Re: [389-users] replication stopped after server restart - problem to reenable

2014-02-14 Thread Rich Megginson
On 02/14/2014 04:43 PM, Jeroen van Meeuwen (Kolab Systems) wrote: On 2014-02-12 23:25, Rich Megginson wrote: Not sure what version 1.2.11.15-1 is on Debian. If it is the same as the upstream 1.2.11.15, that's very old. Should see if you can get them to provide 1.2.11.25 or later. It's

Re: [389-users] replication stopped after server restart - problem to reenable

2014-02-14 Thread Rich Megginson
On 02/14/2014 05:20 PM, Jeroen van Meeuwen (Kolab Systems) wrote: On 2014-02-14 23:03, Jan Kowalsky wrote: On 2014-02-14 22:15, Rich Megginson wrote: On 02/14/2014 01:57 PM, Jan Kowalsky wrote: Maybe I have to mention that there are some extra schemas used by kolab - namely the kolab2 schema

Re: [389-users] Setting up sub-suffix on 1.2.11.15-31 (CentOS 6.5)

2014-02-18 Thread Rich Megginson
On 02/18/2014 02:52 PM, Brian Epstein wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello 389-users, I recently setup two new 389-ds servers in a multi-master replicated pair. I am only replicating the userRoot database at this time. Everything is working well, SSL is

Re: [389-users] Setting up sub-suffix on 1.2.11.15-31 (CentOS 6.5)

2014-02-19 Thread Rich Megginson
On 02/19/2014 12:38 PM, Brian Epstein wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Rich and 389-users, I followed the directions on the page you had sent,

Re: [389-users] Fwd: I'm about to start coding a plugin for Heimdal Kerberos V and have a question

2014-02-20 Thread Rich Megginson
On 02/20/2014 03:11 PM, Paul Robert Marino wrote: I tried asking this on the developer list and didn't get an answer There is no good answer, which is probably why no one replied . . . so im trying the user list now So here is my goal I am about to write a plugin for Heimdal KDC's to update

Re: [389-users] 389DS on SD-Card

2014-02-24 Thread Rich Megginson
On 02/24/2014 01:16 PM, hede wrote: Hi all, I'm planning to use 389ds from SD-Card. So I would like to minimise write I/O. It's absolutely fine if there's only a consistent state saved once a day. For example via some cronjob running ns-slapd db2archive (which I've done so far). I do not

Re: [389-users] One supplier; two consumers : how to enable replication of Account Lockout policy attributes?

2014-02-24 Thread Rich Megginson
On 02/24/2014 02:33 PM, Jon Detert wrote: - Original Message - From: Rich Megginson rmegg...@redhat.com To: General discussion list for the 389 Directory server project. 389-users@lists.fedoraproject.org Sent: Monday, February 24, 2014 2:48:38 PM Subject: Re: [389-users] One supplier

Re: [389-users] Fwd: I'm about to start coding a plugin for Heimdal Kerberos V and have a question

2014-02-27 Thread Rich Megginson
On 02/26/2014 11:01 PM, Paul Robert Marino wrote: sorry for the delayed response I'm on vacation so I haven't been checking my email regularly. On Thu, Feb 20, 2014 at 5:15 PM, Rich Megginson rmegg...@redhat.com wrote: On 02/20/2014 03:11 PM, Paul Robert Marino wrote: I tried asking

Re: [389-users] ACL processing

2014-02-27 Thread Rich Megginson
in logconv.pl, then turning on access logging for internal searches should show those unindexed internal searches, which should show up using logconv.pl Thanks, Russ. On Feb 27, 2014, at 1:19 PM, Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com wrote: On 02/27/2014 12:49 PM

Re: [389-users] Synchronizing with Active Directory

2014-02-28 Thread Rich Megginson
On 02/28/2014 12:46 PM, Riss Nicolas wrote: Hi, We are making some test in order to synchronize 389 Directory with an Active Directory. We don’t install pass sync because we need only to synchronize password from the 389 Directory instance. Everything works well, but when we analyze the

Re: [389-users] ACL processing

2014-03-03 Thread Rich Megginson
show up in logconv.pl, then turning on access logging for internal searches should show those unindexed internal searches, which should show up using logconv.pl Thanks, Russ. On Feb 27, 2014, at 1:19 PM, Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com wrote: On 02/27/2014 12

Re: [389-users] Some bind DNs sporadically can't search users

2014-03-03 Thread Rich Megginson
On 03/03/2014 08:56 AM, Morgan Jones wrote: We're pulling our hair out over this issue and wondering if it rings a bell for anyone or perhaps there's a bug fix in a later version of 389 that might resolve it. I've looked and not found anything but it's also not the easiest issue to search

Re: [389-users] Some bind DNs sporadically can't search users

2014-03-03 Thread Rich Megginson
On 03/03/2014 12:05 PM, Morgan Jones wrote: On Mar 3, 2014, at 11:24 AM, Rich Megginson rmegg...@redhat.com wrote: On 03/03/2014 08:56 AM, Morgan Jones wrote: We're pulling our hair out over this issue and wondering if it rings a bell for anyone or perhaps there's a bug fix in a later

