Re: [389-users] question syncing with AD

2011-06-27 Thread Rich Megginson
On 06/27/2011 02:28 PM, Mi Zhou wrote: Does container entries got synced as well? Say, if a new OU was created on AD, will that be synced on 389? During the initial sync init phase - yes. During the incremental phase - no. Can we initiate a full resync to get this done, or it must be

Re: [389-users] Problem - Could not import LDIF file '/ tmp / ldifESlBSW.ldif'. Error: 65280

2011-07-25 Thread Rich Megginson
On 07/21/2011 04:04 PM, Michel Bulgado wrote: Hello Recently I just installed 389-ds-1.2.1-1.el5.noarch from EPEL repo, because in my company we use Active Directory and want to migrate to Linux What version of 389-ds-base? rpm -qi 389-ds-base FYI, 389 is not a drop in replacement for Active

Re: [389-users] Centos 6?

2011-08-01 Thread Rich Megginson
On 07/29/2011 03:49 PM, Brett Dikeman wrote: On Fri, Jul 29, 2011 at 12:02 PM, Leo Pleimanlplei...@salsalabs.com wrote: Rumor has it there has been a mass exodus from Centos and the ports may be a little behind. You might want to look at Scientific Linux. I just tried SL 6.1. I did a 'basic

Re: [389-users] Centos 6?

2011-08-01 Thread Rich Megginson
On 08/01/2011 07:54 PM, Penedo wrote: On 2 August 2011 09:17, Rich Megginsonrmegg...@redhat.com wrote: So, to summarize, if you want the full 389 ds/admin/console on EL6: 1) you must use EL 6.1 or later 2) you must use 389-ds-base from the fedorapeople.org repo 3) you must use EPEL6 for the

Re: [389-users] Centos 6?

2011-08-02 Thread Rich Megginson
On 08/01/2011 09:41 PM, Penedo wrote: On 2 August 2011 12:42, Rich Megginsonrmegg...@redhat.com wrote: On 08/01/2011 07:54 PM, Penedo wrote: Does the requirement for a payment for the replication feature mean that I should start looking elsewhere for my LDAP needs, if I want to stick to FOSS

Re: [389-users] Centos 6?

2011-08-03 Thread Rich Megginson
On 08/03/2011 02:30 PM, Brett Dikeman wrote: On Mon, Aug 1, 2011 at 7:17 PM, Rich Megginsonrmegg...@redhat.com wrote: Fixed. Fixed. Amazingly, finally, it all seems to have installed. EL6 support is . . . tricky. Rich, thank you for straightening this out so quickly, and the clearest

Re: [389-users] autoenrollment proxy and dogtag 9 ? Where can I find AEP source code ?

2011-08-03 Thread Rich Megginson
On 07/27/2011 04:55 AM, Alexander Jung wrote: Hi, 2011/7/25 Rich Megginsonrmegg...@redhat.com: On 07/20/2011 07:41 AM, Alexander Jung wrote: Hello, I try to use the autoenrollment proxy with the most recent dogtag. Unfourtunately it seems that its been a while since somebody touched that

Re: [389-users] Centos 6?

2011-08-08 Thread Rich Megginson
Hagopian On Tue, Aug 2, 2011 at 9:04 AM, Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com wrote: On 08/01/2011 09:41 PM, Penedo wrote: On 2 August 2011 12:42, Rich Megginsonrmegg...@redhat.com mailto:rmegg...@redhat.com wrote: On 08/01/2011 07:54 PM, Penedo wrote

Re: [389-users] Crashing

2011-08-08 Thread Rich Megginson
On 08/08/2011 02:51 PM, Wendt, Trevor wrote: **resending with message truncated, hit message size max** Hello Rich, Still fails when run from within the server directory: No, it actually worked - see below == [root@

[389-users] Announcing 389 Directory Server version 1.2.9.6 Testing

2011-08-16 Thread Rich Megginson
The 389 Project team is pleased to announce the release of 389-ds-base-1.2.9.6. This release has fixes for bugs found in 1.2.9 testing and bugs from earlier releases. NEW: EL6 support Beginning with RHEL 6.1, the 389-ds-base package is included in the base OS. It is the same as the

Re: [389-users] Announcing 389 Directory Server version 1.2.9.6 Testing

2011-08-16 Thread Rich Megginson
On 08/16/2011 02:23 PM, Anthony Messina wrote: On 08/16/2011 02:04 PM, Rich Megginson wrote: The 389 Project team is pleased to announce the release of 389-ds-base-1.2.9.6. This release has fixes for bugs found in 1.2.9 testing and bugs from earlier releases. Just a warning, I had trouble

Re: [389-users] Announcing 389 Directory Server version 1.2.9.6 Testing

2011-08-22 Thread Rich Megginson
On 08/22/2011 04:55 PM, Anthony Messina wrote: On 08/22/2011 05:40 PM, Rich Megginson wrote: I'm using the latest code on RHEL 6.1 x86_64. This is what I did: setup-ds.pl - use suffix dc=example,dc=com after the server starts, use ldapmodify: dn: dc=example,dc=com changetype: modify

Re: [389-users] Failure while Copy a subtree (deleteOldRdn: 0)

