[Fedora-directory-users] Connect Active Directory to my LDAP

2007-03-30 Thread Michiel van Heukelom - Van Boxtel Software BV
I've got the Fedora LDAP service running, connecting from other Linux server is no problem. the next step is to sunchronize the database to Active Directory. Is there a way to keep my Fedora LDAP as a master database and the AD server (W2003) as a member. So that i should only configure my

Re: [Fedora-directory-users] Connect Active Directory to my LDAP

2007-03-30 Thread Paulo Estrela - Suporte LabInfo UNIFACS
Hi, Did you enable SSL on FDS and AD? It must be enabled for sync works. Information is avaiable on FDS documentation page. Paulo Estrela - Original Message - From: Michiel van Heukelom - Van Boxtel Software BV To: fedora-directory-users@redhat.com Sent: Friday, March 30,

Re: [Fedora-directory-users] Fedora Directry as a domain controller

2007-03-30 Thread Josh Kelley
On 3/27/07, Peter Biggerstaff [EMAIL PROTECTED] wrote: Is it possible to use Fedora DS as a windows PDC? so I can manage windows and Linux clients from the same directory? FDS by itself cannot serve as a Windows PDC; that's well outside the scope of what it's designed to do. Samba is

Re: [Fedora-directory-users] Connect Active Directory to my LDAP

2007-03-30 Thread Alexandre Augusto da Rocha
This is not true. You don't need SSL if AD will be a true slave. SLL is only required if you want to allow users to change their passwords on AD and have that propagated to FDS. -Auggy Paulo Estrela - Suporte LabInfo UNIFACS wrote: Hi, Did you enable SSL on FDS and AD? It must be enabled

[Fedora-directory-users] Comments on the setupssl.sh enabling SSL script

2007-03-30 Thread Andy Schofield
Well, I have succeeding in getting SSL going and the howto is very helpful for this: http://directory.fedora.redhat.com/wiki/Howto:SSL and in particular the script: setupssl.sh http://directory.fedora.redhat.com/download/setupssl.sh In doing so I came across a number of gotchas which might help

Re: [Fedora-directory-users] db_verify

2007-03-30 Thread Ville Silventoinen
Hi Noriko, thanks for you reply. On Thu, 29 Mar 2007, Noriko Hosoi wrote: Ville Silventoinen wrote: Same error for ancestorid.db4, objectclass.db4, parentid.db4, cn.db4, givenName.db4 and sn.db4. How about id2entry.db4? Is it broken? (It's a primary db file.) No, id2entry.db4 is Good.

[Fedora-directory-users] ip in ACI bind rules

2007-03-30 Thread George Holbert
I've noticed that the 'ip' keyword in ACI bind rules seems to have no effect on its own. For example, This does not deny access to IP 1.2.3.4: aci: (version 3.0; acl Deny 1.2.3.4; deny(all) (ip = 1.2.3.4);) But when combined with a userdn clause like this, it works: aci: (version 3.0; acl

Re: [Fedora-directory-users] Connect Active Directory to my LDAP

2007-03-30 Thread Nathan Kinder
Alexandre Augusto da Rocha wrote: This is not true. You don't need SSL if AD will be a true slave. SLL is only required if you want to allow users to change their passwords on AD and have that propagated to FDS. Not exactly. You need SSL to allow passwords to be synchronized in either

Re: [Fedora-directory-users] db_verify

2007-03-30 Thread Noriko Hosoi
Ville Silventoinen wrote: Hi Noriko, thanks for you reply. On Thu, 29 Mar 2007, Noriko Hosoi wrote: [...] Is there a way to find out which entries are causing the problem? Can there be illegal characters in the entries? Could it be possible to share your data with us? (sample data would be

[Fedora-directory-users] virtual attributes in targetfilter

2007-03-30 Thread George Holbert
Under recent versions of FDS, is it OK to use virtual attributes (i.e., nsRole or CoS-generated) in ACI targetfilters? In earlier versions of Netscape DS, this was not recommended, and this is still mentioned in the RHDS 7.1 docs:

Re: [Fedora-directory-users] virtual attributes in targetfilter

2007-03-30 Thread Pete Rowley
George Holbert wrote: Are the docs just a little dated on this, or is it still not a good idea? I believe this warning was written before virtual attribute evaluation was added to the filter code (so searches etc. didn't work with virtual attributes) - that is no longer the case and hasn't

[Fedora-directory-users] Bad Ber Tag Encountered in log analysis

2007-03-30 Thread Philip Kime
I was looking through the logconv.pl output and I see that the majority of connection codes are B1 Bad Ber Tag Encountered Should I be worried about this? LDAP seems to be working fine and has been for months. PK -- Philip Kime NOPS Systems Architect 310 401 0407 --