Re: [389-users] FW: fresh replica reports reloading ruv failed just after successfull initialization

2013-06-24 Thread Rich Megginson
On 06/24/2013 09:34 AM, jovan.vuko...@sungard.com wrote: Hi,   I would like to link the issue I reported on Saturday with the bug 723937 filed some two years ago. There, just as

Re: [389-users] 389-console LDIF export question

2013-06-27 Thread Rich Megginson
On 06/27/2013 04:57 AM, Michael Lang wrote: Dear all, I would like to clarify how the procedure to export - LDIF through the 389-console GUI is done (or how if reproduce should be done). As far as I've understood the exports on the server itself is done through creating a appropriate entry in

Re: [389-users] Problems upgrading from PassSync 1.4 to PassSync 1.5

2013-06-27 Thread Rich Megginson
On 06/27/2013 03:28 AM, Juan Carlos Camargo wrote: Hi list, I was expecting these new changes in PassSync (moreover those related to the 8th bit handling) , so congrats for the advances.

Re: [389-users] 389-console LDIF export question

2013-06-27 Thread Rich Megginson
On 06/27/2013 12:32 PM, Michael Lang wrote: On 06/27/2013 06:13 PM, Rich Megginson wrote: On 06/27/2013 04:57 AM, Michael Lang wrote: Dear all, I would like to clarify how the procedure to export - LDIF through the 389-console GUI is done (or how if reproduce should be done). As far as I've

Re: [389-users] 389-console LDIF export question

2013-06-28 Thread Rich Megginson
On 06/28/2013 02:14 AM, Michael Lang wrote: On 06/27/2013 08:52 PM, Rich Megginson wrote: On 06/27/2013 12:32 PM, Michael Lang wrote: On 06/27/2013 06:13 PM, Rich Megginson wrote: On 06/27/2013 04:57 AM, Michael Lang wrote: Dear all, I would like to clarify how the procedure to export

Re: [389-users] Authentication method not supported

2013-07-15 Thread Rich Megginson
endian. Maybe we have a 32 access to a 64 bit var, which has no effect on little endian machines. Ludwig On 07/01/2013 04:06 PM, Rich Megginson wrote: On 06/30/2013 12:10 AM, _ilmir@atacom.kz_ mailto:il...@atacom.kzwrote: Good morning! Yes. Accesslog level is *772*: / [30/Jun/2013:12:00:31 +0600

Re: [389-users] Fwd: Some cipher suites not working

2013-07-19 Thread Rich Megginson
On 07/19/2013 06:43 AM, Darcy Hodgson wrote: Hello, I have been setting up SSL/TLS with 389 DS on CentOS 6.4. I have been able to get it working and can connect with LDAPS. However when I started to disabled some of the ciphers I noticed that my server wasn't accepting any of the DHE

Re: [389-users] 389 Deadlock

2013-07-22 Thread Rich Megginson
, but this stack trace is useless. Looks like you don't have the right versions of the debuginfo packages. Please check the directions at http://port389.org/wiki/FAQ#Debugging_Crashes and Debugging_Hangs On Mon, Jul 22, 2013 at 8:02 AM, Rich Megginson rmegg...@redhat.com mailto:rmegg

Re: [389-users] Question about lastlogintime

2013-07-26 Thread Rich Megginson
On 07/26/2013 09:07 AM, harry.dev...@faa.gov wrote: We were interested in tracking a user's last login time, and I see the attribute that I can add in the user's profile. But we have 460 users so adding that in manually would be tedious. I saw this article online:

Re: [389-users] Question about lastlogintime

2013-07-26 Thread Rich Megginson
(609)485-4218 harry.dev...@faa.gov From: Rich Megginson rmegg...@redhat.com To: General discussion list for the 389 Directory server project. 389-users@lists.fedoraproject.org Cc: Harry Devine/ACT/FAA@FAA Date: 07/26/2013 11:57 AM Subject:Re: [389-users] Question about

Re: [389-users] Removing non-existent instances

2013-07-29 Thread Rich Megginson
/documentation/en-US/Red_Hat_Directory_Server/9.0/html/Administration_Guide/Managing_Replication-Solving_Common_Replication_Conflicts.html#cleanruv -Tripp On Mon, Jul 29, 2013 at 10:47 AM, Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com wrote: On 07/29/2013 09:46 AM, Tripp

Re: [389-users] How to keep dnanextvalue in sync when using DNA plugin?

2013-07-30 Thread Rich Megginson
On 07/30/2013 08:41 AM, Kyle Johnson wrote: Sorry, I should know better. 389-ds-base-1.2.11.15-12.el6_4.x86_64 Then yes, it has that patch. On 2013-07-30 10:38, Rich Megginson wrote: On 07/30/2013 08:09 AM, Kyle Johnson wrote: I have found this bug (https://bugzilla.redhat.com

Re: [389-users] Question about lastlogintime

2013-07-30 Thread Rich Megginson
Thanks, Harry Harry Devine Common ARTS Software Development AJM-245 (609)485-4218 harry.dev...@faa.gov From: Rich Megginson rmegg...@redhat.com To: Harry Devine/ACT/FAA@FAA Cc: General discussion list for the 389 Directory server project. 389-users@lists.fedoraproject.org Date: 07/26

Re: [389-users] How to keep dnanextvalue in sync when using DNA plugin?