Re: [389-users] Kerberized admin server

2014-03-04 Thread Rich Megginson
On 03/04/2014 10:26 AM, Paul Robert Marino wrote: On Tue, Mar 4, 2014 at 12:13 PM, Rich Megginson rmegg...@redhat.com wrote: On 03/04/2014 09:16 AM, Paul Robert Marino wrote: hello I know there use to be a document on doing this because I did it several years ago at a previous job but I cant

Re: [389-users] Point to multiple LDAP servers

2014-03-05 Thread Rich Megginson
On 03/05/2014 01:22 PM, Chaudhari, Rohit K. wrote: Hello, I want to configure authconfig-tui on Red Hat to point to multiple 389 servers (in case one went inaccessible, the clients would automatically point to the 2nd or 3rd or 4th, etc. server). 1.How do I do this? 2.How would my /etc/hosts

Re: [389-users] sasl/gssapi issue

2014-03-06 Thread Rich Megginson
On 03/06/2014 03:13 PM, Robert Viduya wrote: We're trying to get GSSAPI authentication working with 389 and following the doc page on the website, I think I've gotten it working a little too well. We're using the stock ldapsearch command that comes with RHN, I believe it's from openldap.

Re: [389-users] multi-master changelog, tombstone entries

2014-03-10 Thread Rich Megginson
On 03/08/2014 01:21 AM, Vesa Alho wrote: Hi, 1. replication changelog I've been running multi-master replication setup for a while and realised hadn't configured expiration (changelog max age). Now my changelog file is rather big and I would like get size down. I'm planning to delete

Re: [389-users] Non-contiguous attribute values

2014-03-10 Thread Rich Megginson
On 03/10/2014 08:33 PM, Timothy Pollard wrote: On Mon, 10 Mar 2014 18:41:35 -0600 Rich Megginson rmegg...@redhat.com wrote: On 03/10/2014 04:14 PM, Timothy Pollard wrote: Hi, We received this strange error a few hours ago for one of our DNS entries: [10/Mar/2014:15:56:01 +

Re: [389-users] Non-contiguous attribute values

2014-03-10 Thread Rich Megginson
On 03/10/2014 08:42 PM, Timothy Pollard wrote: A small update; we're now Now as opposed to some time in the past? At what point did you begin seeing these messages, and what changed? seeing this error every four minutes (which is how often the update cron job runs) in the error log:

Re: [389-users] problem on Sparc with DS 1.3.2: Skipping entry ... which has no parent

2014-03-11 Thread Rich Megginson
On 03/11/2014 05:57 AM, Carsten Grzemba wrote: interessting: it is only on 32bit build. 64bit build on Solaris10 Sparc works as expected. I'm not sure. I guess we could try to reproduce on Fedora 32-bit. -- 389 users mailing list 389-users@lists.fedoraproject.org

Re: [389-users] Non-contiguous attribute values

2014-03-11 Thread Rich Megginson
On 03/10/2014 09:17 PM, Timothy Pollard wrote: On Mon, 10 Mar 2014 20:56:08 -0600 Rich Megginson rmegg...@redhat.com wrote: On 03/10/2014 08:42 PM, Timothy Pollard wrote: A small update; we're now Now as opposed to some time in the past? At what point did you begin seeing these messages

Re: [389-users] problem on Sparc with DS 1.3.2: Skipping entry ... which has no parent

2014-03-11 Thread Rich Megginson
On 03/11/2014 07:32 AM, Carsten Grzemba wrote: Am 11.03.14 schrieb *Rich Megginson * rmegg...@redhat.com: On 03/11/2014 05:57 AM, Carsten Grzemba wrote: interessting: it is only on 32bit build. 64bit build on Solaris10 Sparc works as expected. I'm not sure. I guess we could try

Re: [389-users] problem on Sparc with DS 1.3.2: Skipping entry ... which has no parent

2014-03-11 Thread Rich Megginson
On 03/11/2014 08:02 AM, Carsten Grzemba wrote: Am 11.03.14 schrieb *Rich Megginson * rmegg...@redhat.com: On 03/11/2014 07:32 AM, Carsten Grzemba wrote: Am 11.03.14 schrieb *Rich Megginson * rmegg...@redhat.com mailto:rmegg...@redhat.com: On 03/11/2014 05:57 AM, Carsten Grzemba wrote

Re: [389-users] Non-contiguous attribute values

2014-03-11 Thread Rich Megginson
On 03/11/2014 04:09 PM, Timothy Pollard wrote: On Tue, 11 Mar 2014 07:17:25 -0600 Rich Megginson rmegg...@redhat.com wrote: On 03/10/2014 09:17 PM, Timothy Pollard wrote: On Mon, 10 Mar 2014 20:56:08 -0600 Rich Megginson rmegg...@redhat.com wrote: On 03/10/2014 08:42 PM, Timothy Pollard wrote

Re: [389-users] DS 1.3.2.14 on Sparc: Authentication method not supported

2014-03-12 Thread Rich Megginson
On 03/12/2014 03:25 AM, Carsten Grzemba wrote: some tests later I stumble in this problem: [14/03/12:10:03:41] - [Setup] Info Could not authenticate as user 'uid=admin,ou=Administrators,ou=TopologyManagement,o=NetscapeRoot' to server 'ldap://testcsw.contac.lan:389/o=NetscapeRoot'. Error:

