Re: SyncRep - 1 provider : n co nsumer [auf Viren überprüft]

2005-06-24 Thread Howard Chu
Hans Moser wrote: Hi! Coming back to this - http://www.openldap.org/lists/openldap-software/200501/msg00375.html where Howard Chu said: In practice this requirement is of little value and is contrary to one of syncrepl's other design points - the provider is not supposed to need

Re: openldap 2.3 recommended bdb version

2005-06-27 Thread Howard Chu
library or the OpenLDAP code. It merely allows the library to release the transaction log files without requiring slapd to shutdown, so that you can use db_archive or DB_LOG_AUTOREMOVE. -- -- Howard Chu Chief Architect, Symas Corp. Director, Highland Sun http://www.symas.com

Re: smbk5pwd: pass change exop works, {K5KEY} check doesn't

2005-07-02 Thread Howard Chu
the K5 salt. -- -- Howard Chu Chief Architect, Symas Corp. Director, Highland Sun http://www.symas.com http://highlandsun.com/hyc Symas: Premier OpenSource Development and Support

Re: smbk5pwd: pass change exop works, {K5KEY} check doesn't

2005-07-02 Thread Howard Chu
up any statements to this effect for me. Wherever you read that, ignore it. The password-hash should be {K5KEY} if you want the Kerberos key to be used. -- -- Howard Chu Chief Architect, Symas Corp. Director, Highland Sun http://www.symas.com http://highlandsun.com/hyc

Re: deferring operation ?

2005-07-05 Thread Howard Chu
annuaire slapd[19523]: conn=7554 fd=12 ACCEPT from IP=10.5.1.4:35305 (IP=0.0.0.0:389) Jul 4 13:50:03 annuaire slapd[19523]: conn=7552 fd=18 closed Jul 4 13:50:03 annuaire slapd[19523]: connection_read(18): no connection! -- -- Howard Chu Chief Architect, Symas Corp. Director, Highland

Re: Nested groupOfNames members

2005-07-05 Thread Howard Chu
when doing ACL evaluation. -- -- Howard Chu Chief Architect, Symas Corp. Director, Highland Sun http://www.symas.com http://highlandsun.com/hyc Symas: Premier OpenSource Development and Support

Re: 2 GB filesize limit

2005-07-06 Thread Howard Chu
. -- -- Howard Chu Chief Architect, Symas Corp. Director, Highland Sun http://www.symas.com http://highlandsun.com/hyc Symas: Premier OpenSource Development and Support

Re: openldap profiling tools

2005-07-07 Thread Howard Chu
the current (default) settings are working well or not. -- -- Howard Chu Chief Architect, Symas Corp. Director, Highland Sun http://www.symas.com http://highlandsun.com/hyc Symas: Premier OpenSource Development and Support

Re: deferring operation ?

2005-07-11 Thread Howard Chu
-- -- Howard Chu Chief Architect, Symas Corp. Director, Highland Sun http://www.symas.com http://highlandsun.com/hyc Symas: Premier OpenSource Development and Support

Re: concurrency problem

2005-07-11 Thread Howard Chu
works well. -- -- Howard Chu Chief Architect, Symas Corp. Director, Highland Sun http://www.symas.com http://highlandsun.com/hyc Symas: Premier OpenSource Development and Support

Re: Password Controls support?

2005-07-12 Thread Howard Chu
Controls The ldap.h file does not list those controls. It also says some of the controls are in progress and not yet formalized. I would appreciate if someone throughs some light into this. I am particularly interested in the password controls. Thanks a million. Neo -- -- Howard Chu Chief

Re: loglevel -1 in slapd.conf [auf Viren überpr üft]

2005-07-12 Thread Howard Chu
you should file an ITS for this. -- -- Howard Chu Chief Architect, Symas Corp. Director, Highland Sun http://www.symas.com http://highlandsun.com/hyc Symas: Premier OpenSource Development and Support

Re: Index problems: search results returning no responses

2005-07-14 Thread Howard Chu
or on reload? Not in OpenLDAP 2.2, since that release is feature-frozen now and going into end-of-life soon. If you want dynamic index management use OpenLDAP 2.3. Regards, Graham -- -- -- Howard Chu Chief Architect, Symas Corp. Director, Highland Sun http://www.symas.com

Re: poor performance of OpenLDAP vs AD?