2013-07-30 Thread Rich Megginson
on the original server is now up to around ~10080. Kyle On 2013-07-30 11:00, Rich Megginson wrote: On 07/30/2013 08:48 AM, Kyle Johnson wrote: If it has the patch, what would be causing my dnanextvalue fields to not be in sync? They're using the local value of the dnanextvalue, and when

[389-users] [389-announce] Announcing 389 Directory Server version 1.2.11.22

2013-08-01 Thread Rich Megginson
. * Ticket #47378 https://fedorahosted.org/389/ticket/47378 - fix recent compiler warnings * Ticket #543 https://fedorahosted.org/389/ticket/543 - Sorting with attributes in ldapsearch gives incorrect result Rich Megginson (20): * Ticket #47362 https://fedorahosted.org/389/ticket/47362 - ipa

Re: [389-users] 389 crash libdb: PANIC: fatal region error detected

2013-08-02 Thread Rich Megginson
On 08/02/2013 01:30 AM, Manel Gimeno Zaragozá wrote: Hello, Yesterday afternoon my LDAP server crashed without doing any modification, just consulting. My environment is an openvz container: # cat /etc/issue CentOS release 6.4 (Final) Kernel \r on an \m # uname -a Linux newldap.test.es

Re: [389-users] [389-announce] Announcing 389 Directory Server version 1.2.11.22

2013-08-02 Thread Rich Megginson
On 08/02/2013 01:51 AM, Carsten Grzemba wrote: Hi Rich, Am 01.08.13 schrieb *Rich Megginson * rmegg...@redhat.com: On 08/01/2013 02:35 PM, Tim Daley wrote: Just tried it. Looks like I'm still getting 389-ds-base.x86_64 0:1.2.11.21-1.el6_4 when I do a yum clean all yum --enablerepo=epel

Re: [389-users] Question about installing on new servers

2013-08-13 Thread Rich Megginson
on timing and the whims of the replication protocol. We were looking at some of the docs but hadn't really found anything step by step so I thought I'd ask. Thanks! Harry Devine Common ARTS Software Development AJM-245 (609)485-4218 harry.dev...@faa.gov From: Rich Megginson rmegg

Re: [389-users] Fwd: multi-master replication RFC reference

2013-08-19 Thread Rich Megginson
On 08/17/2013 09:47 AM, Archimedes Gaviola wrote: On Fri, Aug 16, 2013 at 9:27 PM, Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com wrote: On 08/16/2013 12:22 AM, Archimedes Gaviola wrote: Hi, I would like to know if 389 DS closely follow this RFC specs http

Re: [389-users] Attribute value ordering

2013-08-21 Thread Rich Megginson
, Tehnološki park 18, p.p. 7, SI-1001 Ljubljana, Slovenia tel: +386 1 479 8877, fax: +386 1 479 88 78 On 08/19/2013 05:22 PM, Rich Megginson wrote: On 08/19/2013 09:12 AM, Mitja Mihelič wrote: Hi! Out DIT holds user entries that have multiple mail attributes (main email, aliases). Here

Re: [389-users] Best way to upgrade DS servers

2013-08-21 Thread Rich Megginson
On 08/21/2013 01:03 PM, Michael Lang wrote: Am 21.08.2013 19:25, schrieb Chris Taylor: I am looking at replacing our two CentOS DS servers which are 5.9 with some on the 6.4 channel. What is the best way to transition all the data over? Should I build them separately and import everything

Re: [389-users] Best way to upgrade DS servers

2013-08-22 Thread Rich Megginson
servers. Does this sound about right? Yes. Chris *From:*389-users-boun...@lists.fedoraproject.org [mailto:389-users-boun...@lists.fedoraproject.org] *On Behalf Of *Rich Megginson *Sent:* Wednesday, August 21, 2013 3:40 PM *To:* Michael Lang *Cc:* General discussion list for the 389

Re: [389-users] Multi-Theading writes to the same 389 Master Server

2013-08-29 Thread Rich Megginson
0x2aeeadf4df1a in ldbm_back_modify (pb=0x2af022054ca0) at ldap/servers/slapd/back-ldbm/ldbm_modify.c:269 On Wed, Aug 21, 2013 at 9:14 AM, Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com wrote: On 08/21/2013 09:53 AM, David Boreham wrote: Another thing you might try

Re: [389-users] Consumer Initialization Failure

2013-08-30 Thread Rich Megginson
On 08/30/2013 01:24 PM, Wick, Samson wrote: Running 389-ds version 1.2.2-1 (according to the rpm) rpm -q 389-ds-base version of 389-ds is almost meaningless In attempting to stand up a new consumer in our environment, the process of allowing the supplier to initialize the consumer

Re: [389-users] Consumer Initialization Failure

2013-09-03 Thread Rich Megginson
Is there a good place I can go to educate myself on what a “vucsn” actually means, and possibly why I have hundreds of thousands of them for userPassword in my initialization files? It is replication meta-data which is supposed to be automatically trimmed. Thanks *From:*Rich Megginson [mailto:rmegg

Re: [389-users] Indexes, looking for practical tips

2013-09-13 Thread Rich Megginson
On 09/13/2013 12:50 AM, Vesa Alho wrote: Hi, I would like to understand how to improve indexes in our current 389 servers. I have not yet touched default indexes settings. Entry cache hit ratio for userRoot is 59%, which is fairly low if I've undestood correctly? I've read the excellent

Re: [389-users] logconv.pl backward compatibility?

