugin not working

2014-10-01 Thread Mark Reynolds
On 10/01/2014 02:34 PM, Ghiurea, Isabella wrote: Hello 389 users, I'm having problems getting the memberof plugin work on 389-Directory/1.2.11.15 B2014.219.179. We are using groupofuniquenames groups. Here's the configuration of the memberof plugin: objectClass: extensibleObject

Re: [389-users] 389DS memeberof plugin not working

2014-10-01 Thread Mark Reynolds
*From:* Mark Reynolds [marey...@redhat.com] *Sent:* Wednesday, October 01, 2014 2:59 PM *To:* General discussion list for the 389 Directory server project.; Ghiurea, Isabella *Subject:* Re: [389-users] 389DS memeberof plugin not working On 10

Re: [389-users] Dse.ldif file modification issues

2014-11-04 Thread Mark Reynolds
Isabella, Sounds like the server was still running when you copied the file over. The server should be stopped when manually updating the dse.ldif. Regards, Mark On 11/03/2014 04:03 PM, Ghiurea, Isabella wrote: _ *From:*Ghiurea, Isabella

Re: [389-users] add user aci problem

2014-11-10 Thread Mark Reynolds
On 11/10/2014 12:22 PM, Alberto Viana wrote: 389-Directory/1.3.2.17 http://1.3.2.17 B2014.182.124 I'm trying to add an user (whitout using the manager, with a regular user): Without any aci: ldap_add: Insufficient access (50) additional info: Insufficient 'add' privilege to the

Re: [389-users] administrative limit exceed error

2014-11-19 Thread Mark Reynolds
On 11/19/2014 02:38 PM, ghiureai wrote: More details: I need for non directory manager to be able to count all the DS entries , I have cfg ldse.ldif sizelimit set to 50 but the non directory manager user gets error: Hi Isabella, It's the lookthroughlimit you want to adjust - it's

Re: [389-users] 389-ds and Multi CPU's

2014-12-08 Thread Mark Reynolds
On 12/08/2014 02:08 PM, Fong, Trevor wrote: Hi Everyone, We’ve inherited a 389-ds system (1.2.11.15-48.el6_6) that is running on a VM provisioned with a single CPU. We have been experiencing high CPU with a client that connects with a single connection, and then runs large amounts of

Re: [389-users] 389-ds and Multi CPU's

2014-12-09 Thread Mark Reynolds
. Thanks, Trev From: Mark Reynolds marey...@redhat.com mailto:marey...@redhat.com Reply-To: mreyno...@redhat.com mailto:mreyno...@redhat.com mreyno...@redhat.com mailto:mreyno...@redhat.com Date: Monday, December 8, 2014 at 11:29 AM To: 389-users@lists.fedoraproject.org mailto:389-users

Re: [389-users] 389-ds and Multi CPU's

2014-12-09 Thread Mark Reynolds
. The Directory Manager account should only be used under certain circumstances. Avoid using this account for client applications. Cleaning up temp files... Done. From: Mark Reynolds marey...@redhat.com mailto:marey...@redhat.com Reply-To: mreyno...@redhat.com mailto:mreyno...@redhat.com mreyno

Re: [389-users] DS crashed /killed by OS

2015-02-04 Thread Mark Reynolds
Looks like you ran out of memory on the system(possibly a Directory Server memory leak?) Was there anything in the Directory Server errors log? What version of 389 are you using? rpm -qa | grep 389-ds-base You should monitor the 389 process and see if it continues to grow day after day.

Re: [389-users] Ldif import issue

2015-01-15 Thread Mark Reynolds
On 01/15/2015 11:06 AM, Jean Félix DESIR wrote: Hi, I'am facing this import issue: I can't add this attribut to a object on my 389 DS: dn: cn=template,ou=services,ou=profiles,ou=Authent,dc=region,dc=enterprise,dc=net rbClientDnsPri: XXX *rbForwardPolicy: MYVALUE* rbContextName: PPP

Re: [389-users] Permanently Disable SSLv3

2015-01-20 Thread Mark Reynolds
John, FYI, I was able to reproduce this, and I opened this ticket: https://fedorahosted.org/389/ticket/47994 Regards, Mark On 01/05/2015 10:18 AM, John Trump wrote: 389-ds-base-1.2.11.25-1.el6.x86_64 idm-console-framework-1.1.7-2.el6.noarch 389-ds-console-1.2.6-1.el6.noarch On Wed, Dec