Re: [389-users] 389-console problem restore backup

2014-04-02 Thread Rich Megginson
On 04/02/2014 02:50 AM, Carsten Grzemba wrote: If I try to restore backups I get the error: error:could not read config file. In the console log I see: http://testcsw.contac.lan:2389/[1:0] recv error: could not read config file. http://testcsw.contac.lan:2389/[1:0] recv system_errno: 13

Re: [389-users] git repo / tarball issues

2014-04-03 Thread Rich Megginson
On 04/03/2014 07:06 AM, Timo Aaltonen wrote: Hi It's me again :) 1) 389-ds-console 1.2.7 has no tarball though it was tagged for release in Sep'12 2) 389-adminutil 1.1.20 is not tagged in git Looks like it is, according to https://git.fedorahosted.org/cgit/389/adminutil.git/

Re: [389-users] 1.2.11.29 prediction?

2014-04-03 Thread Rich Megginson
On 04/03/2014 08:53 AM, Michael Gettes wrote: Hi all, I recognize 389 is a community project and asking for timelines can be problematic. Right now, I am sorta stuck between a rock and a hard place. In production, I am on 1.2.11.15 which has problems that are fixed by 1.2.11.28. I have

Re: [389-users] 1.2.11.29 prediction?

2014-04-03 Thread Rich Megginson
On 04/03/2014 09:30 AM, Michael Gettes wrote: On Apr 3, 2014, at 11:13 AM, Rich Megginson rmegg...@redhat.com wrote: On 04/03/2014 08:53 AM, Michael Gettes wrote: Hi all, I recognize 389 is a community project and asking for timelines can be problematic. Right now, I am sorta stuck between

Re: [389-users] epel-389-ds-base not updated with 389-ds-base-1.2.11.28

2014-04-03 Thread Rich Megginson
On 04/03/2014 11:16 AM, Orion Poplawski wrote: On 04/02/2014 03:45 PM, Noriko Hosoi wrote: Orion Poplawski wrote: The epel-389-ds-base repo has not been updated with 389-ds-base-1.2.11.28, which according to https://admin.fedoraproject.org/updates/FEDORA-EPEL-2014-0834 is an important

Re: [389-users] Is it safe to downgrade?

2014-04-03 Thread Rich Megginson
On 04/03/2014 12:09 PM, Orion Poplawski wrote: We're looking to downgrade 389-ds-base from 1.2.11.28-1.el5 to 1.2.9.9-1.el5. I know that various schema updates and the like happen on upgrades, but I don't know about what happens in the downgrade case. I'm not sure either. Thanks for any

Re: [389-users] 1.2.11.29 prediction?

2014-04-04 Thread Rich Megginson
On 04/04/2014 01:04 PM, Morgan Jones wrote: On Apr 3, 2014, at 5:11 PM, Rich Megginson rmegg...@redhat.com wrote: On 04/03/2014 02:56 PM, Morgan Jones wrote: On Apr 3, 2014, at 3:39 PM, Rich Megginson rmegg...@redhat.com wrote: On 04/03/2014 01:35 PM, Michael Gettes wrote: Yeah, I hear

[389-users] Source directory is now list-able

2014-04-07 Thread Rich Megginson
http://port389.org/sources is now open and list-able. The default sort order is latest first. The http://port389.org/wiki/Source page has been updated with this link. -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users

Re: [389-users] [389-devel] Source directory is now list-able

2014-04-08 Thread Rich Megginson
On 04/08/2014 02:24 PM, Timo Aaltonen wrote: On 07.04.2014 21:52, Rich Megginson wrote: http://port389.org/sources is now open and list-able. The default sort order is latest first. The http://port389.org/wiki/Source page has been updated with this link. \o/ many thanks for this :) Sure

Re: [389-users] [389][Active Directory] Replication issue

2014-04-14 Thread Rich Megginson
On 04/14/2014 02:49 AM, Moisés Barba Pérez wrote: Hello, Unfortunately in our organization we have a replication agreement between 389 DS and an Active Directory. For some reason, some Active Directory admin has run a script which has change the givenname and sn attrs (now they are in

Re: [389-users] [389][Active Directory] Replication issue

2014-04-14 Thread Rich Megginson
the trailing whitespace is not visible. I'm not sure how to get around that myself. Steven Crothers steven.croth...@gmail.com On Mon, Apr 14, 2014 at 9:58 AM, Rich Megginson rmegg...@redhat.com wrote: On 04/14/2014 02:49 AM, Moisés Barba Pérez wrote: Hello, Unfortunately in our organization we

Re: [389-users] Long distance replication

2014-04-14 Thread Rich Megginson
On 04/14/2014 03:00 PM, Elizabeth Jones wrote: Have any of you encountered issues with replication over long distances, such as between data centers? We have a master in each of our data centers and a consumer at each data center, but all changes are pretty much made at data center A and then