2013-09-16 Thread Rich Megginson
On 09/16/2013 01:58 PM, Michael Gettes wrote: Hi, I am currently on 389-ds-base 1.2.11.15-22.el6_4 and I am running logconv.pl on 5.5M line log file. At the end it hangs up - in a loop forever and doesn't finish generating the report. What I am wondering is if I installed 1.3 latest on

Re: [389-users] logconv.pl backward compatibility?

2013-09-25 Thread Rich Megginson
time is spent spitting out the unindexed stuff which is critical information to fix apps or provide additional indices. Right. We are working on this. /mrg On Sep 16, 2013, at 4:01 PM, Rich Megginson rmegg...@redhat.com wrote: On 09/16/2013 01:58 PM, Michael Gettes wrote: Hi, I am currently

Re: [389-users] 389 won't start - help please?

2013-09-30 Thread Rich Megginson
On 09/29/2013 06:11 PM, Michael R. Gettes wrote: we are able to get a backtrace via gdb (gdb) bt #0 0x7fc637cd5bd8 in attrlist_find () from /usr/lib64/dirsrv/libslapd.so.0 #1 0x7fc637ce70b2 in slapi_entry_attr_find () from /usr/lib64/dirsrv/libslapd.so.0 #2 0x7fc62c7f34e4 in

Re: [389-users] Problem starting and replicating RHDS9

2013-10-01 Thread Rich Megginson
On 10/01/2013 06:19 AM, Ric wrote: Hello All, I hope you can forgive a request which I am sure doesn't have enough information in it, please let me know what else I can add if you might be able to help. I have a problem with our installation of RHDS9 and practically nothing in the logs to

Re: [389-users] 389 crash 1.2.11.15-22.el6_4

2013-10-02 Thread Rich Megginson
On 10/02/2013 08:22 AM, Michael Gettes wrote: We had a crash early this morning on one of our masters (MMR with 2 servers, 3 replicas connected to each). Nothing in the errors log. The service was restarted and has not crashed since. From syslog we have: kernel: ns-slapd[18143]:

Re: [389-users] 389 crash 1.2.11.15-22.el6_4

2013-10-02 Thread Rich Megginson
to find? How's this? http://port389.org/wiki/Documentation#Howtos /mrg On Oct 2, 2013, at 10:32 AM, Rich Megginson rmegg...@redhat.com wrote: On 10/02/2013 08:22 AM, Michael Gettes wrote: We had a crash early this morning on one of our masters (MMR with 2 servers, 3 replicas connected

[389-users] Announcing 389 Directory Server version 1.2.11.23

2013-10-02 Thread Rich Megginson
/ticket/47540 - Coverity fixes 12023, 12024, and 12025 * Ticket #422 https://fedorahosted.org/389/ticket/422 - 389-ds-base - Can't call method getText Rich Megginson (13): * Bug 999634 https://bugzilla.redhat.com/show_bug.cgi?id=999634 - ns-slapd crash due to bogus DN * Ticket #47516 https

[389-users] EL5 - new testing build - 389-ds-base-1.2.11.24

2013-10-04 Thread Rich Megginson
There are still some of you in the 389 community that are running on EL5, and we haven't had an update for quite some time. The 389 team has backported some fixes that allow the 1.2.11 branch to build on EL5. There is a new build in epel-testing for EL5 - 389-ds-base-1.2.11.24-1.el5 If you

Re: [389-users] SunONE 5.2 vs centos-ds or 389 ds

2013-10-07 Thread Rich Megginson
On 10/05/2013 10:41 PM, sang jun song wrote: I was performance test last week. I want to migrate from SunONE 5.2 to centos-ds or 389 ds. but SunONE 5.2 performance is GoD!!~. why? OS: redhat linux 5.9 or centos linnux 5.9 HW : Specifications are the same. target Directory Server:

Re: [389-users] Problems with replication

2013-10-15 Thread Rich Megginson
On 10/15/2013 04:40 AM, Parasit Hendersson wrote: Hi, Once again we have a problem on our servers , this time with replication. In the log file repeatedly appear the same entries. [15/Oct/2013:11:08:43 +0200] NSMMReplicationPlugin - agmt=master port 389 to slave port 389 (slave:389): Beginning

Re: [389-users] Problems with replication

2013-10-15 Thread Rich Megginson
On 10/15/2013 07:39 AM, Parasit Hendersson wrote: W dniu 2013-10-15 15:24, Rich Megginson pisze: A given solution in this case it does not help, i made (again) initialization and the effect is exactly the same. What else can be wrong? You initialized the server slave port 389 from

Re: [389-users] slapi_ldap_init segmentation fault

2013-10-18 Thread Rich Megginson
On 10/17/2013 06:15 PM, Russell Beall wrote: Hi, I am trying to port a plugin from our Sun DS to 389. I worked through a number of API differences and got it to compile. When I tried to run a test I keep getting segmentation faults in the pthread library regardless of how I compile or link

Re: [389-users] MemberOf Plugin - experiences?