Re: [389-users] Recreating replica agreements

2015-01-14 Thread Mark Reynolds
On 01/14/2015 08:01 AM, carne_de_passaro wrote: Hello guys, I am planning to recreate my replica agreements, which today uses SSL on port 636, to use startTLS on port 389. My question is: Do I have to reinitialize the databases of the agreements that I recreate? Danilo, You should not

Re: [389-users] Issue with LDAP modify to change replication schedule

2015-01-30 Thread Mark Reynolds
On 01/30/2015 02:43 PM, Justin Edmands wrote: 389 List, I need to modify the replication schedule via LDIF import. I have no issues doing it in the 389-console. I am attempting to import this ldif (with dc changes to mask our info) dn: cn=dirsrv1 to

Re: [389-users] Questions on Version - 1.2.11.X

2015-01-26 Thread Mark Reynolds
Hi Jordan, See comments below... On 01/26/2015 03:08 PM, Jordan, Phillip wrote: First late me state that I have been tasked to fix and upgrade the directory due to recent issues. I have vast experience in most other directories but not in 389 Directory space. So I have a few questions

Re: [389-users] Crash 389ds

2015-01-07 Thread Mark Reynolds
Andrey, This just isn't enough information to diagnose. Do you have a core file? If not, please enable core files: http://www.port389.org/docs/389ds/FAQ/faq.html#sts=Debugging%C2%A0Crashes Hopefully you can catch it again and get a core, and then we can work on it. Regards, Mark On

Re: [389-users] Referential Integrity

2015-03-18 Thread Mark Reynolds
On 03/17/2015 06:11 PM, William wrote: So in the case of having RI on two ldap servers, you would set this to off, since the server that handled the delete will replicate the other updates soon after. In the case of RI on a single server, when the non-RI server issues a delete, the RI enabled

Re: [389-users] Referential Integrity

2015-03-16 Thread Mark Reynolds
On 03/15/2015 07:14 PM, William wrote: Anyway, I think I'd need to look at the internals of the plugin at this point to work out for sure what's going on. Looks like someone already did this. nsslapd-pluginAllowReplUpdates It looks like there is no documentation about how this config

Re: [389-users] Referential Integrity

2015-03-17 Thread Mark Reynolds
On 03/16/2015 06:50 PM, William wrote: nsslapd-pluginAllowReplUpdates It looks like there is no documentation about how this config value works though: and the values it influences aren't widely through the code so I can't confirm if it's a finished feature. It is finished, and I will write

Re: [389-users] GUI console and Kerberos

2015-03-13 Thread Mark Reynolds
On 03/11/2015 05:48 PM, prmari...@gmail.com wrote: Update I got pulled away on something else but there is progress. I tried the Apache Kerberos ‎5 auth module initial auth worked but then it went back to LDAP error 32 because it looks like it passed username@realm to the ldap server as the

Re: [389-users] db2bak on a provider/master

2015-02-26 Thread Mark Reynolds
On 02/26/2015 08:30 AM, Mitja Mihelič wrote: Hi! We have a provider/consumer (master/slave) setup and we wish to create a database backup on the master. Replica setting on the master are set to Single Master. But when I run .../db2bak $backup_path/$current_date Backup fails an the following

Re: [389-users] authenticated time stamp

2015-05-08 Thread Mark Reynolds
On 05/08/2015 09:51 AM, Chase Miller wrote: Hello 389 Group, Is there an object class/attribute that I can add to a user's entry that will capture their last authenticated time stamp. I want to capture this so I can go delete users that have not authenticated after so many days. Chase,

Re: [389-users] Migrating from openldap/slapd to 389

2015-05-14 Thread Mark Reynolds
Hi Bobby, See comments below... On 05/14/2015 09:24 AM, Bobby Krupczak wrote: Hi! Hey, I'm sure you guys are tired of folks asking this question but I've spent the last day searching the InterWebs and still have questions. I'm fixing to switch from openldap/slapd to 389 for ldap

Re: [389-users] Retrieve list of groups that a user belongs to

2015-04-06 Thread Mark Reynolds
On 04/06/2015 10:28 AM, harry.dev...@faa.gov wrote: I know this is slightly off topic, but I thought that maybe someone on this list could be of some assistance. I need to get the list of groups that a particular user belongs to, similar to the linux command line program ‘groups’. I