Re: [389-users] [389][Active Directory] Replication issue

2014-04-16 Thread Rich Megginson
#Troubleshooting In my case, I am not the AD admin and I would like to probe that some changes had been made in AD and replicated to 389DS. See above. Regards, Moses. 2014-04-15 15:44 GMT+02:00 Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com: On 04/15/2014 03:23 AM, Moisés Barba

Re: [389-users] SSL

2014-04-17 Thread Rich Megginson
Replying to list. On 04/17/2014 12:22 PM, Andy wrote: I am having an issue with securing Directory Server communication using SSL which I need guidance on how to solve. I am setting up a master and

Re: [389-users] glue entry problem

2014-04-22 Thread Rich Megginson
On 04/22/2014 03:07 PM, Elizabeth Jones wrote: I have all kinds of borkage in my ldap today. I created a new ou in one of my data centers, ou=cdc,ou=service accts,ou=staff,ou=people,dc=mycompany,dc=com under this I added 2 users. About 5 minutes later I got an alarm from my monitoring system

Re: [389-users] glue entry problem

2014-04-22 Thread Rich Megginson
On 04/22/2014 03:18 PM, Elizabeth Jones wrote: rpm -q 389-ds-base 389-ds-base-1.2.11.25-1.el6.x86_64 I strongly encourage you to use the version of 389-ds-base included with the base EL6 OS. If not, you might try upgrading to 1.2.11.29 from the copr repo http://port389.org/wiki/Download

Re: [389-users] Installing dsgw web interface

2014-04-23 Thread Rich Megginson
AJM-245 (609)485-4218 harry.dev...@faa.gov From: Rich Megginson rmegg...@redhat.com AJM-245, CARTS Software Safety To: General discussion list for the 389 Directory server project. 389-users@lists.fedoraproject.org, Date: 04/23/2014 02:02 PM Subject: Re: [389-users] Installing dsgw web

Re: [389-users] Export/Import: openldap-2.3.27 to 389-ds-1.2.2-1

2014-04-25 Thread Rich Megginson
On 04/25/2014 02:02 PM, Brian Arthur wrote: Hi, I’m trying to import an openldap-2.3.27 export into 389-ds-1.2.2-1 Note - 389-ds is just a meta package - please reference the version of 389-ds-base, which is the core LDAP server package. and am getting the follow errors in the “rejects”

Re: [389-users] Export/Import: openldap-2.3.27 to 389-ds-1.2.2-1

2014-04-28 Thread Rich Megginson
On 04/28/2014 11:24 AM, Brian Arthur wrote: *From:*Rich Megginson [mailto:rmegg...@redhat.com] *Sent:* Friday, April 25, 2014 2:02 PM *To:* General discussion list for the 389 Directory server project.; brianpatrickart...@gmail.com *Subject:* Re: [389-users] Export/Import: openldap-2.3.27

Re: [389-users] Failed to send extended operation: LDAP error -1 (Can't contact LDAP server)

2014-05-05 Thread Rich Megginson
On 05/05/2014 08:55 AM, Graham Leggett wrote: On 05 May 2014, at 11:37 AM, Graham Leggett minf...@sharp.fm wrote: It should be possible to add an N+1th replica to an N-node deployment. Replication agreements are peer-to-peer, so you just add a new replication agreement from each of the

Re: [389-users] dsgw not checking passwords during auth

2014-05-05 Thread Rich Megginson
On 05/05/2014 07:34 AM, Ted Strother wrote: I have a web server running dsgw which is pointing at an ldap instance on another server in the config. Searches work fine, actions tht require auth work fine when the password was correct. When an incorrect password is entered it is still accepted, a

Re: [389-users] Failed to send extended operation: LDAP error -1 (Can't contact LDAP server)

2014-05-05 Thread Rich Megginson
On 05/05/2014 09:39 AM, David Boreham wrote: On 5/5/2014 9:24 AM, Rich Megginson wrote: See https://fedorahosted.org/389/ticket/47606 This bug looks quite consistent with the OP's symptoms and the presence of a large group entry, but he should be seeing Incoming BER Element was too long

Re: [389-users] dsgw not checking passwords during auth

2014-05-05 Thread Rich Megginson
button and try again. If you have forgotten the password for this entry, a directory administrator must reset the password for you. Ok. Must be a regression. Please file a ticket. On Mon, May 5, 2014 at 11:26 AM, Rich Megginson rmegg...@redhat.com wrote: On 05/05/2014 07:34 AM, Ted Strother

Re: [389-users] Failed to send extended operation: LDAP error -1 (Can't contact LDAP server)

2014-05-05 Thread Rich Megginson
On 05/05/2014 10:13 AM, Graham Leggett wrote: On 05 May 2014, at 5:41 PM, Rich Megginson rmegg...@redhat.com wrote: See https://fedorahosted.org/389/ticket/47606 This bug looks quite consistent with the OP's symptoms and the presence of a large group entry, but he should be seeing Incoming

Re: [389-users] Failed to send extended operation: LDAP error -1 (Can't contact LDAP server)

