Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-08 Thread Dan Scott
On Fri, Oct 8, 2010 at 16:28, Nathan Kinder wrote: > On 10/08/2010 12:08 PM, Dan Scott wrote: >> >> On Fri, Oct 8, 2010 at 14:52, James Roman  wrote: >> >>> >>>  On 10/08/2010 01:49 PM, Dan Scott wrote: >>> On Fri, Oct 8, 2010 at 13:18, Rich Megginson  wrote: > > Dan Sc

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-08 Thread Nathan Kinder
On 10/08/2010 12:08 PM, Dan Scott wrote: On Fri, Oct 8, 2010 at 14:52, James Roman wrote: On 10/08/2010 01:49 PM, Dan Scott wrote: On Fri, Oct 8, 2010 at 13:18, Rich Megginsonwrote: Dan Scott wrote: On Fri, Oct 8, 2010 at 11:39, James Roman wrote:

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-08 Thread Rich Megginson
Dan Scott wrote: On Fri, Oct 8, 2010 at 13:18, Rich Megginson wrote: Dan Scott wrote: On Fri, Oct 8, 2010 at 11:39, James Roman wrote: So does anyone have any more suggestions? Or should I just configure a new replica with new hostname and IP? Thanks, Dan I've

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-08 Thread Dan Scott
On Fri, Oct 8, 2010 at 14:52, James Roman wrote: >  On 10/08/2010 01:49 PM, Dan Scott wrote: >> >> On Fri, Oct 8, 2010 at 13:18, Rich Megginson  wrote: >>> >>> Dan Scott wrote: On Fri, Oct 8, 2010 at 11:39, James Roman  wrote: >> So does anyone have any more suggestions? Or

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-08 Thread James Roman
On 10/08/2010 01:49 PM, Dan Scott wrote: On Fri, Oct 8, 2010 at 13:18, Rich Megginson wrote: Dan Scott wrote: On Fri, Oct 8, 2010 at 11:39, James Roman wrote: So does anyone have any more suggestions? Or should I just configure a new replica with new hostname and IP? Thanks, Dan I've s

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-08 Thread Dan Scott
On Fri, Oct 8, 2010 at 13:18, Rich Megginson wrote: > Dan Scott wrote: >> >> On Fri, Oct 8, 2010 at 11:39, James Roman wrote: >> So does anyone have any more suggestions? Or should I just configure a new replica with new hostname and IP? Thanks, Dan >>> >>>

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-08 Thread Rich Megginson
Dan Scott wrote: On Fri, Oct 8, 2010 at 11:39, James Roman wrote: So does anyone have any more suggestions? Or should I just configure a new replica with new hostname and IP? Thanks, Dan I've seen the initial problem where the memberof elements stop updating on my own FreeIPA v1 re

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-08 Thread Dan Scott
On Fri, Oct 8, 2010 at 11:39, James Roman wrote: > >> So does anyone have any more suggestions? Or should I just configure a >> new replica with new hostname and IP? >> >> Thanks, >> >> Dan > > I've seen the initial problem where the memberof elements stop updating on > my own FreeIPA v1 replica a

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-08 Thread Dan Scott
On Thu, Oct 7, 2010 at 11:47, Dan Scott wrote: > On Thu, Oct 7, 2010 at 11:32, James Roman wrote: >>  On 10/07/2010 11:20 AM, Rich Megginson wrote: >>> >>> 20 is "type or value exists" - I think this means that it is attempting to >>> set a referral for the master, but there already is one.