2011-08-23 Thread Rich Megginson
On 08/23/2011 07:22 AM, Roberto Polli wrote: Hi all, I'm playing with the changeType: modrdn command, and I got the following issue. 1- I want to copy a subtree in another location: source: ou=People,dc=top dest: ou=PeopleBak,dc=top 2- I can move it with changeType: modrdn newrdn:

Re: [389-users] Announcing 389 Directory Server version 1.2.9.6 Testing

2011-08-23 Thread Rich Megginson
On 08/22/2011 11:00 PM, Anthony Messina wrote: On 08/22/2011 06:37 PM, Rich Megginson wrote: Ok. I'll just keep trying. Does it matter who you do the search as? That is, do you use directory manager, anonymous, or a regular user? Most of the queries were run anonymously (internal to the LAN

Re: [389-users] fedora-idm-console is not working after ssl enabled

2011-08-24 Thread Rich Megginson
On 08/24/2011 12:26 AM, s.varadha rajan wrote: Hi, Thanks for the reply for you and team. yesterday i fixed that issue.my system is having already jss4 installed and the problem is related to path.i created libjss4.so link in my lib path, i.e /usr/lib as like, root@varad:/usr/lib# ls -l

Re: [389-users] fedora-idm-console is not working after ssl enabled

2011-08-24 Thread Rich Megginson
On 08/24/2011 08:26 AM, u...@3.am wrote: The web interface provided by 389-admin doesn't do very much. You might want to use 389-dsgw. Does anybody know if the DSGW interface is available for CentOS Directory Server? The RHDS docs mention it, but the only file that appears on the server

Re: [389-users] Microsoft Windows Password Sync?

2011-08-25 Thread Rich Megginson
On 08/24/2011 11:55 PM, Craig T wrote: Hi, Setup: Fedora 15 x64 * 389-admin-1.1.16-1.fc15.x86_64 * 389-admin-console-1.1.7-2.fc15.noarch * 389-admin-console-doc-1.1.7-2.fc15.noarch * 389-adminutil-1.1.13-2.fc15.x86_64 * 389-console-1.1.4-2.fc15.noarch * 389-ds-base-1.2.8.3-1.fc15.x86_64

Re: [389-users] Setting up multi master replication error 81

2011-08-31 Thread Rich Megginson
B2011.122.1636 dataversion: 020110830132535020110830132535 netscapemdsuffix: cn=ldap://dc=xxx,dc=stag,dc=cle,dc=us:389 I see what you are trying here, but still seems to be passing *From:*Rich Megginson [mailto:rmegg...@redhat.com] *Sent:* Wednesday, August 31, 2011 3:42 PM *To:* General discussion list

Re: [389-users] Failed to install a local copy of 389-ds-1.2.6.jar

2011-09-01 Thread Rich Megginson
On 09/01/2011 03:31 AM, Jim Hilton wrote: Hi, When I open the Directory Server console on a fresh install of 389-ds I get the following message: Failed to install a local copy of 389-ds-1.2.6.jar or one of its supporting files I have installed 389-ds via yum on a fresh Fedora 15 server

Re: [389-users] Fwd: 389 v1.2.9.8 freeze/deadlock

2011-09-01 Thread Rich Megginson
On 09/01/2011 08:08 AM, Andrey Ivanov wrote: Hi, i've tried to install the 1.2.9.8 testing version in our production environment but there is a regular freeze/deadlock after a particular search. It is a search sent by outlook 2003 (you type the name of the person and then click Check the

Re: [389-users] adding schema to 389ds

2011-09-14 Thread Rich Megginson
On 09/14/2011 07:19 AM, Karoly Czovek wrote: Hi guys, I'm just trying to extend 389ds schemes with this schema: http://proyectofedora.org/wiki/Fedora_Directory_Server_99zimbra.ldif but i get the following errors, any easy workaround/fix about? Notice the error message:

Re: [389-users] problem with admin client

2011-09-14 Thread Rich Megginson
On 09/14/2011 09:09 AM, Ellsworth, Josh wrote: A colleague set up 389DS and used the IP address as the hostname during the setup. I am having trouble connecting to the admin server using the windows client. The error message I received is as follows: Cannot connect to the Admin Server

Re: [389-users] RH5 upgrade Problem Directoryserver

2011-09-14 Thread Rich Megginson
On 09/14/2011 12:00 PM, Robert Viduya wrote: I'm having issues with this as well, but I'm trying to do a clean install, not an upgrade. I pulled down 389-dsgw-1.1.7-2.el5.x86_64.rpm as suggested, but it's failing to install with dependency errors as well: # yum localinstall

Re: [389-users] RH5 upgrade Problem Directoryserver

2011-09-15 Thread Rich Megginson
On 09/15/2011 07:24 AM, Enrico M. V. Fasanelli wrote: On 15 Sep 2011, at 15:12, Rich Megginson wrote: [root@dsa ~]# yum clean all Loaded plugins: kernel-module Cleaning up Everything then yum install 389-adminutil # this should install 1.1.14 which provides libadminutil.so.0

Re: [389-users] Certificate based Authentication

2011-09-15 Thread Rich Megginson
On 09/15/2011 04:37 PM, David Partridge wrote: Attempting to configure Certificate based authentication with SASL External such that if TLS successfully completed the user is authenticated by certificate DN as an authenticated user without the requirement for the corresponding DN to be present