2005-07-14 Thread Howard Chu
Tomasz Chmielewski wrote: Howard Chu schrieb: Quanah Gibson-Mount wrote: --On Wednesday, July 13, 2005 2:49 PM +0200 Tomasz Chmielewski [EMAIL PROTECTED] wrote: Recently, when planning to deploy a directory server, I was confronted with someone claiming that OpenLDAP performs poorly

Re: ldap newbie again

2005-07-22 Thread Howard Chu
and build the code. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: BDB corruption on windows port of 2.2.19

2005-07-22 Thread Howard Chu
all these errors? Am I using the wrong version of db_recover? Or is the home directory supposed to be different when running db_recover under the OpenLDAP folder? -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc

Re: Duplicate attributeType: 2.5.4.13

2005-07-24 Thread Howard Chu
Samuel Tran wrote: Howard Chu wrote: Samuel Tran wrote: Hi All, I am currently testing OpenLDAP 2.3.4. After successfully building it I am now trying to configure slapd using the new style (http://www.openldap.org/doc/admin23/slapdconf2.html). However when I try to run: /usr/local

Re: olcDefaultSearchBase: value #0: olcDefaultSearchBase invalid DN 21 (Invalid syntax)

2005-07-27 Thread Howard Chu
system resources. slapd stopped. connections_destroy: nothing to destroy. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: Problem finding telephonenumber in a plain numeric search when number is stored with special characters

2005-08-06 Thread Howard Chu
: http://groups-beta.google.com/group/comp.std.internat/msg/24fc32228689a620?dmode=source -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: How does it handle 10k users and 3k desktops.

2005-08-06 Thread Howard Chu
of OpenLDAP 2.1 releases we stated quite clearly that you need to read the Sleepycat documentation and understand it in order to get the best use of it. People who deployed incorrectly have only themselves to blame for not reading and following directions. -- -- Howard Chu Chief Architect

Re: slapd hangs doing large ldap (add|modify|delete)

2005-08-10 Thread Howard Chu
a checkpoint before closing the database environment. If slapcat was running as root, and the checkpoint caused a new log file to be created, it would be created/owned by root, and other processes would be unable to write to the log. This was ITS#3703.) -- -- Howard Chu Chief Architect

Re: Installing Openldap from a tarball

2005-08-10 Thread Howard Chu
/directory/openldap/configuration/bdb-build-42.html No need to go surfing the web; in OpenLDAP 2.3 the patch is in ./build/BerkeleyDB42.patch in the source tree. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc

Re: multiple databases (subordinate) and subschemaSubentry

2005-08-11 Thread Howard Chu
cn=Manager,o=stepping-stone,c=ch rootpw gugus directory /var/lib/openldap-hdb/stepping-stone I know, it doesn't really answer your question, but it works. Kind regards, Michael -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sun

Re: syncrepl w/ 2.3 and bdb 4.3 working great

2005-08-14 Thread Howard Chu
will not be able to db_recover it; if you're doing a lot of incremental slapadds over a course of time you probably shouldn't risk -q... -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp

Re: problem with sasl and openldap

2005-08-16 Thread Howard Chu
is meaningless in slapd, as slapd doesn't use ldapdb. See the SASL docs (options.html); it specifically says the ldapdb plugin is not for use with slapd. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Team

Re: Problem with Password Policy Overlay - Password Reset

2005-08-16 Thread Howard Chu
do you mean by user can't authenticate ? Certainly they should still be able to Bind. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: substring index oddity

2005-08-24 Thread Howard Chu
. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: substring index oddity

2005-08-24 Thread Howard Chu
: uid=test* : 0.007 seconds # numEntries: 100 uid=*est222* : 0.048s # numEntries: Quite good. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: new slapd.d configuration format and Invalid DN syntax (34)

2005-08-26 Thread Howard Chu
specify that when converting the config format. Are the permissions in slapd.d correct? -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: slapcat or ldapsearch could not return complete query result