2014-05-05 Thread Rich Megginson
On 05/05/2014 10:49 AM, Graham Leggett wrote: On 05 May 2014, at 6:24 PM, Rich Megginson rmegg...@redhat.com wrote: I think the problem is this: [05/May/2014:17:34:41 +0200] - import userRoot: WARNING: Skipping entry nsuniqueid=---,o=Foo,c=ZA which has

Re: [389-users] constraint averlay

2014-05-07 Thread Rich Megginson
On 05/06/2014 10:59 PM, rayane karim wrote: Hi All is constraint overlay implemented on DS like olcConstraintAttribute for attribute syntax checking like regex No. Regards Rayane -- 389 users mailing list 389-users@lists.fedoraproject.org

Re: [389-users] Yum Update vs Yum Upgrade

2014-05-20 Thread Rich Megginson
On 05/20/2014 10:58 AM, Fong, Trevor wrote: Hi Everyone, After taking over the LDAP service from a colleague, I updated the 389 DS service to the latest release by issuing a “yum update …”. Then when searching around the 389-ds documentation, I came across the install page that said that I

Re: [389-users] Account Lockout Policies

2014-05-20 Thread Rich Megginson
On 05/20/2014 11:43 AM, Dustin Rice wrote: Hello there, so I've been looking into setting up some account lockout policies in my enviroment. I have 2 multimaster 389ds servers with some 389ds consumer replicas. I've enable passwordIsGlobalPolicy in cn=config on all servers. So if an account

Re: [389-users] NSMMReplicationPlugin - changelog program - _cl5GetEntryCount: failed to get changelog statistics

2014-06-11 Thread Rich Megginson
On 06/11/2014 11:45 AM, Enrique Terrazas wrote: Hello, Fairly new to 389/LDAP. A brief setup backstory: Two servers in a mulit-master environment both running CentOS 5.8 and 389 DS 1.2.9.9 Not sure what the problem is, but it is going to be virtually impossible for us to support version

Re: [389-users] Removing entries with invalid DN syntax

2014-06-26 Thread Rich Megginson
On 06/26/2014 07:50 AM, Audun Røe wrote: Hello, I'm trying to delete some problematic entries from our 389 directory. The entry DNs contain and (probably found their way into the directory years ago). This causes problems with JNDI where DNs from search results are fed directly back into

Re: [389-users] Removing entries with invalid DN syntax

2014-06-26 Thread Rich Megginson
On 06/26/2014 07:59 AM, Rich Megginson wrote: On 06/26/2014 07:50 AM, Audun Røe wrote: Hello, I'm trying to delete some problematic entries from our 389 directory. The entry DNs contain and (probably found their way into the directory years ago). This causes problems with JNDI where DNs

Re: [389-users] Removing entries with invalid DN syntax

2014-06-26 Thread Rich Megginson
) but the server wouldn't start at all with this gone. Can't see any other attributes in dse.ldif that seem to apply. What is your version of 389-ds-base? rpm -q 389-ds-base -Audun On Thu, Jun 26, 2014 at 4:01 PM, Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com wrote: On 06/26

Re: [389-users] 1.3.2.16 Release version missing dependencies

2014-07-01 Thread Rich Megginson
On 07/01/2014 12:58 AM, Balaji P wrote: Hi , I’ve downloaded the 389 DS source “Release 1.3.2.16” from _http://port389.org/sources/389-ds-base-1.3.2.16.tar.bz2_. When trying to compile with configure and make options [trying to compile the code in CentOS6.5 final, I’ve a custom script to build

Re: [389-users] 1.2.11.30 ETA?

2014-07-03 Thread Rich Megginson
On 07/02/2014 08:13 PM, Timothy Pollard wrote: On Thu, 12 Jun 2014 17:05:24 -0400 Michael Gettes get...@gmail.com wrote: Kind 389 devs, i am on 1.2.11.29 and for my environment - it’s been great! I have been watching the tickets with respect to 1.2.11.30 and I am curious as to when this

Re: [389-users] 1.2.11.30 ETA?

2014-07-03 Thread Rich Megginson
On 07/03/2014 03:58 PM, Timothy Pollard wrote: On Thu, 03 Jul 2014 07:27:51 -0600 Rich Megginson rmegg...@redhat.com wrote: On 07/02/2014 08:13 PM, Timothy Pollard wrote: I'd also like to know if anyone has anything specific they could share about the intended release date of 1.2.11.30. I

Re: [389-users] Header menu display issue in DSGW

2014-07-07 Thread Rich Megginson
On 07/07/2014 06:54 AM, Dave Page wrote: Hi On Mon, Jul 7, 2014 at 1:38 PM, Vincent Gerris vger...@gmail.com wrote: If you mean that the layout is messed up, you are right. It is terrible and looks different on about any browser. I filed a bug for the ubuntu package where I found it too:

Re: [389-users] Error with usernames containing periods

2014-07-07 Thread Rich Megginson
On 07/07/2014 06:09 AM, Dave Page wrote: Hi I'm working on a PoC migration of an OpenLDAP infrastructure to 389. Our existing directory has periods in all of the usernames, e.g. dave.page. However, this seems to cause problems with the org chart interface, which complains with: . is not

Re: [389-users] 1.2.11.30 ETA?

