Dear Rob, All, Just to be clear, we have indeed tracked this down to another issue, and the OTP/LDAP timing is fine. I imagine you already knew this, but this is confirmed to _not_ be an issue.
Regards, Callum -- Callum Smith Research Computing Core Wellcome Trust Centre for Human Genetics University of Oxford e. [email protected]<mailto:[email protected]> On 4 Feb 2019, at 22:06, Rob Crittenden <[email protected]<mailto:[email protected]>> wrote: Callum Smith via FreeIPA-users wrote: Dear All, I'm seeing issues with the time synchronisation for OTP but ONLY for authentication through LDAP and not through kerberos. Is this even possible or am I going down the wrong rabbit hole on this issue. The error presents as LDAP authentication giving "ldap operation failed" when authentication to HashiCorp Vault, configured to auth against IPA over LDAP, if the token is slightly old. Have you been able to define a range for "slightly old"? Is there some latency that is causing issue? Is anything logged in the 389-ds error log when the operations error fires? I'm not sure which error level would help in this case, some can be kinda spammy. Is this easily reproducible on an otherwise quiet system? rob
_______________________________________________ FreeIPA-users mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/[email protected]