2013-10-22 Thread Rich Megginson
/removing users from groups would trigger it to update ALL groups for that user, Yes, it does. so I just bulk added everyone to a group and problem solved. On Tue, Oct 22, 2013 at 12:01 PM, Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com wrote: On 10/22/2013 10:52 AM, Jonathan

Re: [389-users] SSL simple (I hope) question

2013-10-23 Thread Rich Megginson
On 10/23/2013 03:34 PM, Russell Beall wrote: I am working out the best way to enable SSL in a new 389 directory suite setup. I found that when updating the SSL certificate, there are problems with the symmetric keys used for attribute encryption. The instructions simply say to delete those

Re: [389-users] COMPATIBILITY BETWEEN VERSIONS.

2013-11-04 Thread Rich Megginson
On 11/03/2013 05:15 AM, Ezequiel Larrarte wrote: Hi people ... Nowadays, I have CentOS5 on my servers, but next year I ll start setting up CentOS 6 on them. I ll first install 389DS on the main CentOS5 servers from EPEL repository (currently version 1.2.1) and I guess replication between them

Re: [389-users] PAM Pass through authentication only one threaded

2013-11-04 Thread Rich Megginson
On 11/04/2013 08:05 AM, Jan Tomasek wrote: Hi Rich, On 11/01/2013 04:28 PM, Rich Megginson wrote: If there is 30 or more parallel connections 389 hangs for ever. Very often killing process ldapsearch process does not help. Server is very often unable to restart so I have to kill it with -9

Re: [389-users] COMPATIBILITY BETWEEN VERSIONS.

2013-11-04 Thread Rich Megginson
On 11/04/2013 08:16 AM, Ezequiel Larrarte wrote: Hi Rich, Can you be more specific? On Nov 4, 2013 11:49 AM, Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com wrote: On 11/03/2013 05:15 AM, Ezequiel Larrarte wrote: Hi people ... Nowadays, I have CentOS5

Re: [389-users] COMPATIBILITY BETWEEN VERSIONS.

2013-11-04 Thread Rich Megginson
Megginson wrote: On 11/04/2013 09:39 AM, Ezequiel Larrarte wrote: On Mon, Nov 4, 2013 at 1:21 PM, Rich Megginson rmegg...@redhat.com wrote: On 11/04/2013 09:06 AM, Ezequiel Larrarte wrote: No matter that they are different versions??? Yes. The replication protocol is the same. The only problems you

Re: [389-users] PAM Pass through authentication only one threaded

2013-11-04 Thread Rich Megginson
On 11/04/2013 10:46 AM, Jan Tomasek wrote: On 11/04/2013 05:22 PM, Rich Megginson wrote: On 11/04/2013 09:08 AM, Jan Tomasek wrote: On 11/04/2013 05:04 PM, Rich Megginson wrote: Does the script open a connection to the same server it is being called from? Yes. So this is a case of self

Re: [389-users] Export Replica Question

2013-11-04 Thread Rich Megginson
On 11/04/2013 12:59 PM, Paul Whitney wrote: I have a master, hub, and 4 consumers. I want to initialize the consumers who have a replication agreement from the hub. Is it okay to export the replica from one replication agreement to a consumer and use the that same replica for the three

Re: [389-users] COMPATIBILITY BETWEEN VERSIONS.

2013-11-05 Thread Rich Megginson
4, 2013 12:21 PM, Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com wrote: On 11/04/2013 08:16 AM, Ezequiel Larrarte wrote: Hi Rich, Can you be more specific? On Nov 4, 2013 11:49 AM, Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com wrote

Re: [389-users] 389 1.3 - something to consider

2013-11-08 Thread Rich Megginson
On 11/08/2013 02:10 PM, Michael Gettes wrote: As I currently understand things, 389 1.2 is available via RPM dist channels (including epel test using rmeggins people repo) . . . and really isn't fully supported. My main intention for providing EL6 binaries was to give a preview of upcoming

Re: [389-users] 389 1.3 - something to consider

2013-11-08 Thread Rich Megginson
On 11/08/2013 02:58 PM, Michael Gettes wrote: On Nov 8, 2013, at 4:50 PM, Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com wrote: On 11/08/2013 02:10 PM, Michael Gettes wrote: As I currently understand things, 389 1.2 is available via RPM dist channels (including epel test using

Re: [389-users] 389 directory server crash

2013-11-14 Thread Rich Megginson
On 11/14/2013 08:50 AM, Mitja Mihelič wrote: One of the consumers has crashed again and I have attached the stacktrace. Four hous later it crashed again. I do hope there is something in the stacktraces, so that something can be done to prevent future crashes. Unfortunately, not enough.