2014-07-07 Thread Rich Megginson
On 07/03/2014 05:13 PM, Timothy Pollard wrote: On Thu, 03 Jul 2014 16:10:01 -0600 Rich Megginson rmegg...@redhat.com wrote: On 07/03/2014 03:58 PM, Timothy Pollard wrote: We're actually on CentOS 6. We'd be happy to use the standard distro version, but we're seeing a lot of crashes (about half

Re: [389-users] 1.2.11.30 ETA?

2014-07-07 Thread Rich Megginson
this for my test environment - which is somewhat active. If you think this would be helpful. Are you also running into these issues? /mrg On Jul 7, 2014, at 10:36 AM, Rich Megginson rmegg...@redhat.com wrote: On 07/03/2014 05:13 PM, Timothy Pollard wrote: On Thu, 03 Jul 2014 16:10:01 -0600 Rich

Re: [389-users] Header menu display issue in DSGW

2014-07-07 Thread Rich Megginson
at 4:02 PM, Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com wrote: On 07/07/2014 06:54 AM, Dave Page wrote: Hi On Mon, Jul 7, 2014 at 1:38 PM, Vincent Gerris vger...@gmail.com mailto:vger...@gmail.com wrote: If you mean that the layout

Re: [389-users] Error with usernames containing periods

2014-07-08 Thread Rich Megginson
On 07/08/2014 03:26 AM, Dave Page wrote: On Mon, Jul 7, 2014 at 3:03 PM, Rich Megginson rmegg...@redhat.com wrote: On 07/07/2014 06:09 AM, Dave Page wrote: Hi I'm working on a PoC migration of an OpenLDAP infrastructure to 389. Our existing directory has periods in all of the usernames, e.g

Re: [389-users] Leading/trailing spaces in password

2014-07-09 Thread Rich Megginson
On 07/09/2014 06:04 AM, David Kupka wrote: Hi! I encounter a problem with 389 Directory Server. When the password for Directory Manager contains leading and/or trailing spaces (' ', ASCII code 32) setup-ds.pl ignores them. I'm then able to authenticate with stripped password but not with the

Re: [389-users] 389 windows console

2014-07-11 Thread Rich Megginson
On 07/11/2014 03:17 PM, Ryan Ferguson wrote: When using the 389 windows console version 1.1.6 Posix Group is not displayed and we cannot view group members to add and remove from the group. However when using the linux console the Posix Group tab is available. Is this a known issue and is

Re: [389-users] synchronize 389DS uid with userPrincipalName from Active Directory

2014-07-22 Thread Rich Megginson
On 07/22/2014 04:05 AM, Mihai Carabas wrote: Hi, We are currently using 389-DS as a LDAP server for our university (University Politehnica from Bucharest). Right now we have about 35000 accounts created into the 389-DS. We need to synchronize all the accounts with an Active Directory server for

Re: [389-users] synchronize 389DS uid with userPrincipalName from Active Directory

2014-07-22 Thread Rich Megginson
On 07/22/2014 07:56 AM, Mihai Carabas wrote: On Tue, Jul 22, 2014 at 4:43 PM, Rich Megginson rmegg...@redhat.com wrote: On 07/22/2014 04:05 AM, Mihai Carabas wrote: Hi, We are currently using 389-DS as a LDAP server for our university (University Politehnica from Bucharest). Right now we have

Re: [389-users] DS SSL cfg

2014-07-22 Thread Rich Megginson
On 07/22/2014 03:17 PM, Isabella Ghiurea wrote: Hello List, I would like to know if DS can be cfg for TLS/SSL + CA connections later one or must to be done at installation time ? Later on. Set up without TLS/SSL, then configure later.

Re: [389-users] 389-console in rhel7

2014-07-24 Thread Rich Megginson
On 07/24/2014 01:18 AM, Pepe Charli wrote: Is 389-console available for rhel7? No, not yet. https://fedoraproject.org/wiki/EPEL/epel7/Requests#EPEL_Branch_Requests https://fedorahosted.org/389/ticket/47865 Thanks, -- 389 users mailing list 389-users@lists.fedoraproject.org

Re: [389-users] port 389 listener getting hung up on connection locks?

2014-07-25 Thread Rich Megginson
On 07/25/2014 07:59 AM, Thomas Walker wrote: On Thu, Jul 24, 2014 at 04:14:13PM -0400, Thomas Walker wrote: On Thu, Jul 24, 2014 at 01:50:39PM -0600, Rich Megginson wrote: Did the above make any significant difference with respect to the performance? The problem is definitely load related

Re: [389-users] password policy not deleted when user deleted

2014-08-05 Thread Rich Megginson
On 08/05/2014 12:23 PM, Elizabeth Jones wrote: Doing some experimenting with user password policies. I created an account and then applied a user level fine grained password policy on that account. Then I deleted the account. Then I recreated the account, and the fine grained password policy

Re: [389-users] ns-inactivate.pl

2014-08-13 Thread Rich Megginson
On 08/13/2014 12:09 PM, Elizabeth Jones wrote: I'm trying to use ns-inactivate.pl to deactivate user accounts, but I don't know how to get it to use port 636. It works fine on 389 but if I use -p 636 no dice. I dont see that there is a flag to tell it where to find the cert that it needs to

Re: [389-users] db2bak.pl issuess

2014-08-13 Thread Rich Megginson
On 08/13/2014 12:39 PM, Dan Lavu wrote: So directory manager is the *value* of the attribute, the attribute is CN (common name) the DN, what it's explicitly asking for is the Distinguished Name, which is the absolute location of the user in the directory you are trying to use. For example CN

Re: [389-users] Configuring interfaces?