Re: [389-users] Limit on number of databases per directory server instance

2015-05-19 Thread Mark Reynolds
is the resources available on the system (disk space, CPU, memory) *From:*389-users-boun...@lists.fedoraproject.org [mailto:389-users-boun...@lists.fedoraproject.org] *On Behalf Of *Mark Reynolds *Sent:* Tuesday, May 19, 2015 2:31 PM *To:* General discussion list for the 389 Directory server project

Re: [389-users] Python3 support - question

2015-06-25 Thread Mark Reynolds
Hi Robert, Which version of Fedora is going to start being python3 only? Thanks, Mark On 06/24/2015 08:05 AM, Robert Kuska wrote: Hello everyone, I am Robert Kuska, I am a python co-maintainer and co-owner of change Python3 as default which aims to provide python3 only packages by default

Re: [389-users] Not able to enable audit logs

2015-06-15 Thread Mark Reynolds
On 06/15/2015 05:23 AM, Prashant Bapat wrote: There is no error. It goes thru fine. When I restart the LDAP server after adding it, there is nothing in the audit file. And no entry in the dse.ldif. Are you directly modifying the dse.ldif? If so, you MUST do so while the server is stopped,

Re: [389-users] Limit on number of databases per directory server instance

2015-05-19 Thread Mark Reynolds
On 05/19/2015 02:25 PM, Colin Tulloch wrote: Hi all – Is there a limit to the number of databases that can be present on an instance of directory server – or on a server/VM itself? Some colleagues of mine seem to believe there is a limit of 10 DBs per server. I haven’t seen this in the

Re: [389-users] How to modify the logging dir

2015-08-20 Thread Mark Reynolds
On 08/20/2015 10:20 AM, bahan w wrote: Hm ok. Ok, and to do that I use the ldapmodify command ? Something like : ldapmodify -x -D cn=Directory Manager -w mdp password manager -h FQDN hosting server -p 389 dn:cn=config changetype:modify replace:nsslapd-accesslog nsslapd-accesslog:MYPATH

Re: [389-users] MemberOf plugin beahvior change in 1.3.3.

2015-08-04 Thread Mark Reynolds
On 08/04/2015 07:50 AM, Andrey Ivanov wrote: Looks like the behavior change was introduced in this ticket: https://fedorahosted.org/389/ticket/47810 Yes, with the introduction of backend transaction plugins in 1.3.3, if a plugin fails to do its job, the entire operation should fail. This

Re: [389-users] MemberOf plugin beahvior change in 1.3.3.

2015-08-04 Thread Mark Reynolds
Hi Andrey, On 08/04/2015 10:33 AM, Andrey Ivanov wrote: Hi Mark, thank you for your rapid reply, 2015-08-04 16:14 GMT+02:00 Mark Reynolds marey...@redhat.com mailto:marey...@redhat.com: Looks like the behavior change was introduced in this ticket: https://fedorahosted.org/389

Re: [389-users] access log error : Resource temporarily unavailable

2015-07-31 Thread Mark Reynolds
On 07/31/2015 12:42 PM, ghiureai wrote: Hi lIst. we are getting the following in access files, would like to know wher eto look for clues , what means Resource temporarily unavailable ? op=1 RESULT err=0 tag=101 nentries=5514 etime=14 notes=U [31/Jul/2015:09:37:21 -0700] conn=143371

Re: [389-users] 389-DS poor performance retrieving groups

2015-08-05 Thread Mark Reynolds
On 08/05/2015 06:19 AM, Ludwig Krispenz wrote: On 08/04/2015 08:32 PM, Mark Reynolds wrote: On 08/04/2015 12:53 PM, German Parente wrote: - Original Message - From: Mark Reynolds marey...@redhat.com To: General discussion list for the 389 Directory server project. 389-users

Re: [389-users] 389-DS poor performance retrieving groups

2015-08-05 Thread Mark Reynolds
On 08/04/2015 11:57 AM, ghiureai wrote: https://www.flowdock.com/app/canfar/access-control/threads/QyygOboGumgx3qw3tIO_828AMgQ We are seeing poor performance from LDAP retrieving 2500-4500 entries compare with one of our regular RDBMS , here is bellow the result for a ldapsearch. We are

Re: [389-users] 389-DS poor performance retrieving groups

2015-08-05 Thread Mark Reynolds
On 08/05/2015 08:24 AM, Mark Reynolds wrote: On 08/04/2015 11:57 AM, ghiureai wrote: https://www.flowdock.com/app/canfar/access-control/threads/QyygOboGumgx3qw3tIO_828AMgQ We are seeing poor performance from LDAP retrieving 2500-4500 entries compare with one of our regular RDBMS , here