2005-08-26 Thread Howard Chu
schools and libraries are stronger than ever in the present religio-political climate. They often focus on fantasy and sf books, which foster that deadly enemy to bigotry and blind faith, the imagination. -- Ursula K. Le Guin -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com

Re: new slapd.d configuration format and Invalid DN syntax (34)

2005-08-26 Thread Howard Chu
were not read in properly, which is why I asked if the permissions on slapd.d were correct. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: new slapd.d configuration format and Invalid DN syntax (34)

2005-08-27 Thread Howard Chu
/core.schema structuralObjectClass: olcIncludeFile -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: new slapd.d configuration format and Invalid DN syntax (34)

2005-08-27 Thread Howard Chu
olcSizeLimit: 5000 olcSockbufMaxIncoming: 524288 olcSockbufMaxIncomingAuth: 16777215 olcThreads: 16 olcTLSCACertificateFile: /etc/openldap/certs/cacert.pem olcTLSCRLCheck: none olcTLSVerifyClient: never structuralObjectClass: olcGlobal -- -- Howard Chu Chief Architect, Symas Corp. http

Re: threads v. concurrency?

2005-08-27 Thread Howard Chu
CPUs. This is very general advice, you need to look at what pthread_set_concurrency really means on your platform (assuming you're using POSIX threads). -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core

Re: OL 2.3.x, uid attribute commented out in core.schema

2005-08-31 Thread Howard Chu
. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: Question pertaining to PPolicy overlay feature

2005-09-01 Thread Howard Chu
. Thanks, Shawn -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: back-meta (Was: (ITS#3971) slapo-glue dissolving after one query)

2005-09-01 Thread Howard Chu
your test environment (including writing a test client in Java with JNDI) just to see what you're talking about. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org

Re: Question pertaining to PPolicy overlay feature

2005-09-02 Thread Howard Chu
when the password is changed. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: Glue, relay, chain, rwm, meta - which one?

2005-09-04 Thread Howard Chu
. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: Question pertaining to PPolicy overlay feature

2005-09-05 Thread Howard Chu
Shawn McKinney wrote: --- Howard Chu [EMAIL PROTECTED] wrote: The current revision in CVS HEAD makes the pwdAccountLockedTime user modifiable again (undoing the draft-9 change for now) and also deletes the attribute automatically when the password is changed. I've verified

Re: Intermittent hang/deadlock when iterating through LDAP search results using JLDAP

2005-09-09 Thread Howard Chu
with the rest of the JLDAP reports, but it hasn't disappeared. Jon Roberts www.mentata.com ... forthwith donning my flame-retardant assflaps Speaking as a C programmer, I can only say somebody needs to get their act together. I don't know who that somebody is though. -- -- Howard Chu Chief

Re: Alias dereferencing

2005-09-11 Thread Howard Chu
referrals are precisely the correct feature needed to implement these references. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: requesting clarification of use of config backend

2005-09-12 Thread Howard Chu
BSD admin/developer at large -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: Syncrepl does not copy operational attributes?

2005-09-13 Thread Howard Chu
Dave Horsfall wrote: On Tue, 13 Sep 2005, Howard Chu wrote: createTimestamp creatorsName modifiersName modifyTimestamp [...] Depends on your syncrepl consumer configuration, since you explicitly specify which attributes to replicate there. So attrs=* replicates

Re: Open LDAP performance tuning

2005-09-13 Thread Howard Chu
in OpenLDAP 2.3 your question is somewhat meaningless since a slapd.conf keyword has been added for controlling settings in DB_CONFIG. (See the slapd-bdb(5) manpage in OpenLDAP 2.3) -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp

Re: case sensitivity in DN component attribute

2005-09-13 Thread Howard Chu
the schema definition in memory. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: OL 2.3.7, ppolicy, how to unlock account?

2005-09-14 Thread Howard Chu
, resetting the password automatically unlocks the account. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: 2.3.7 build problems (libtool?)

2005-09-16 Thread Howard Chu
now in HEAD, try applying the patch in slapd/saslauthz.c -r1.158 to your source. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: Being a consumer and a provider for the same database (toward different servers) ?