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-07 Thread Nathan Kinder
On 10/06/2010 07:03 PM, Rich Megginson wrote: Dan Scott wrote: Hi, On Wed, Oct 6, 2010 at 19:29, Nathan Kinder wrote: On 10/06/2010 03:08 PM, Dan Scott wrote: I'm not sure which group this is referring to. Admins only contains 3 users, no nested groups. Do any other groups have a "member"

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-07 Thread Dan Scott
On Thu, Oct 7, 2010 at 11:32, James Roman wrote: >  On 10/07/2010 11:20 AM, Rich Megginson wrote: >> >> 20 is "type or value exists" - I think this means that it is attempting to >> set a referral for the master, but there already is one. >>> >>> Curie contains the same log entry. >>> >>> But, non

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-07 Thread Simo Sorce
On Thu, 07 Oct 2010 09:20:29 -0600 Rich Megginson wrote: > > > Does IPA have its own memberOf plugin, or is it using the one from > 389? In v1, it had its own memberof plugin. Simo. -- Simo Sorce * Red Hat, Inc * New York ___ Freeipa-users mai

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-07 Thread James Roman
On 10/07/2010 11:20 AM, Rich Megginson wrote: 20 is "type or value exists" - I think this means that it is attempting to set a referral for the master, but there already is one. Curie contains the same log entry. But, none of the users contain the memberOf attributes on ohm. Does IPA have its

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-07 Thread Rich Megginson
Dan Scott wrote: On Thu, Oct 7, 2010 at 10:58, Rob Crittenden wrote: Dan Scott wrote: On Thu, Oct 7, 2010 at 10:20, Rich Megginson wrote: Dan Scott wrote: On Wed, Oct 6, 2010 at 22:02, Rich Megginson wrote: Dan Scott wrote: Hi, On Wed, O

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-07 Thread Dan Scott
On Thu, Oct 7, 2010 at 10:58, Rob Crittenden wrote: > Dan Scott wrote: >> >> On Thu, Oct 7, 2010 at 10:20, Rich Megginson  wrote: >>> >>> Dan Scott wrote: On Wed, Oct 6, 2010 at 22:02, Rich Megginson  wrote: > > Dan Scott wrote: > >> >> Hi, >> >> On

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-07 Thread Simo Sorce
On Thu, 7 Oct 2010 10:43:15 -0400 Dan Scott wrote: > Sorry about that, I now get: > > adding new entry cn=memberOf_fixup_2010_10_7_10_41_11, cn=memberOf > task, cn=tasks, cn=config > ldap_add: Insufficient access > > I have an admin Kerberos ticket and I know the password is correct > because o

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-07 Thread Rob Crittenden
Dan Scott wrote: On Thu, Oct 7, 2010 at 10:20, Rich Megginson wrote: Dan Scott wrote: On Wed, Oct 6, 2010 at 22:02, Rich Megginson wrote: Dan Scott wrote: Hi, On Wed, Oct 6, 2010 at 18:30, Rich Megginson wrote: Dan Scott wrote: I'm not sure which group this is referring to. Ad

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-07 Thread James Roman
Sorry about that, I now get: adding new entry cn=memberOf_fixup_2010_10_7_10_41_11, cn=memberOf task, cn=tasks, cn=config ldap_add: Insufficient access I have an admin Kerberos ticket and I know the password is correct because otherwise I get 'ldap_simple_bind: Invalid credentials'. Thanks,

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-07 Thread Dan Scott
On Thu, Oct 7, 2010 at 10:20, Rich Megginson wrote: > Dan Scott wrote: >> >> On Wed, Oct 6, 2010 at 22:02, Rich Megginson wrote: >> >>> >>> Dan Scott wrote: >>> Hi, On Wed, Oct 6, 2010 at 18:30, Rich Megginson wrote: > > Dan Scott wrote: > > >>>

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-07 Thread Rich Megginson
Dan Scott wrote: On Wed, Oct 6, 2010 at 22:02, Rich Megginson wrote: Dan Scott wrote: Hi, On Wed, Oct 6, 2010 at 18:30, Rich Megginson wrote: Dan Scott wrote: I'm not sure which group this is referring to. Admins only contains 3 users, no nested groups. The probl

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-07 Thread Dan Scott
On Wed, Oct 6, 2010 at 22:02, Rich Megginson wrote: > Dan Scott wrote: >> >> Hi, >> >> On Wed, Oct 6, 2010 at 18:30, Rich Megginson wrote: >> >>> >>> Dan Scott wrote: >>> I'm not sure which group this is referring to. Admins only contains 3 users, no nested groups. The pr