Re: [389-users] 389 illegal seek after Replication Delete

2013-11-14 Thread Rich Megginson
On 11/14/2013 03:36 PM, Jeffrey Dunham wrote: We're running 389-Directory/1.2.10.14 http://1.2.10.14 on Rhel5.3 and just ran into a database issue that we've not seen before. I don't know if it's related to the replication delete just before it, but we've successfully added and deleted multiple

Re: [389-users] 389 directory server crash

2013-11-18 Thread Rich Megginson
On 11/18/2013 07:01 AM, Mitja Mihelič wrote: On 15. 11. 2013 21:46, Rich Megginson wrote: On 11/15/2013 02:58 AM, Mitja Mihelič wrote: On 14. 11. 2013 22:08, Rich Megginson wrote: On 11/14/2013 08:50 AM, Mitja Mihelič wrote: One of the consumers has crashed again and I have attached

Re: [389-users] 1.2.11.xx in stable repos

2013-11-19 Thread Rich Megginson
On 11/19/2013 02:23 AM, Lulzim KELMENI wrote: Hello, We are planning to update our 389-ds from version 389-ds-base-1.2.10.7-1.el6.x86_64 to version 1.2.11.xx. We have tested the 389-ds-base-1.2.11.23-3.el6.x86_64 version from epel-testing-389-ds-base repo. We have not find any probem with

Re: [389-users] 389-ds-base-1.2.10.14-3.2.el5: replication latency = 300s, 400s, 900s..

2013-11-20 Thread Rich Megginson
On 11/18/2013 04:12 AM, Justin Piszcz wrote: Hi, Problem: During high levels of writes to the master server, _some_ LDAP search hosts replication_latency rises (and in some cases, does not recover) unless its removed from service or slapd is restarted. Version: 389-ds-base-1.2.10.14-3.2.el5

Re: [389-users] nsds5replicaLastInitStatus: -2 Total update abortedSystem error

2013-11-25 Thread Rich Megginson
On 11/23/2013 08:11 AM, Graham Leggett wrote: Hi all, I have two LDAP servers in a multimaster replication setup that has worked fine for a while. Recently it was reported to me that the two LDAP servers had somehow gone out of sync and refused to replicate. I am trying to fix this by

Re: [389-users] setup-ds-admin.pl --update and multiple masters

2013-11-25 Thread Rich Megginson
On 11/23/2013 02:14 AM, Vesa Alho wrote: Hi, I have the following setup: ldap1.example.com ldap2.example.com They are in Multiple Master configuration. After normal yum updates, I run setup-ds-admin.pl --update 1. What does this script actually do with --update parameter? Does it only

Re: [389-users] Password Failure Lockout doesn't seem to work

2013-11-25 Thread Rich Megginson
On 11/25/2013 03:33 PM, JLPicard wrote: Hi, I am testing out 389_ds_base, version =1.2.11.15,REV=2013.01.31 running on mixed Solaris 10 servers (SPARC and X86) sourced from http://www.opencsw.org/packages/CSW389-ds-base in multi-master mode with 4 servers that is primarily used for

Re: [389-users] Upgrade failure

2013-11-25 Thread Rich Megginson
On 11/25/2013 04:37 PM, Gordon Messmer wrote: On Friday, I updated one of several systems that I manage from version 1.2.11.15 to version 1.2.11.25. Thereafter, the service was unable to start. The error indicates a problem with SSL that I don't understand. I've included the relevant

Re: [389-users] setup-ds-admin.pl errors

2013-11-26 Thread Rich Megginson
. On Thu, Nov 21, 2013 at 3:09 PM, Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com wrote: On 11/21/2013 09:55 AM, Alberto Viana wrote: Rich, Yes. If you need any specific info about how I built please let me know. yes, your configure

Re: [389-users] Upgrade failure

2013-11-26 Thread Rich Megginson
On 11/25/2013 06:26 PM, Gordon Messmer wrote: On 11/25/2013 03:54 PM, Rich Megginson wrote: Is there some reason you need to upgrade from the OS provided official RHEL 6.4 version of 389-ds-base to the non-OS provided version from the rmeggins epel6 repo? I no longer remember why that's

Re: [389-users] migrate-ds-admin.pl

2013-12-02 Thread Rich Megginson
On 12/02/2013 07:19 AM, Alberto Viana wrote: After some tries I got it working but now i'm getting these errors: +[02/Dec/2013:12:16:25 -0200] - 389-Directory/1.3.2.6 http://1.3.2.6 B2013.336.123 starting up +[02/Dec/2013:12:16:25 -0200] - I'm resizing my cache now...cache was 417587200 and

Re: [389-users] Replication issue after improper shutdown

2013-12-02 Thread Rich Megginson
On 12/02/2013 05:49 AM, Sugantha J wrote: Hi Everyone I am running 389 DS 1.2.8.2 in CentOS 4.8. I have a multi master setup, with 12 LDAP servers. Everything was working fine, till one of the boxes (ldapw02) suddenly crashed. When it came back up, I see the following in the error log,

Re: [389-users] Replication issue after improper shutdown

2013-12-03 Thread Rich Megginson
:*Rich Megginson [mailto:rmegg...@redhat.com] *Sent:* Tuesday, December 03, 2013 12:22 AM *To:* General discussion list for the 389 Directory server project. *Cc:* Sugantha J *Subject:* Re: [389-users] Replication issue after improper shutdown On 12/02/2013 05:49 AM, Sugantha J wrote: Hi

Re: [389-users] 1.2.11.15 rolls up some objectclasses?