Re: [389-users] can't install 389-ds-base 1.2.9.9 on RHEL 6.1

2011-09-15 Thread Rich Megginson
On 09/15/2011 05:43 PM, Thang Nguyen wrote: I can't seem to install 389-ds-base 1.2.9.9 on RHEL6.1 using yum. I follow the instructions from http://directory.fedoraproject.org/wiki/Download by 1. Download and copy epel-389-ds-base.repo to /etc/yum.reposd 2. rpm -Uvh

Re: [389-users] fixed epel-6 repo

2011-09-16 Thread Rich Megginson
On 09/16/2011 08:32 AM, Andrea Modesto Rossi wrote: On Ven, 16 Settembre 2011 4:19 pm, Rich Megginson wrote: The EPEL-6 repo has been fixed. You can now install 389-ds-base-1.2.9.9 via yum. See http://directory.fedoraproject.org/wiki/Download for more information. -- 389 users mailing list

Re: [389-users] ad nested objects sync

2011-09-16 Thread Rich Megginson
On 09/16/2011 08:55 AM, Vasil Mikhalenya wrote: hi all, can windows sync agreement replicate nested objects ? like cn=user1,ou=location1,ou=Root,dc=domain ? when i specify ou=Root,dc=domain in sync agreement - it replicates only objects under ou=Root,dc=domain itself like

Re: [389-users] migrating from openLDAP

2011-09-20 Thread Rich Megginson
On 09/20/2011 05:30 PM, Ellsworth, Josh wrote: We are working on consolidating our diverse LDAP systems onto 389DS, but we are having some trouble with openLDAP. The designers of a particular software package are using a custom openLDAP schema and we aren't sure how to get it into 389. When we

Re: [389-users] 389-adminutil package dependency issues fresh install

2011-09-22 Thread Rich Megginson
On 09/22/2011 11:58 AM, Aaron Oas wrote: I recently spent hours resolving a packaging issue when trying to install 389-ds 1.2.9.9, and thought I would share my finding, which is that the recent 389-adminutil-1.1.14 package version seems to have gone backwards in the library versions it

Re: [389-users] passsync - ldap error in queryusername

2011-09-29 Thread Rich Megginson
On 09/29/2011 01:59 PM, Aaron Hagopian wrote: Recently this message started to show up on our windows domain controller in the passsync log file: ... 09/29/11 14:38:50: Ldap error in QueryUsername 1: Operations error 09/29/11 14:39:54: Ldap error in QueryUsername 1: Operations error 09/29/11

Re: [389-users] Best way to sync ldap and samba passwords

2011-10-05 Thread Rich Megginson
On 10/05/2011 01:07 PM, David Hoskinson wrote: I am trying to find out the best way to change my password using ldappaswd... and have it also update my samba passwd. Plain old 389 can't do that, but freeipa can. From what I am understanding the ldap sync option in samba will do that, but

Re: [389-users] Some problems after Server upgrade

2011-10-07 Thread Rich Megginson
On 10/07/2011 09:03 AM, Andrea Modesto Rossi wrote: On Ven, 7 Ottobre 2011 4:11 pm, Andrea Modesto Rossi wrote: Hi, i have updated my VirtualMachine with 389 from centos5.6 to centos5.7. Now i'm not able to start 389-console, indeed i have an error: [root@deimos ~]# 389-console -bash:

Re: [389-users] Some problems after Server upgrade

2011-10-07 Thread Rich Megginson
On 10/07/2011 04:23 PM, Rich Megginson wrote: On 10/07/2011 04:21 PM, Orion Poplawski wrote: On 10/07/2011 04:05 PM, Rich Megginson wrote: On 10/07/2011 12:34 PM, Orion Poplawski wrote: I forgot I ran into this too: # rpm -vql 389-console -rw-r--r-- 1 root root 323 Jun 15 15:49 /etc/java

Re: [389-users] 389 pauses every 5 minutes under load

2011-10-10 Thread Rich Megginson
On 10/07/2011 11:56 AM, Justin Gronfur wrote: Hello all, I need your expertise... please help me! (Disclaimer: I am a relative newcomer to 389ds) I'm running a Java application that keeps user authentication, permissions, and preferences in ldap. And I'm currently load testing this

Re: [389-users] Replication issue

2011-10-12 Thread Rich Megginson
*From:* Rich Megginson [mailto:rmegg...@redhat.com] *Sent:* Wednesday, October 12, 2011 4:11 PM *To:* Reinhard Nappert *Cc:* General discussion list for the 389 Directory server project.; Marc Sauton *Subject:* Re: [389

Re: [389-users] Configure access log

2011-10-14 Thread Rich Megginson
On 10/14/2011 02:22 AM, Moisés Barba Pérez wrote: /HI, I'm doing a backup for mi access logs in several ldap servers and I have found that some of this logs have been deleted because of rotation info. The thing is, I want to save all the access log generated in a day in files of 100MB. I

Re: [389-users] GUI console fails to show up after upgrade

2011-10-14 Thread Rich Megginson
Harry Harry Devine Common ARTS Software Development AJT-144 (609)485-4218 harry.dev...@faa.gov From: Rich Megginson rmegg...@redhat.com To: Harry Devine/ACT/FAA@FAA Cc: General discussion list for the 389 Directory server project. 389-users@lists.fedoraproject.org, Ted Rush/ACT/FAA@FAA

Re: [389-users] SSL Question

2011-10-19 Thread Rich Megginson
On 10/19/2011 06:59 AM, Chris Cawley wrote: When I look in the console/manage cert/etc. See http://directory.fedoraproject.org/wiki/Howto:SSL#Viewing_the_list_of_built-in_CA_certs -Chris *From:*389-users-boun...@lists.fedoraproject.org [mailto:389-users-boun...@lists.fedoraproject.org]

Re: [389-users] help with 'no such attribute' error?