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Rich Megginson
Dan Scott wrote: Hi, On Wed, Oct 6, 2010 at 19:29, Nathan Kinder wrote: On 10/06/2010 03:08 PM, Dan Scott wrote: I'm not sure which group this is referring to. Admins only contains 3 users, no nested groups. Do any other groups have a "member" attribute that points to your "c

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Rich Megginson
Dan Scott wrote: Hi, On Wed, Oct 6, 2010 at 18:30, Rich Megginson wrote: Dan Scott wrote: I'm not sure which group this is referring to. Admins only contains 3 users, no nested groups. The problem appears to be related to the users, rather than the groups. None of the users on ohm ha

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Dan Scott
Hi, On Wed, Oct 6, 2010 at 19:29, Nathan Kinder wrote: > On 10/06/2010 03:08 PM, Dan Scott wrote: >> >> I'm not sure which group this is referring to. Admins only contains 3 >> users, no nested groups. >> > > Do any other groups have a "member" attribute that points to your > "cn=admins" group's

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Nathan Kinder
On 10/06/2010 03:08 PM, Dan Scott wrote: I'm not sure which group this is referring to. Admins only contains 3 users, no nested groups. Do any other groups have a "member" attribute that points to your "cn=admins" group's DN? The error message indicates that some other group has your admin

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Dan Scott
Hi, On Wed, Oct 6, 2010 at 18:30, Rich Megginson wrote: > Dan Scott wrote: >> >> I'm not sure which group this is referring to. Admins only contains 3 >> users, no nested groups. >> >> The problem appears to be related to the users, rather than the >> groups. None of the users on ohm have a 'memb

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Rich Megginson
Dan Scott wrote: I'm not sure which group this is referring to. Admins only contains 3 users, no nested groups. The problem appears to be related to the users, rather than the groups. None of the users on ohm have a 'memberOf'. Curie has the correct memberOf attributes. The error message spe

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Dan Scott
I'm not sure which group this is referring to. Admins only contains 3 users, no nested groups. The problem appears to be related to the users, rather than the groups. None of the users on ohm have a 'memberOf'. Curie has the correct memberOf attributes. The groups themselves appear to be correct

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Rich Megginson
Dan Scott wrote: Hi, ohm_admins.ldif and curie_admins.ldif attached. I added a '-h $hostname' to the command to ensure that I queried both servers. The results look identical to me, apart from the ordering. Thanks, Dan On Wed, Oct 6, 2010 at 15:34, Rob Crittenden wrote: Dan Scott wrote:

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Dan Scott
Hi, ohm_admins.ldif and curie_admins.ldif attached. I added a '-h $hostname' to the command to ensure that I queried both servers. The results look identical to me, apart from the ordering. Thanks, Dan On Wed, Oct 6, 2010 at 15:34, Rob Crittenden wrote: > Dan Scott wrote: >> >> Hi, >> >> On We

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Rob Crittenden
Dan Scott wrote: Hi, On Wed, Oct 6, 2010 at 11:32, Simo Sorce wrote: On Wed, 6 Oct 2010 10:26:48 -0400 Dan Scott wrote: Hi, I have master and slave FreeIPA servers. I recently upgraded the slave by wiping, re-installing Fedora 13 and re-creating the replication using ipa-replica-prepare an

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Dan Scott
Hi, On Wed, Oct 6, 2010 at 11:32, Simo Sorce wrote: > On Wed, 6 Oct 2010 10:26:48 -0400 > Dan Scott wrote: > >> Hi, >> >> I have master and slave FreeIPA servers. I recently upgraded the slave >> by wiping, re-installing Fedora 13 and re-creating the replication >> using ipa-replica-prepare and

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Simo Sorce
On Wed, 6 Oct 2010 10:26:48 -0400 Dan Scott wrote: > Hi, > > I have master and slave FreeIPA servers. I recently upgraded the slave > by wiping, re-installing Fedora 13 and re-creating the replication > using ipa-replica-prepare and ipa-replica-install. > > For some reason, the slave is having