2013-12-03 Thread Rich Megginson
On 12/02/2013 06:42 PM, Colin Panisset wrote: I have a 4-way multi-master replication configuration; the servers are slightly different versions, as below: A - 1.2.9.9-1.el5 (CentOS 5) B - 1.2.9.9-1.el5 (CentOS 5) C - 1.2.10.2-20.el6_3 (CentOS 6) D - 1.2.11.15-22.el6_4 (CentOS 6) D was

Re: [389-users] Upgrade failure

2013-12-03 Thread Rich Megginson
On 12/03/2013 03:11 PM, Gordon Messmer wrote: On 11/25/2013 03:54 PM, Rich Megginson wrote: Is there some reason you need to upgrade from the OS provided official RHEL 6.4 version of 389-ds-base to the non-OS provided version from the rmeggins epel6 repo? Now I remember... there's no Windows

Re: [389-users] check hostname option

2013-12-05 Thread Rich Megginson
On 12/05/2013 10:12 AM, Alberto Viana wrote: I have 2 389 running (389-Directory/1.3.2.6 http://1.3.2.6 and 389-Directory/1.3.1.3 http://1.3.1.3) with multiple master configuration. When I set the option check hostname against name in certificate for outbound SSL connections the agreement

Re: [389-users] Version Display on RHDS 9 Upgrade

2013-12-06 Thread Rich Megginson
On 12/06/2013 10:41 AM, Paul Whitney wrote: I recently upgraded my DS9 instance (RHDS9 RHBA-2013-0960) on both ldap server and my console. This should bring my servers to DS 9.1. Yet, I still see Version 9.0.0. Is this correct or did I miss a step? There should have been something in the

Re: [389-users] Version Display on RHDS 9 Upgrade

2013-12-06 Thread Rich Megginson
, Rich Megginson rmegg...@redhat.com wrote: On 12/06/2013 10:41 AM, Paul Whitney wrote: I recently upgraded my DS9 instance (RHDS9 RHBA-2013-0960) on both ldap server and my console. This should bring my servers to DS 9.1. Yet, I still see Version 9.0.0. Is this correct or did I miss a step

Re: [389-users] Version Display on RHDS 9 Upgrade

2013-12-06 Thread Rich Megginson
symbolic links and for 9.0 jar files, why will the console not use the jars already present? A 9.1 server must use the 9.1 jars, not the 9.0 jars. Paul M. Whitney E-mail: paul.whit...@mac.com Cell: 410.493.9448 On Dec 06, 2013, at 12:35 PM, Rich Megginson rmegg...@redhat.com wrote

Re: [389-users] 1.2.11.15 rolls up some objectclasses?

2013-12-09 Thread Rich Megginson
On 12/08/2013 10:24 PM, Colin Panisset wrote: Hi Rich, apologies for the delay in replying, I've been out of the office for a couple of days. On 12/04/2013 08:31 AM, Rich Megginson wrote: On 12/02/2013 06:42 PM, Colin Panisset wrote: I have a 4-way multi-master replication configuration

Re: [389-users] Version Display on RHDS 9 Upgrade

2013-12-09 Thread Rich Megginson
On 12/09/2013 10:55 AM, Paul Whitney wrote: Paul M. Whitney E-mail: paul.whit...@mac.com On Dec 09, 2013, at 11:27 AM, Rich Megginson rmegg...@redhat.com wrote: On 12/09/2013 09:30 AM, Paul Whitney wrote: Rich, I deinstalled and reinstalled my DS 9.0 ISO, then ran through the updates

Re: [389-users] Version Display on RHDS 9 Upgrade

2013-12-09 Thread Rich Megginson
2011.312.195. It would appear to me that the config instance did not get updated correctly. I would appear that setup-ds-admin.pl -u is still not running correctly. Paul M. Whitney E-mail: paul.whit...@mac.com On Dec 09, 2013, at 12:53 PM, Rich Megginson rmegg...@redhat.com wrote: On 12/09/2013

Re: [389-users] hang on 1.2.11.15

2013-12-11 Thread Rich Megginson
On 12/11/2013 10:34 AM, Michael Gettes wrote: 389-Directory/1.2.11.15 B2013.238.2155 2 MMR master servers (this hang happened on one of the masters) along with 3 read-only replicas. Linux 2.6.32-358.18.1.el6.x86_64 #1 SMP Fri Aug 2 17:04:38 EDT 2013 x86_64 x86_64 x86_64 GNU/Linux

Re: [389-users] group issues

2013-12-12 Thread Rich Megginson
On 12/12/2013 11:55 AM, Alberto Viana wrote: I found the root cause, it's happens when I change a user from one OU to another on my windows side. Is that an expected behavior? sounds like https://fedorahosted.org/389/ticket/355 On Thu, Dec 12, 2013 at 3:47 PM, Alberto Viana

Re: [389-users] group issues

2013-12-12 Thread Rich Megginson
that I modified the OU. Am I clear enough? Yes. If you can reproduce the issue with 1.2.11, please file a ticket. Thanks On Thu, Dec 12, 2013 at 5:02 PM, Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com wrote: On 12/12/2013 11:55 AM, Alberto Viana wrote: I found

Re: [389-users] unstable 389 in Fedora 20 - a time for epoch bump?