2011-11-02 Thread Rich Megginson
On 11/02/2011 03:49 PM, brandon wrote: So I'm hoping somebody can assist with a confusing problem I am having. I am running 389-ds-1.2.1-1. What platform? What version of 389-ds-base? I have nodes in a subtree where I am unable to modify the userPassword attribute through perl-LDAP, but I

Re: [389-users] replication issues with promoting hub to master

2011-11-08 Thread Rich Megginson
:*389-users-boun...@lists.fedoraproject.org [mailto:389-users-boun...@lists.fedoraproject.org] *On Behalf Of *Rich Megginson *Sent:* Tuesday, November 08, 2011 7:29 AM *To:* SHAW-MILLER, JOHN (Synetrix) *Cc:* General discussion list for the 389 Directory server project. *Subject:* Re: [389-users

Re: [389-users] Unable to Manage Registered Servers from Console

2011-11-10 Thread Rich Megginson
On 11/10/2011 11:48 AM, Tom Tucker wrote: I would appreciate any troubleshooting advise you might have regarding my registered ldap servers. I am referring to the first page you see when launching the console (servers listed underneath Servers and Applications). I see my servers listed,

Re: [389-users] Unable to Manage Registered Servers from Console

2011-11-10 Thread Rich Megginson
. On Thu, Nov 10, 2011 at 1:48 PM, Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com wrote: On 11/10/2011 11:48 AM, Tom Tucker wrote: I would appreciate any troubleshooting advise you might have regarding my registered ldap servers. I am referring to the first page you

Re: [389-users] Restricting access to replication manager DN

2011-11-14 Thread Rich Megginson
On 11/14/2011 05:00 PM, Iain Morgan wrote: Hello, I think I already know the answer to this question, but I'd like to make sure. I would like to restrict which source IP addresses may bind to a replication manager DN on a consumer. As far as I can see, there is no way to to this . Is that

Re: [389-users] Several issues with 389 DS

2011-11-15 Thread Rich Megginson
On 11/15/2011 11:46 AM, Ellsworth, Josh wrote: We are working on transitioning from Sun Directory Server 7 (SDSEE) to 389DS and are having trouble in one of our environments. We have had success in 2 environments simply exporting the directory from SDSEE, importing it into 389, and then

Re: [389-users] Multiple threads simultaneously working on connection's private buffer causes ns-slapd to abort

2011-11-19 Thread Rich Megginson
2214 2215 2216 } /* while (1) */ 2217 } Thanks regards, Rushendra From: Rich Megginson [rmegg...@redhat.com] Sent: Friday, November 18, 2011 11:34 PM To: Reddy, Gandikota Rushendra (ESN) Cc: 389-users

Re: [389-users] Sync OU from Active Directory

2011-12-05 Thread Rich Megginson
On 12/05/2011 06:07 AM, Walter Neu wrote: Hi, is it possible to sync a complete LDAP tree from an Active Directory or only user and group entries? No. My problem is, that I have to build the complete tree from our AD server on my 389ds to sync the user entries, because OUs are not synced.

Re: [389-users] console issues

2011-12-15 Thread Rich Megginson
On 12/15/2011 10:46 AM, Ellsworth, Josh wrote: I am working on deploying 389 in my organization but I'm having an issue with the Windows console. After I log in, the console looks like the screenshot here: http://imgur.com/W1hVd When I click on the Directory Server tree it changes to say

Re: [389-users] Getting Started with the console

2011-12-19 Thread Rich Megginson
On 12/19/2011 03:56 PM, Stephen More wrote: I have looked through the documentation and have found references to install package 389-admin so that I can run setup-ds-admin.pl and 389-console. But I can only find the 389-ds-base package in the documented repo on:

Re: [389-users] Replication trouble when promoting dedicated Consumer to Multiple master [SOLVED]

2011-12-19 Thread Rich Megginson
On 07/15/2011 06:00 AM, Roland Schwingel wrote: Hi. Finally I got it I don't know whether I did it the fully correct way, but it works now. I found that this mysterious replica id 3 was stored in dse.ldif of my server-b: To recap my scenario: server A - server B

Re: [389-users] bak2db restore got stuck in infinite loop

2012-01-03 Thread Rich Megginson
On 01/03/2012 03:50 PM, Groten, Ryan wrote: *From:*Rich Megginson [mailto:rmegg...@redhat.com] *Sent:* Tuesday, January 03, 2012 3:42 PM *To:* General discussion list for the 389 Directory server project. *Cc:* Groten, Ryan *Subject:* Re: [389-users] bak2db restore got stuck in infinite loop