2005-09-18 Thread Howard Chu
-sessionlog 100 Thanks a lot for anwsers. [EMAIL PROTECTED] with the suffix o=my-company -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org

Re: No entries in Accesslog

2005-09-23 Thread Howard Chu
) for the database, just as you would for any other database. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: slapd crashes when accessing accesslog

2005-09-23 Thread Howard Chu
Michael Ströder wrote: Howard Chu wrote: You must initialize the database, the accesslog overlay doesn't do it for you. That is, you must create the suffix entry (cn=accesslog) for the database, just as you would for any other database. Played with it: Subordinate eEntries

Re: Ldapsearch returning incorrect value

2005-09-26 Thread Howard Chu
rid of the trailing spaces, then it would just display it without base64 encoding. As usual - garbage in, garbage out. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp

Re: problem with sets in 2.2.5 (not in 2.1.25)

2005-09-28 Thread Howard Chu
by users set.regex=(user/x2xTenant[$1]) read to get this working in 2.2. By the way, 2.2.28 is the latest 2.2 release. Since you're upgrading anyway, you definitely should not be using something as old as 2.2.5. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director

Re: Is fedora core 3 a ticking timebomb?

2005-09-29 Thread Howard Chu
a number of times on the list in the past couple days. Better still - this message means you need to upgrade to OpenLDAP 2.3... -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp

Re: How to raise the open file descriptor limit for slapd?

2005-10-05 Thread Howard Chu
to explicitly #undef it first to remove the default value that glibc uses. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: Oddity with BDB backend

2005-10-05 Thread Howard Chu
this if that were true. You probably need to run db_recover. Switching up to 2.3 would be a good move, since none of this particular code exists any more in 2.3. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc

Re: Replicate through an VPN ?

2005-10-08 Thread Howard Chu
users on the intervening networks. What if a malicious user intercepts the message from the master that signals the slave to create the VPN? Why use a VPN at all, why not just use TLS? -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp

Re: slapd fails to start up in 2.3.8 and 2.3.9

2005-10-11 Thread Howard Chu
Buchan Milne wrote: On Monday, 10 October 2005 19:34, Howard Chu wrote: errno 38 is ENOSYS, it seems the epoll_ctl system call is not implemented on your target kernel. You say that running make test works though? On the build host, which has a 2.6 kernel. The kernel on the target

Re: Upgrade issue ({CLEARTEXT} not available)

2005-10-11 Thread Howard Chu
? Sounds like ITS#4021. The fix was released in 2.3.8, and was not backported to 2.2. The patch is simple, you can get it from CVS libraries/liblutil/passwd.c r1.103 -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc

Re: ITS#3971 Fix

2005-10-11 Thread Howard Chu
. The nature of this misbehaviour seems to be a little bit deeper, so I didn't investigate this. I don't believe you should be using the rwm overlay as a global overlay since the relay backend automatically invokes it itself. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com

Re: Slurpd and TLS/SSL

2005-10-13 Thread Howard Chu
of slapd.conf, the rest of its configuration (including TLS parameters) must be set via ldap.conf. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: Slurpd and TLS/SSL

2005-10-13 Thread Howard Chu
working on that O'Reilly book ever contacted anyone on the OpenLDAP project re: reviewing its content. (And yes, we have done so when asked by other authors in the past.) As such, the book's technical accuracy and best-practice suggestions are somewhat questionable. -- -- Howard Chu Chief

Re: Slurpd and TLS/SSL

2005-10-13 Thread Howard Chu
happening?) You can see what's happening without using any external network debugging tools. Just make sure debug level 2 is included in your debug flags. E.g., run slapd -d2, slurpd -d2, -d3, -d7, etc... -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sun

Re: 2.3.11 test007 fails

2005-10-15 Thread Howard Chu
| slapd destroy: freeing system resources. | slapd stopped. ` any hints? -Dieter -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: 2.3.11 test007 fails

2005-10-15 Thread Howard Chu
discussed in that ITS have already been resolved.) -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: database directory inside database directory

2005-10-17 Thread Howard Chu
tell it to. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: What is the glue overlay function?

