https://bugs.openldap.org/show_bug.cgi?id=9295

          Issue ID: 9295
           Summary: ppolicy and replication: pwdLockedTime replication
                    fails to replicate
           Product: OpenLDAP
           Version: 2.4.50
          Hardware: All
                OS: All
            Status: UNCONFIRMED
          Severity: normal
          Priority: ---
         Component: overlays
          Assignee: [email protected]
          Reporter: [email protected]
  Target Milestone: ---

If you have the following setup, a replica will hit an error during
replication.

a) ppolicy is configured on provider(s) and replicas.  Replica has
schemachecking=on in its syncrepl configuration
b) account gets locked on the replica, so pwdAccountLockedTime is set on the
replica but not on the provider(s)
c) admin does a MOD/ADD op against a provider for the user entry to add a value
to pwdAccountLockedTime

dn: ...
changetype: modify
add: pwdAccountLockedTime
pwdAccountLockedTime: ...

d) provider accepts this modification.
e) replica rejects this modification because the resulting change means that
there would be two pwdAccountLockedTime values on the account in question

Generally I believe that in this scenario, the MOD/ADD on the provider should
be treated as a replace OP instead of an ADD op

-- 
You are receiving this mail because:
You are on the CC list for the issue.

Reply via email to