[389-users] Announcing 389 bugzilla is moving to 389 trac

2012-01-04 Thread Rich Megginson
The 389 team will be switching to trac for keeping track of bugs/enhancement requests/issues instead of Red Hat Bugzilla. * Why? We needed a clear separation between upstream 389 development and downstream Red Hat product/process. It was getting too confusing using bugzilla for both

Re: [389-users] Wiki/FireFox 9.0 problem

2012-01-04 Thread Rich Megginson
On 01/04/2012 02:13 AM, Andrey Ivanov wrote: After some research apparently it was fixed in MediaWiki 1.16 released 2010-07-28 (https://bugzilla.wikimedia.org/show_bug.cgi?id=31807) Thanks Andrey. We are working on it. 2012/1/4 Andrey Ivanov andrey.iva...@polytechnique.fr

Re: [389-users] TLS handshake failure

2012-01-09 Thread Rich Megginson
On 01/09/2012 04:11 PM, Iain Morgan wrote: On Mon, Jan 09, 2012 at 16:59:33 -0600, Rich Megginson wrote: On 01/09/2012 03:59 PM, Iain Morgan wrote: The error log does not report any issues. It indicates that ns-slapd is listening on both port 389 and 636. and it does not indicate any errors

Re: [389-users] el6 testing repository out of date

2012-01-18 Thread Rich Megginson
On 01/18/2012 03:21 PM, Orion Poplawski wrote: I'm seeing 389-ds-base 1.2.10-0.6.a6.el5 in epel testing, but only 389-ds-base-1.2.9-0.2.a2.el6 in epel-testing-389-ds-base. Is this repo still active? Updated - try it now -- 389 users mailing list 389-users@lists.fedoraproject.org

Re: [389-users] dirsrv-admin stat not working

2012-01-20 Thread Rich Megginson
On 01/20/2012 09:16 AM, Dan Whitmire wrote: I am having a terrible time attempting to get dirsrv-admin working on Fedora 15. Can someone please help me? I have selinux in permissive mode. I have tried all that I know to do, so any advice is welcome. I get the following: # service

Re: [389-users] 389 DS on RHEL 6.2 - invalid pointer.

2012-01-26 Thread Rich Megginson
On 01/20/2012 10:25 AM, Dan H. Eicher wrote: Anyone have any suggestions? CentOS 6? RHEL 6? Are you fully upgraded to 6.2? Do you have a core file? If you have abrt installed, find /var/spool/abrt -name corefile find /var/spool/abrt -name coredump rpm -qa | grep 389

Re: [389-users] Problems with Database Import.

2012-01-26 Thread Rich Megginson
the normal behavior, or should a bug report be filled? slapd is dying or crashing? That is not normal. Thanks for the help, Dan On 01/24/2012 03:21 PM, Rich Megginson wrote: On 01/24/2012 12:25 PM, Dan H. Eicher wrote: Hi, I will answer publicly so others might get some benefit, but first

Re: [389-users] Dir Admin Shows Stopped

2012-01-30 Thread Rich Megginson
On 01/30/2012 03:23 PM, Dan Whitmire wrote: When I bring up the 389-console it shows that the Administration Server as being down. When I do 'service dirsrv-admin status' it shows as running. I recently installed PKI CA, RA, TPS, and TKS. I'm experiencing problems with TKS which I believe

Re: [389-users] Directory Server Error‏

2012-02-01 Thread Rich Megginson
On 02/01/2012 12:40 AM, Gokser GUL wrote: Hello All, I m using Directory server and had a problem while configuring single master replication. I m trying to implement a directory server architecture for a future project and I m trying to implement a single master replication environment.

Re: [389-users] Lost Directory Manager user

2012-02-01 Thread Rich Megginson
On 02/01/2012 07:15 AM, Marco Pizzoli wrote: Hi, I'm putting hands to a 389-ds deploy not installed by me and I'm trying to find out what the Directory Manager entry is. It is not cn=Directory Manager. They chose to change it, and now nobody knows/remember what it is. Can I discover this in

Re: [389-users] Dir Admin Shows Stopped

2012-02-02 Thread Rich Megginson
On 02/02/2012 06:16 PM, Dan Whitmire wrote: On 01/30/2012 04:35 PM, Rich Megginson wrote: On 01/30/2012 03:23 PM, Dan Whitmire wrote: When I bring up the 389-console it shows that the Administration Server as being down. When I do 'service dirsrv-admin status' it shows as running. I

Re: [389-users] admserv_host_ip_check: ap_get_remote_host could not resolve

2012-02-08 Thread Rich Megginson
making this change? Brett *From:*Rich Megginson [mailto:rmegg...@redhat.com] *Sent:* 08 February 2012 00:57 *To:* MATON Brett *Cc:* General discussion list for the 389 Directory server project. *Subject:* Re: [389-users] admserv_host_ip_check: ap_get_remote_host could not resolve On 02/07/2012 03

Re: [389-users] dirsrv-admin with existing (remote) configuration server using SSL

2012-02-08 Thread Rich Megginson
On 02/08/2012 07:20 AM, MATON Brett wrote: Installation appears to go fine until it tries to start the admin server: Configuration directory server URL [ldap://local FQDN:389/o=NetscapeRoot]: ldaps://Config Server FQDN:636/o=NetscapeRoot ... CA certificate filename:

