On 11/10/2011 11:48 AM, Tom Tucker wrote:
I would appreciate any troubleshooting advise you might have regarding
my registered ldap servers. I am referring to the first page you see
when launching the console (servers listed underneath Servers and
Applications). I see my servers listed, however I am unable to open
them. Their "Server status" always reports "Stopped" even though the
remote servers are running.
Based on my tcpdump capture below the 'admin prohibited' message is a
clear indication of the problem, but I can't seem to correct it. I
have reran the setup several times, confirmed the password and such.
What am I missing?
Have you tried running setup-ds-admin.pl -u on both the local servers
and the remote servers?
==============================================================================
13:35:27.458489 IP serverA.mydomain.com.30940 >
serverB.mydomain.com.ldap: Flags [S], seq 404137883, win 14600,
options [mss 1460,sackOK,TS val 348721371 ecr 0,nop,wscale 6], length 0
13:35:27.458591 IP serverB.mydomain.com <http://serverB.mydomain.com>
> serverA.mydomain.com <http://serverA.mydomain.com>: ICMP host
serverB.mydomain.com <http://serverB.mydomain.com> unreachable - admin
prohibited, length 68
Please specify the information about your configuration directory
server. The following information is required:
- host (fully qualified), port (non-secure or secure), suffix,
protocol (ldap or ldaps) - this information should be provided in the
form of an LDAP url e.g. for non-secure
ldap://host.example.com:389/o=NetscapeRoot
<http://host.example.com:389/o=NetscapeRoot>
or for secure
ldaps://host.example.com:636/o=NetscapeRoot
<http://host.example.com:636/o=NetscapeRoot>
- admin ID and password
- admin domain
- a CA certificate file may be required if you choose to use ldaps and
security has not yet been configured - the file must be in PEM/ASCII
format - specify the absolute path and filename
Configuration directory server URL
[ldap://serverA.mydomain.com:389/o=NetscapeRoot
<http://serverA.mydomain.com:389/o=NetscapeRoot>]:
Configuration directory server admin ID
[uid=admin,ou=Administrators,ou=TopologyManagement,o=NetscapeRoot]:
Configuration directory server admin password:
Configuration directory server admin domain [mydomain.com
<http://mydomain.com>]:
--
389 users mailing list
[email protected]
https://admin.fedoraproject.org/mailman/listinfo/389-users
--
389 users mailing list
[email protected]
https://admin.fedoraproject.org/mailman/listinfo/389-users