2013-12-13 Thread Rich Megginson
On 12/13/2013 02:44 AM, Petr Spacek wrote: Hello list, I'm sorry for nagging you, but Fedora 20 release day is coming and I have experienced serious issues with 389-ds-base-1.3.2.8-1.fc20.x86_64. https://fedorahosted.org/389/ticket/47629 Would it be worth to build a 389-ds-base-1.3.1 for

Re: [389-users] DS+SSL Start up Errors...

2014-01-06 Thread Rich Megginson
On 12/22/2013 08:15 PM, David Barr wrote: Good Morning! I’m working my way through http://directory.fedoraproject.org/wiki/Howto:SSL trying to create the certificates with OpenSSL, and then get them added to the NSS database. Most of that is fine. It’s only at the end that the directory

Re: [389-users] Upgraded to RHDS 9.1 but Console is Still Looking for 9.0 JAR

2014-01-08 Thread Rich Megginson
On 01/08/2014 10:31 AM, Paul Whitney wrote: Hi, I recently updated RHDS 9.0 servers to 9.1. I am getting mixed results with the update. Steps taken: 1. Stop all dirsrv and dirsrv-admin services 2. Executed yum localupdate *.rpm 3. After the yum completes. Execute setup-ds.pl --debug

Re: [389-users] ACI warnings in error log

2014-01-13 Thread Rich Megginson
On 01/13/2014 07:27 AM, Chris Chatfield wrote: Hi, I'm seeing a similar situation as was described in the mailing list message errors log - NSACLPlugin - acllas__client_match_URL: from Feb 2013. The final result of this was a suggestion to file a ticket. As far as I can see this wasn't done.

Re: [389-users] How to specify number of hashing iterations for a password

2014-01-15 Thread Rich Megginson
On 01/15/2014 10:38 AM, Richard Mixon wrote: During the bind process is there anyway to tell 389 directory server to hash a plaintext password n (multiple) times before trying to compare to what is stored? I am trying to implement something similar to what's described in this article:

Re: [389-users] How to specify number of hashing iterations for a password

2014-01-15 Thread Rich Megginson
? No. Nathan, I have a background in C, but do mostly Java these days. I will take a look at ticket 397 and get back to you if it's something I could work on. Can you provide me the pointers you were referring to? Thank you - Richard On Wed, Jan 15, 2014 at 11:25 AM, Rich Megginson rmegg

Re: [389-users] How to specify number of hashing iterations for a password

2014-01-15 Thread Rich Megginson
referring to? Thank you - Richard On Wed, Jan 15, 2014 at 11:25 AM, Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com wrote: On 01/15/2014 10:38 AM, Richard Mixon wrote: During the bind process is there anyway to tell 389 directory server to hash a plaintext password n

Re: [389-users] Only username as bind dn

2014-01-16 Thread Rich Megginson
On 01/16/2014 07:48 AM, Paolo Barbato wrote: Hi Rich, On 16/gen/2014, at 15:28, Rich Megginson rmegg...@redhat.com wrote: On 01/16/2014 12:56 AM, Paolo Barbato wrote: Thanks for replies, I think I need to better describe what I'm testing. As I said I've a central repository for credentials

Re: [389-users] Password synchronisation beetween openldap and AD 2008 R2

2014-01-16 Thread Rich Megginson
On 01/16/2014 07:57 AM, Louis-Marie Plumel wrote: Hello, Actually , i work with openldap. I've installed an AD 2008 R2.My challenge is to work with both and synchronise LDAP and AD 2008 R2. After a long research on the web, i don't find any information about howto synchronise passwords .

Re: [389-users] Password synchronisation beetween openldap and AD 2008 R2

2014-01-16 Thread Rich Megginson
mailto:pspa...@redhat.com On 16.1.2014 15:59, Rich Megginson wrote: On 01/16/2014 07:57 AM, Louis-Marie Plumel wrote: Hello, Actually , i work with openldap. I've installed an AD 2008 R2.My challenge is to work with both

Re: [389-users] Only username as bind dn

2014-01-16 Thread Rich Megginson
On 01/16/2014 08:13 AM, Paolo Barbato wrote: On 16/gen/2014, at 15:52, Rich Megginson rmegg...@redhat.com wrote: On 01/16/2014 07:48 AM, Paolo Barbato wrote: Hi Rich, On 16/gen/2014, at 15:28, Rich Megginson rmegg...@redhat.com wrote: On 01/16/2014 12:56 AM, Paolo Barbato wrote: Thanks

Re: [389-users] Naming conflict on hub/consumer

2014-01-21 Thread Rich Megginson
On 01/21/2014 10:47 AM, Colin Tulloch wrote: Hi All – We had a bundle of problems with our MM/consumer setup. Ran of out FDs on the consumers, had the slapd process on a master die, etc. Platform? 389-ds-base version? rpm -q 389-ds-base We’re getting things back up and running

Re: [389-users] Naming conflict on hub/consumer

2014-01-21 Thread Rich Megginson
] *On Behalf Of *Rich Megginson *Sent:* Tuesday, January 21, 2014 1:33 PM *To:* General discussion list for the 389 Directory server project. *Subject:* Re: [389-users] Naming conflict on hub/consumer If the answers given below are not satisfactory, please file tickets for all of these issues