2014-09-02 Thread Rich Megginson
On 09/02/2014 06:56 PM, David Barr wrote: Good Morning! I’m having a bad time finding documentation on how I would set up my 389-ds to only listen to localhost:389, and require all other connections to happen on port 636. The server is headless, so using the console is less than optimum. Has

Re: [389-users] Export the object definitions only

2014-09-10 Thread Rich Megginson
On 09/10/2014 06:48 AM, Rob Crittenden wrote: Ghiurea, Isabella wrote: Hi Gurus, I would like to know how can I export only the objects definitons aka :roles, ac's definitons not the DS data content, we would like to be able have a copy of definition for development purpose. Thank you Isabella

Re: [389-users] installing 389-ds-base-1.3.2.2 on CentOS using repositories

2014-09-16 Thread Rich Megginson
On 09/16/2014 08:45 AM, Vesa Alho wrote: On 16/09/14 15:02, Luigi Santangelo wrote: Hi all, I'm trying to install 389-ds-base 1.3.2.2 or higher on my Centos 6.5 Server because I need SyncRepl (released starting from that version). I installed epel Repo. Running yum install 389\*, the

Re: [389-users] installing 389-ds-base-1.3.2.2 on CentOS using repositories

2014-09-16 Thread Rich Megginson
On 09/16/2014 09:02 AM, Michael Gettes wrote: Rich, as i choose to be on the bleeding edge, is it a good or bad idea to run 1.3.3 on rhel 6? We have not built nor tested 1.3.3 on EL6, so I don't know. /mrg On Sep 16, 2014 8:54 AM, Rich Megginson rmegg...@redhat.com mailto:rmegg

Re: [389-users] No sample entries means no suffix/BaseDN?

2014-09-23 Thread Rich Megginson
On 09/23/2014 10:18 AM, David Barr wrote: Good morning! In the current EPEL version of 389-ds, if I go through config-ds-admin.pl, option 3, these questions are included: ``` Suffix [dc=localdomain]: Do you want to install the sample entries? [no]: Type the full path and filename, the word

Re: [389-users] register-ds-admin against external LDAP urls

2014-09-24 Thread Rich Megginson
On 09/24/2014 05:53 AM, Alan Willis wrote: The documentation for register-ds-admin.pl http://register-ds-admin.pl says the following: The register-ds-admin.pl http://register-ds-admin.pl script does not support external LDAP URLs, so the Directory Server instance must be registered against a

Re: [389-users] how to install the last 389-ds-1.3.3 on SL

2014-09-24 Thread Rich Megginson
On 09/24/2014 03:08 PM, Ghiurea, Isabella wrote: I'm running Scientific Linux release 6.5,base4.0-amd64, I have 389-ds -1.2.2-1.el6 package installed using yum , I can 't get the last version 389-ds-1.3.3 via yum installed , what I'm missing? You are missing 389-ds-base-1.3.3.x. There is no

Re: [389-users] 389-users Digest, Vol 112, Issue 16 : How to install the last 389-ds-1.3.3 on SL (Ghiurea, Isabella

2014-09-25 Thread Rich Megginson
it is more specific than Re: Contents of 389-users digest... Today's Topics: 1. Re: register-ds-admin against external LDAP urls (Rich Megginson) 2. DS SSL -CA replication and clients (Ghiurea, Isabella) 3. how to install the last 389-ds-1.3.3 on SL (Ghiurea, Isabella) 4. Re: how

Re: [389-users] 389-console: Directory Server entry disappeared from Server Group - how can I get it back?

2014-09-26 Thread Rich Megginson
On 09/26/2014 12:51 AM, Ray wrote: Hi there, I recently had a permission issue which denied write access to all of 389's directories to the user running 389 (in my case nobody). This lead to corrupted Berkeley DBs (which I fixed by exporting them one by one with db_dump and then re-creating

Re: [389-users] upgrade 389ds-base 1.2.2. to last release

2014-09-26 Thread Rich Megginson
On 09/26/2014 11:48 AM, Ghiurea, Isabella wrote: Hi, I'm runing SL6.5, I have installed but not cfg 389-ds-1.2.2-1.el6.noarch package , next we build from source code rpm389-ds-base-cadc-1.3.3.3-sl6_00.x86_64, got installed in /opt/dirsrv., when start setup-ds-admin .pl ( is still showing

Re: [389-users] upgrade 389ds-base 1.2.2. to last release

2014-09-26 Thread Rich Megginson
On 09/26/2014 01:04 PM, Ghiurea, Isabella wrote: HI Rich, see this most of ds packages are gome now the setup-ds-admin .pl can't be run: ( I 'm not sure all this packages removed are in last tar ball realese also) yum erase 389\* idm-console-framework Loaded plugins: dellsysid,

Re: [389-users] How relevant is Poodlebleed Bug to 389?