Re: [389-users] Possible problems on 1.2.10-0.6.a6.fc15.x86_64

2012-02-08 Thread Rich Megginson
On 02/08/2012 08:53 AM, Edward Z. Yang wrote: Hello folks, We recently updated our dirsrv instances to 1.2.10-0.6.a6.fc15.x86_64, and had it crash repeatedly one of our more loaded servers. We haven't debugged in depth but were curious whether or not anyone else had seen this problem. There

Re: [389-users] admserv_host_ip_check: ap_get_remote_host could not resolve

2012-02-08 Thread Rich Megginson
that explains how/why this function returns NULL. Cheers, Brett *De :*Rich Megginson [mailto:rmegg...@redhat.com] *Envoyé :* mercredi 8 février 2012 21:15 *À :* MATON Brett *Cc :* General discussion list for the 389 Directory server project. *Objet :* Re: [389-users] admserv_host_ip_check

Re: [389-users] dirsrv-admin with existing (remote) configuration server using SSL

2012-02-08 Thread Rich Megginson
NSSEngine /etc/dirsrv/admin-serv/* *De :*Rich Megginson [mailto:rmegg...@redhat.com] *Envoyé :* mercredi 8 février 2012 21:16 *À :* MATON Brett *Cc :* General discussion list for the 389 Directory server project. *Objet :* Re: [389-users] dirsrv-admin with existing (remote) configuration server using SSL

Re: [389-users] 389 on a Redhat VPS?

2012-02-09 Thread Rich Megginson
On 02/08/2012 07:41 PM, Craig T wrote: hi, Has anyone setup 389-ds on a OpenVZ VPS yet? I'm attempting to setup IPA 2.x on my VPS and it's giving odd errors when starting the 389 Directory Server. Spec; Centos 6.2 (x86-64) model name : Intel(R) Xeon(R) CPU E5645 @ 2.40GHz Linux

Re: [389-users] Admin Server - Encryption Tab

2012-02-09 Thread Rich Megginson
On 02/09/2012 08:45 AM, MATON Brett wrote: Platform RHEL6.2 x86_64 (EPEL repository enabled) $ rpm -qa | grep 389 389-admin-console-doc-1.1.8-1.el6.noarch 389-ds-base-libs-1.2.9.14-1.el6_2.2.x86_64 389-admin-console-1.1.8-1.el6.noarch 389-adminutil-1.1.14-2.el6.x86_64

Re: [389-users] Admin Server - Encryption Tab

2012-02-09 Thread Rich Megginson
On 02/09/2012 10:01 AM, MATON Brett wrote: On 02/09/2012 08:45 AM, MATON Brett wrote: Platform RHEL6.2 x86_64 (EPEL repository enabled) $ rpm -qa | grep 389 389-admin-console-doc-1.1.8-1.el6.noarch 389-ds-base-libs-1.2.9.14-1.el6_2.2.x86_64 389-admin-console-1.1.8-1.el6.noarch

Re: [389-users] Admin Server - Encryption Tab

2012-02-09 Thread Rich Megginson
On 02/09/2012 10:13 AM, MATON Brett wrote: Platform RHEL6.2 x86_64 (EPEL repository enabled) $ rpm -qa | grep 389 389-admin-console-doc-1.1.8-1.el6.noarch 389-ds-base-libs-1.2.9.14-1.el6_2.2.x86_64 389-admin-console-1.1.8-1.el6.noarch 389-adminutil-1.1.14-2.el6.x86_64

Re: [389-users] replication failure - clock skew

2012-02-09 Thread Rich Megginson
On 02/09/2012 12:23 PM, Greg Kuchyt wrote: Yesterday afternoon, one of my consumers randomly crashed/rebooted. Upon rebooting, its replication agreement with its master failed with the following error: Unable to acquire replica: Excessive clock skew between the supplier and the consumer.

Re: [389-users] SASL Mappings Question

2012-02-13 Thread Rich Megginson
a fedora account to file a bug. tried to login to trac. authentication not working. If you are on freenode irc, join #fedora-admin and ask those guys for help otherwise, let me know your fedora account name and I will file a ticket for you /mrg On Mon, Feb 13, 2012 at 10:12 AM, Rich

Re: [389-users] ACI for read only access

2012-02-14 Thread Rich Megginson
On 02/14/2012 12:17 AM, Walter Neu wrote: Hi all, I'm confused about ACI and need some help from the experts I want to create an ACI for read only access to a certain branch of my LDAP tree. Therefor I created the following ACI (targetattr = userPassword || uid) (target =

Re: [389-users] CMP operations against pwdPolicySubentry hanging

2012-02-14 Thread Rich Megginson
On 02/14/2012 06:37 PM, Iain Morgan wrote: Hello, On a fairly frequent basis, one of my 389 DS servers hangs after certain CMP operations. Once this happens, the server cannot be shutdown gracefully. This has been going on for several weeks, and I have not yet found a solution. My setup