Re: [389-users] Naming conflict on hub/consumer

2014-01-21 Thread Rich Megginson
, or theres something else. Why would it be limited to 700? *From:*389-users-boun...@lists.fedoraproject.org [mailto:389-users-boun...@lists.fedoraproject.org] *On Behalf Of *Rich Megginson *Sent:* Tuesday, January 21, 2014 3:12 PM *To:* General discussion list for the 389 Directory server

Re: [389-users] Naming conflict on hub/consumer

2014-01-21 Thread Rich Megginson
...@lists.fedoraproject.org [mailto:389-users-boun...@lists.fedoraproject.org] *On Behalf Of *Rich Megginson *Sent:* Tuesday, January 21, 2014 4:46 PM *To:* General discussion list for the 389 Directory server project. *Subject:* Re: [389-users] Naming conflict on hub/consumer On 01/21/2014 02:45 PM, Colin Tulloch

Re: [389-users] Naming conflict on hub/consumer

2014-01-21 Thread Rich Megginson
of the sed to get it working properly. *From:*389-users-boun...@lists.fedoraproject.org [mailto:389-users-boun...@lists.fedoraproject.org] *On Behalf Of *Rich Megginson *Sent:* Tuesday, January 21, 2014 5:24 PM *To:* General discussion list for the 389 Directory server project. *Subject:* Re

Re: [389-users] Naming conflict on hub/consumer

2014-01-22 Thread Rich Megginson
consumers to masters, and replicated to them. *From:*389-users-boun...@lists.fedoraproject.org [mailto:389-users-boun...@lists.fedoraproject.org] *On Behalf Of *Rich Megginson *Sent:* Wednesday, January 22, 2014 9:36 AM *To:* General discussion list for the 389 Directory server project. *Subject

Re: [389-users] db2index on RHDS 9.1

2014-01-30 Thread Rich Megginson
On 01/30/2014 10:17 AM, David Boreham wrote: On 1/30/2014 10:18 AM, Paul Whitney wrote: rpm -q 389-ds-base 389-ds-base-1.2.11.15-30.el6_5.x86_64 No errors, just a status: reindex userRoot: Processed 315000 entries (pass 11) -- avg rate 15283456.5/sec, recent rate 0.0/sec. hit ration 0%

Re: [389-users] db2index on RHDS 9.1

2014-01-30 Thread Rich Megginson
and/or configuration that is causing problems? Paul M. Whitney E-mail: paul.whit...@mac.com On Jan 30, 2014, at 12:48 PM, Rich Megginson rmegg...@redhat.com wrote: On 01/30/2014 10:17 AM, David Boreham wrote: On 1/30/2014 10:18 AM, Paul Whitney wrote: rpm -q 389-ds-base 389-ds-base-1.2.11.15-30.el6_5

Re: [389-users] replication error

2014-02-10 Thread Rich Megginson
On 02/07/2014 10:16 PM, Elizabeth Jones wrote: Hi - I have just encountered a replication error on our 389DS. We are running Version 1.2.10.12 Build number 2012.180.1623. We had the following error earlier today from our ldap1 server (running multimaster) - 07/Feb/2014:13:06:52 -0600]

Re: [389-users] replication error

2014-02-10 Thread Rich Megginson
On 02/10/2014 02:40 PM, Elizabeth Jones wrote: It's going to be practically impossible to support 1.2.10. Can you upgrade to 1.2.11? I'm heading that way right now. I found a bug on redhat that looks like it is exactly what I'm running into --

Re: [389-users] Searches Hang - Apparently entryrdn index related

2014-02-12 Thread Rich Megginson
On 02/11/2014 10:32 PM, Timothy Pollard wrote: Hi, After our LDAP instance has been running for a while large LDAP searches in our userRoot start hanging. This appears to be caused by the entryrdn index becoming corrupt since it can be fixed by regenerating the entryrdn index. To give an

Re: [389-users] replication stopped after server restart - problem to reenable

2014-02-12 Thread Rich Megginson
/Red_Hat_Directory_Server/9.0/html/Administration_Guide/Managing_Replication-Configuring-Replication-cmd.html I've added some more information and logs below. On 2014-02-12 18:04, Rich Megginson wrote: On 02/12/2014 06:29 AM, Jan Kowalsky wrote: Version and platform please - rpm -q 389-ds-base yes, sorry, I

Re: [389-users] replication stopped after server restart - problem to reenable

2014-02-14 Thread Rich Megginson
On 02/14/2014 01:57 PM, Jan Kowalsky wrote: On 2014-02-13 15:12, Rich Megginson wrote: On 02/13/2014 02:05 AM, Jan Kowalsky wrote: On 2014-02-12 23:25, Rich Megginson wrote: On 02/12/2014 02:34 PM, Jan Kowalsky wrote: Hi Rich, Not sure what version 1.2.11.15-1 is on Debian

Re: [389-users] paged results on large results sets and memory

2014-02-14 Thread Rich Megginson
doesn't necessarily help with the memory usage. this would be the answer i am looking for. /mrg On Feb 14, 2014, at 4:13 PM, Rich Megginson rmegg...@redhat.com wrote: On 02/14/2014 02:04 PM, Michael Gettes wrote: I did some searching to try and answer the following question and the answer

<    1   2   3   4   5   6   7   8   9   >