2014-10-15 Thread Rich Megginson
On 10/15/2014 08:16 AM, Jan Tomasek wrote: Hello, is http://poodlebleed.com/ related to 389? I think it is, this is not implementation flaw in OpenSSL, this seems to be related to the SSLv3 design. I've found: http://directory.fedoraproject.org/docs/389ds/design/nss-cipher-design.html

Re: [389-users] RHEL / CentOS 7

2014-10-15 Thread Rich Megginson
On 10/15/2014 04:00 PM, Gordon Messmer wrote: What's the status of 389 DS on RHEL 7? Not available yet. No time frame. Perhaps around RHEL 7.1. If you are a Red Hat customer, ask support. As I recall, when Red Hat originally started shipping 389-ds-base it lacked replication and windows

Re: [389-users] 389 console

2014-10-15 Thread Rich Megginson
On 10/15/2014 04:26 PM, Ghiurea, Isabella wrote: HI List, I need to know how can I add a second host entry to 389 UI Admin console under same Admin Domain , I already have an Admin domain :mytest.com and host name server1.org.com , need to add another server2.org.com same domain . You

Re: [389-users] 389 console

2014-10-15 Thread Rich Megginson
On 10/15/2014 04:55 PM, Ghiurea, Isabella wrote: Thank you Rich, I did that but I'm back to server1 ujsing 389UI Admin console and can't see the second host: server2.org , do I need to to register or reboot anything ? setup-ds-admin.pl should have done that for you if you correctly

Re: [389-users] 389 console

2014-10-16 Thread Rich Megginson
to re-create only the admin server cfg part and keep my existing ds instance on second host? You might be able to use register-ds-admin.pl Thank you Rich Isabella From: Rich Megginson [rmegg...@redhat.com] Sent: Wednesday, October 15, 2014 7:03 PM

Re: [389-users] How relevant is Poodlebleed Bug to 389?

2014-10-17 Thread Rich Megginson
), Cipher is (NONE) Then SSLv3 is disabled. If the s_client output looks like this: New, TLSv1/SSLv3, Cipher is AES128-SHA and it's waiting for input, then SSLv3 is enabled! Have a nice day, Paul On 2014-10-15 20:20, Rich Megginson wrote: On 10/15/2014 12:34 PM, Michael Gettes wrote: Hi David

Re: [389-users] Regarding patch availability for RHBA-2014:1623-1

2014-10-17 Thread Rich Megginson
On 10/17/2014 07:58 AM, Balaji P wrote: Hi While analyzing this problem we noticed this issue is released for RHEL in version 1.2.11.15 version. Is it possible to deliver the fix in 1.2.8.2 The 389 team is not going to do this. and 1.2.11.32 streams? There isn't a 1.2.11.32 stream.

Re: [389-users] stable packages for Centos 7

2014-10-20 Thread Rich Megginson
On 10/20/2014 04:48 AM, Angel Bosch wrote: can someone give me some light on this issue? I'm getting some presure from my direct bosses and I need all info I can get to evaluate our DS environment for next year. There should be some pre-built and supported 389 packages available for EL7

Re: [389-users] Error code 51 and replication errors

2014-10-22 Thread Rich Megginson
On 10/22/2014 09:54 AM, Shilen Patel wrote: Hi, I’m running 1.2.11.32. What is output of rpm -q 389-ds-base? I have 6 replicas (two of which are read-only). I ran into an issue where a DELETE operation failed on a server with error code 51 (ldap busy). [21/Oct/2014:23:44:44 -0400]

Re: [389-users] Error code 51 and replication errors

2014-10-22 Thread Rich Megginson
. These are really only for those users who needed critical fixes or features not yet in the supported EL6.6 version. I don't know if that will fix your problem, but it will make it a lot easier to support. Thanks! — Shilen From: Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com Reply-To: 389

Re: [389-users] Error code 51 and replication errors

2014-10-22 Thread Rich Megginson
. As for this particular problem, see https://fedorahosted.org/389/ticket/47409 Thanks! — Shilen From: Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com Reply-To: 389-users@lists.fedoraproject.org mailto:389-users@lists.fedoraproject.org 389-users@lists.fedoraproject.org mailto:389-users

Re: [389-users] Error code 51 and replication errors

2014-10-22 Thread Rich Megginson
as 1.2.11.15-47? No. -47 has a lot more bug fixes. If so, I’ll check out 1.2.11.15-34 in 6.5. Otherwise, I’ll upgrade to 6.6 first. Appreciate the help. Thanks! — Shilen From: Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com Reply-To: 389-users@lists.fedoraproject.org mailto

Re: [389-users] Solaris 5.2 DS replicate to 389 DS

2014-11-02 Thread Rich Megginson
On 11/02/2014 02:22 PM, Gary Algier wrote: Hello, I am looking for help with creating a replication agreement between a Solaris DS and a 389 DS. I says in the FAQ: Sun DS 5.2 changed the replication protocol, so you

<    2   3   4   5   6   7   8   9   >