Re: [389-users] CMP operations against pwdPolicySubentry hanging

2012-02-15 Thread Rich Megginson
On 02/15/2012 01:56 PM, Iain Morgan wrote: On Tue, Feb 14, 2012 at 19:54:39 -0600, Rich Megginson wrote: On 02/14/2012 06:37 PM, Iain Morgan wrote: Hello, On a fairly frequent basis, one of my 389 DS servers hangs after certain CMP operations. Once this happens, the server cannot be shutdown

Re: [389-users] CMP operations against pwdPolicySubentry hanging

2012-02-15 Thread Rich Megginson
On 02/15/2012 03:51 PM, Iain Morgan wrote: On Wed, Feb 15, 2012 at 15:04:52 -0600, Rich Megginson wrote: On 02/15/2012 01:56 PM, Iain Morgan wrote: On Tue, Feb 14, 2012 at 19:54:39 -0600, Rich Megginson wrote: On 02/14/2012 06:37 PM, Iain Morgan wrote: Hello, On a fairly frequent basis, one

Re: [389-users] CMP operations against pwdPolicySubentry hanging

2012-02-23 Thread Rich Megginson
On 02/23/2012 01:13 PM, Iain Morgan wrote: On Wed, Feb 15, 2012 at 18:19:10 -0600, Rich Megginson wrote: On 02/15/2012 03:51 PM, Iain Morgan wrote: On Wed, Feb 15, 2012 at 15:04:52 -0600, Rich Megginson wrote: On 02/15/2012 01:56 PM, Iain Morgan wrote: On Tue, Feb 14, 2012 at 19:54:39 -0600

Re: [389-users] EL5 Install instructions broken?

2012-02-29 Thread Rich Megginson
On 02/28/2012 07:42 PM, Michael Gettes wrote: Hi All, I am following the instructions on http://port389.org/wiki/Download for EL5 (towards the bottom) and it would appear the URLs are bad. There appears to be no port389.org/yum/blah http://port389.org/yum/blah. I need to use EL5 - going to

Re: [389-users] 389-console

2012-02-29 Thread Rich Megginson
On 02/29/2012 03:07 PM, Ldap Tester wrote: I have been running 2 masters for a number of years now. The packages I have installed currently are: 389-admin-1.1.23-1.fc16.x86_64 389-admin-console-1.1.8-2.fc16.noarch 389-admin-console-doc-1.1.8-2.fc16.noarch 389-adminutil-1.1.14-1.fc16.x86_64

Re: [389-users] Error updating to 389 1.2.9.9

2012-03-01 Thread Rich Megginson
changed with 389-ds-base 1.2.10.2 - any chance you could try that version, in epel-testing? On Mar 1, 2012, at 22:26, Rich Megginson wrote: On 03/01/2012 08:10 PM, Michael R. Gettes wrote: As I have tried to learn more about this problem, it would appear there isn't an obvious way to address

Re: [389-users] continuously segfault: 389ds 1.2.10.2 - 1.el6

2012-03-05 Thread Rich Megginson
On 03/05/2012 07:52 AM, Roberto Polli wrote: Hi Mark, Mark Reynoldsmarey...@redhat.com We actually just fixed this on Friday via Ticket 305. Rich would know more about the next release that would contain this fix. This is it https://fedorahosted.org/389/ticket/305 The stuff is cos-related,

Re: [389-users] ChainOnUpdate

2012-03-05 Thread Rich Megginson
On 03/05/2012 03:55 PM, Jim Finn wrote: Note: I have searched through years past in 389-users and have found a few others experiencing the same problem, yet I could not find any resolution. I am attempting to setup chain on update per

Re: [389-users] dirsrv does not start anymore

2012-03-06 Thread Rich Megginson
On 03/05/2012 06:36 PM, Vasil Mikhalenya wrote: Hi all, I can not solve the following issue. I can not start my master anymore. /var/log/dirsrv/slapd-ldap1/errors: [05/Mar/2012:19:43:06 +0300] - 389-Directory/1.2.10.2 B2012.054.1543 starting up [05/Mar/2012:19:43:06 +0300] - Detected

Re: [389-users] 389-ds on Centos 6.2 java probs

2012-03-06 Thread Rich Megginson
On 03/05/2012 09:56 AM, mja...@guesswho.com wrote: Hi, I’m trying to install 389-ds on Centos 6.2 and failing with java probs. Sorry for the verbosity below. The Install Guide (http://directory.fedoraproject.org/wiki/Install_Guide) says “If you see something that says /gcj/ or /GCJ/ you're

Re: [389-users] Require SSL/TLS connections?

2012-03-06 Thread Rich Megginson
On 02/23/2012 06:40 PM, David Nguyen wrote: Hi All, I have TLS connections working and would like to disable non-SSL connections (ie unencrypted traffic). Same situation as what was asked below in 2007: http://lists.fedoraproject.org/pipermail/389-users/2007-October/006347.html Is this

Re: [389-users] Setting limits per DN

2012-03-06 Thread Rich Megginson
On 02/15/2012 07:15 PM, Michael Gettes wrote: My global time limit is 3600. global idle timeout is 0. global size limit is 500. global lookthroughlimit is 5000. on my DN I have established nsidletimeout, nssizelimit, nslookthroughlimit and nstimelimit as -1. What platform? What version