2005-10-18 Thread Howard Chu
to understand. The slapo-glue man page has been removed from the distribution. See the slapd.conf(5) man page instead, look up the subordinate keyword. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Team

Re: change related to its 4046 seems to break sasl/gssapi working with AD

2005-10-19 Thread Howard Chu
are seen as purely informational. ITS#4046 doesn't seem to be the right number. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: installation problems

2005-10-19 Thread Howard Chu
. 4.3.27 appeared to work. I haven't tested the current (4.3.29) yet. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: Problems with slapcat/slapadd in upgrade from 2.2.23 to 2.3.11

2005-10-21 Thread Howard Chu
* of creating and deleting the data. Clearly in such a situation you have *no* coherent security policy, which in my book is equivalent to having no security. *That's* scary. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc

Re: User Schema Load failed ..., using ppolicy.schema overlay

2005-10-27 Thread Howard Chu
, Buchan -- Buchan Milne ISP Systems Specialist B.Eng,RHCE(803004789010797),LPIC-2(LPI74592) -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: OpenLDAP Hooks and Integration

2005-10-31 Thread Howard Chu
to implement this feature you desire rests on the application side. When you take the time to think through the actual flow of information and steps needed to process it, it's all pretty obvious. No need to wonder. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com

Tuning BerkeleyDB

2005-11-03 Thread Howard Chu
would probably have defaulted to using test-and-set mutexes. If you're on 2.6 with NPTL it would most likely default to using POSIX mutexes. It's worth double-checking your BerkeleyDB build to see exactly how it was configured. -- -- Howard Chu Chief Architect, Symas Corp. http

Re: openldap build problem

2005-11-03 Thread Howard Chu
the domain controller. Any ideas on what I might have missed? See ITS#4102. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: asynchronous event notification?

2005-11-03 Thread Howard Chu
database into the foreign database. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: Corrupt LDAP DB ...

2005-11-05 Thread Howard Chu
then? Whining on the discussion list doesn't get problems resolved. If you've identified a specific weakness, but don't report it, you shouldn't be surprised that it doesn't get fixed sooner. You have only yourself to blame, for not filing the report. -- -- Howard Chu Chief Architect, Symas

Re: ppolicy overlay password problem

2005-11-07 Thread Howard Chu
: 864000 pwdMinLength: 5 pwdGraceAuthNLimit: 5 pwdAllowUserChange: TRUE pwdMustChange: FALSE pwdMaxFailure: 3 pwdFailureCountInterval: 120 pwdSafeModify: FALSE structuralObjectClass: device -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp

Re: Modifying ACIs programmatically?

2005-11-07 Thread Howard Chu
to directives, but I don't see any samples of how this can be done programmatically. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: How do I run a query on the bdb database before I've started listening for incoming request?

2005-11-10 Thread Howard Chu
listening (before main.c/slapd_daemon() Out of curiosity, *why* do you want to do this? -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: Translucent overlay odds?

2005-11-12 Thread Howard Chu
flawed? No, the current design of the translucent overlay does not allow totally local entries to exist. I.e., there must be a corresponding remote entry. Also, it expects the local and remote DB to have the same suffix. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com

Re: Translucent overlay odds?

2005-11-13 Thread Howard Chu
Pierangelo Masarati wrote: On Sat, 2005-11-12 at 17:23 -0800, Howard Chu wrote: Pierangelo Masarati wrote: Is local addition intended to be supported? Yes, apparently, according to the man page; but I note this case is not tested in test034. So my question is: does my approach make

Re: BDB 4.4 is released

2005-11-21 Thread Howard Chu
annoying. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: openldap-server-2.2.29: multimaster support

2005-11-21 Thread Howard Chu
for; the overhead for maintaining ACID would drop write throughput to a few operations per second on a moderate sized network. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp

Re: sizelimit evaluated before ACLs?

2005-11-23 Thread Howard Chu
-bdb. But that's probably OK, since the pagedResults feature properly belongs in the frontend as well. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: sizelimit evaluated before ACLs?