Re: [389-users] 389-DS poor performance retrieving groups

2015-08-05 Thread Mark Reynolds
surrounding wildcards then you must use 3 characters: cn=*abc* Regards, Mark Thank you [389-users] 389-DS poor performance retrieving groups On 08/05/2015 08:24 AM, Mark Reynolds wrote: / // // On 08/04/2015 11:57 AM, ghiureai wrote: // https://www.flowdock.com/app/canfar/access-control

Re: [389-users] Admin Server. How to turn off access control by host/domain name?

2015-08-11 Thread Mark Reynolds
On 08/11/2015 10:14 AM, Aleksey Chudov wrote: Hi, I'm configuring 389 DS on CentOS 7 using some packages from epel-testing # rpm -qa | grep 389 | sort 389-admin-1.1.42-1.el7.x86_64 389-admin-console-1.1.10-1.el7.noarch 389-admin-console-doc-1.1.10-1.el7.noarch

Re: [389-users] 389-DS poor performance retrieving groups

2015-08-04 Thread Mark Reynolds
On 08/04/2015 12:53 PM, German Parente wrote: - Original Message - From: Mark Reynolds marey...@redhat.com To: General discussion list for the 389 Directory server project. 389-users@lists.fedoraproject.org Sent: Tuesday, August 4, 2015 6:04:17 PM Subject: Re: [389-users] 389-DS

Re: [389-users] 389-DS poor performance retrieving groups

2015-08-04 Thread Mark Reynolds
On 08/04/2015 11:57 AM, ghiureai wrote: https://www.flowdock.com/app/canfar/access-control/threads/QyygOboGumgx3qw3tIO_828AMgQ We are seeing poor performance from LDAP retrieving 2500-4500 entries compare with one of our regular RDBMS , here is bellow the result for a ldapsearch. We are

Re: [389-users] updating/removing user indexes Q

2015-10-21 Thread Mark Reynolds
On 10/21/2015 01:33 PM, ghiureai wrote: Gmorning Mark the indexes had been removed at developers request to improve performance , now I reboot the DS and the indexes come up online. Maybe there was a misunderstanding. I'm sure a developer did not recommend you remove the default system

Re: [389-users] making a dedicated consumer a supplier

2015-11-12 Thread Mark Reynolds
On 11/12/2015 02:09 PM, ghiureai wrote: Gmorning Mark, Thank you again for fast reply, do I stilll need to create a rep agreement ? Yes, if you want to replicate changes to another server. This was also the last step in my previous reply. Here's how to do it through the command line:

Re: [389-users] ACIs caching issue

2015-11-16 Thread Mark Reynolds
On 11/16/2015 12:30 PM, Adrian Damian wrote: Hello 389 Gurus, This is a very subtle issue that we are seeing on our LDAP server. Sometimes, the ACIs return different results for the same search executed from different clients (a Java client vs. a Python or the ldapsearch client). More

Re: [389-users] ACIs caching issue

2015-11-16 Thread Mark Reynolds
group read", acidn="ou=admingroups,ou=abc" ... [16/Nov/2015:10:41:43 -0800] NSACLPlugin - STAR Access allowed on attr:uniqueMember; entry:cn=jcmt-mjlsg14b,ou=admingroups,ou=abc [16/Nov/2015:10:41:43 -0800] NSACLPlugin - conn=57465 op=52 (on attr): Allow read on entry(cn=jcmt-mjlsg1

Re: [389-users] ACIs caching issue

2015-11-16 Thread Mark Reynolds
the client to list larger number of entries and it works fine. Or is there a different configurable size limit? What should I look for? Thanks, Adrian On 11/16/2015 12:23 PM, Mark Reynolds wrote: On 11/16/2015 01:58 PM, Adrian Damian wrote: Hi Mark, Thanks for the quick reply. I don't exactl

Re: [389-users] making a dedicated consumer a supplier

2015-11-12 Thread Mark Reynolds
On 11/12/2015 12:31 PM, ghiureai wrote: Hi List , I'm looking for cmd line steps to make a dedicated consumer in a supplier in single master replication ( if original master goes offline), I have the steps from Admin GUI , I would like to hase same steps but using cmd's line : - add

  1   2   3   4   5   6   7   8   9   >