Re: [389-users] SSL initialization Failed

2012-03-07 Thread Rich Megginson
On 03/07/2012 06:34 AM, Luigi Santangelo wrote: Hi guru, i have a problem with enabling SSL in my Fedora Directory Server. I already searched with google and I have found other people that have same problem but, following the instructions, I cannot resolve my problem (maybe my problem has a

Re: [389-users] DSGW jpegPhoto upload

2012-03-07 Thread Rich Megginson
On 03/07/2012 02:32 PM, Eric Raymond wrote: Hello All, I have gone through the documentation with dsgw, and editing the content, but was suprised to find nothing about uploading photos through the webUI. Is there any documentation on how this can be added to the web pages? I wanted to

Re: [389-users] Replacing a DS server

2012-03-08 Thread Rich Megginson
...@lists.fedoraproject.org [mailto:389-users-boun...@lists.fedoraproject.org] *On Behalf Of *Rich Megginson *Sent:* Thursday, March 08, 2012 12:47 PM *To:* General discussion list for the 389 Directory server project. *Subject:* Re: [389-users] Replacing a DS server On 03/08/2012 10:45 AM, Gerhardus Geldenhuis wrote

Re: [389-users] Replacing a DS server

2012-03-08 Thread Rich Megginson
On 03/08/2012 11:05 AM, mja...@guesswho.com wrote: Thx for the heads-up. Would I be better off just adding the new server with a new IP address as a multi-master, then removing the old one? Not re-using either the hostname or IP? That would certainly be easier. *From:*Rich Megginson

Re: [389-users] LDAP server is unwilling to perform

2012-03-12 Thread Rich Megginson
On 03/12/2012 12:39 PM, mja...@guesswho.com wrote: Pls. see attached. Thx. Hmm - nothing to go on there - please turn on the Replication log level and reproduce the problem - then the errors log may contain more clues http://port389.org/wiki/FAQ#Troubleshooting Mike *From:*Rich Megginson

Re: [389-users] CMP operations against pwdPolicySubentry hanging

2012-03-12 Thread Rich Megginson
On 03/12/2012 05:40 PM, Iain Morgan wrote: On Thu, Feb 23, 2012 at 12:13:18 -0800, Iain Morgan wrote: On Wed, Feb 15, 2012 at 18:19:10 -0600, Rich Megginson wrote: On 02/15/2012 03:51 PM, Iain Morgan wrote: On Wed, Feb 15, 2012 at 15:04:52 -0600, Rich Megginson wrote: On 02/15/2012 01:56 PM

Re: [389-users] LDAP server is unwilling to perform

2012-03-13 Thread Rich Megginson
- /var/log/dirsrv/slapd-INST/errors Mike *From:*Rich Megginson [mailto:rmegg...@redhat.com] *Sent:* Monday, March 12, 2012 3:14 PM *To:* General discussion list for the 389 Directory server project. *Cc:* Michael James *Subject:* Re: [389-users] LDAP server is unwilling to perform On 03/12/2012

Re: [389-users] LDAP server is unwilling to perform

2012-03-13 Thread Rich Megginson
to the list? ldapsearch -xLLL -D cn=directory manager -W -b cn=config cn=389 to analog *From:*Michael James *Sent:* Tuesday, March 13, 2012 12:13 PM *To:* 'Rich Megginson' *Subject:* RE: [389-users] LDAP server is unwilling to perform That’s a big **IF** there… I did turn up the logging

[389-users] Announcing 389 Directory Server version 1.2.10.4 Testing

2012-03-13 Thread Rich Megginson
The 389 Project team is pleased to announce the release of 389-ds-base-1.2.10.4. This release contains a fix for a bug that causes the directory server to hang when using compare operations with virtual attributes. No new features were added after alpha 8, just many bug fixes. There are also

Re: [389-users] bypassing limits for persistent search and specific user

2012-03-13 Thread Rich Megginson
On 03/13/2012 05:09 PM, Petr Spacek wrote: Hello list, I'm looking for way how to bypass nsslapd-sizelimit and nsslapd-timelimit for persistent search made by specific user (or anything made by that user). Please, can you point me to right place in documentation about persistent

Re: [389-users] bypassing limits for persistent search and specific user

2012-03-14 Thread Rich Megginson
On 03/14/2012 07:42 AM, Petr Spacek wrote: Hello, On 03/14/2012 12:16 AM, Nathan Kinder wrote: On 03/13/2012 04:09 PM, Petr Spacek wrote: Hello list, I'm looking for way how to bypass nsslapd-sizelimit and nsslapd-timelimit for persistent search made by specific user (or anything made by

Re: [389-users] About LDAP filters

2012-03-14 Thread Rich Megginson
On 03/14/2012 01:33 AM, Juan Asensio Sánchez wrote: Hi Is it important the order of the filter in a search? So, what's the most optomized filter? It's very difficult to say. You'd really have to parse the code to understand what it's doing. ((uid=*)(objectClass=sambaSamAccount)) Or

Re: [389-users] altering replication agreements

2012-03-20 Thread Rich Megginson
On 03/14/2012 07:25 PM, Michael R. Gettes wrote: EL 5.6 and ds-389 1.2.9.9 I have a question of curiosity… I have a number of replication agreements. They were initially configured as TLS on port 389. I need them to be moved to SSL on 636. I could re-create the agreements and delete the

<    1   2   3   4   5   6   7   8   9   >