2005-11-23 Thread Howard Chu
a SIZELIMIT_EXCEEDED result to the caller when appropriate. Then no callers (backends or overlays) need to worry about testing the limit, they just need to handle the non-success return codes. (Which they do already.) At 03:14 PM 11/23/2005, Howard Chu wrote: Eric Irrgang wrote: I'm sorry

Re: put failed: DB_LOCK_DEADLOCK .....

2005-11-25 Thread Howard Chu
of the message and what to do to fix it ? I use openldap 2.3.11. This is not a fatal error and does not need fixing. Read the Sleepycat documentation. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Team

Re: Do overlays affect the speed of OpenLDAP?

2005-11-26 Thread Howard Chu
looking for, you can't expect quality information. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: refreshAndPersist filter 2.3.11

2005-11-30 Thread Howard Chu
) for syncrepl as in the LDAP Sync Replication config example from the Doc, but set type = refreshAndPersist instead of type=refreshOnly then syncing does not work. Please submit this information to the ITS, otherwise it will be ignored. -- -- Howard Chu Chief Architect, Symas Corp. http

Re: refreshAndPersist speed

2005-12-02 Thread Howard Chu
the syncrepl client multi-threaded to address this shortcoming. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: Linking against a specific Berkeley DB install

2005-12-02 Thread Howard Chu
/local/BerkeleyDB.4.4. How do I get OpenLDAP to link with the bdb 4.4? -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: Some syncrepl questions

2005-12-02 Thread Howard Chu
? You need at least version 2.2.24 to accept replication updates from a 2.3 master. You need at least version 2.3.12 to accept replication updates from any previous release. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com

Re: refreshAndPersist filter 2.3.11

2005-12-02 Thread Howard Chu
Howard Chu wrote: Alexey Kravchuk wrote: Hi, syncrepl of slapd 2.3.11 with type = refreshAndPersist works only when the syncrepl filter allows to fetch all parent entries up to the base. Yet it worked fine in 2.2.13. That is if we specify searchbase=dc=example,dc=com, filter=(objectClass

Re: FYI - Not an OpenLDAP bug - or OpenLDAP on Windows 2000 using Hummingbird SOCKS client

2005-12-06 Thread Howard Chu
with each other, and by doing so we all naturally help each other as a result. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: bdb indexing limits

2005-12-07 Thread Howard Chu
. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org/project/

Re: master ldap database is not getting populated

2005-12-09 Thread Howard Chu
if i can use slave database to export the missing entries to an ldiff file and then use the ldiff file to populate the master database. I also don't know how to find what entries are missing in the master ldap. thanks -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com

Re: OpenLDAP, Kerberos not Compatible with DIGEST-MD5?

2005-12-11 Thread Howard Chu
servers you'll need the ldapdb module, which used to be in OpenLDAP contrib but is now part of Cyrus SASL. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc OpenLDAP Core Teamhttp://www.openldap.org

Re: ldaps and Active Directory

2005-12-12 Thread Howard Chu
:/etc/openldap/cacerts. In /etc/openldap/ldap.conf I have tried: TLS_CACERTDIR /etc/openldap/cacerts TLS_CACERT /etc/openldap/cacerts/cacert.pem Any suggestions would be greatly appreciated. Grant -- -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com

Re: syncrepl'd MOD deleted(?) entry

2005-12-13 Thread Howard Chu
consider critical. ;) Which reminds me I need to get some of the newer patches up on my site... At this stage, CVS HEAD and 2.3 are close enough that anyone can just pull the necessary patches out of HEAD. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland

Re: Syncrepl and user event

2005-12-15 Thread Howard Chu
Aaron Richton wrote: Quite honestly, I have no idea. Use the source... On Thu, 15 Dec 2005, [UTF-8] Micha�^B Kasperczyk wrote: Does syncrepl calls overlays while adding new objects to slave LDAP? Yes it does. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com

Re: forcing password hash

2005-12-19 Thread Howard Chu
and then generates the hash later. As such, quality checking can always be performed when using the exop. Thanks, Jim */Howard Chu [EMAIL PROTECTED]/* wrote: Kurt D. Zeilenga wrote: At 11:57 AM 12/19/2005, Jim Boden wrote: Is there a way to force openldap to hash the userPassword entry

  1   2   3   4   5   6   7   8   9   10   >