Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-08 Thread Dan Scott
On Thu, Oct 7, 2010 at 11:47, Dan Scott danieljamessc...@gmail.com wrote: On Thu, Oct 7, 2010 at 11:32, James Roman james.ro...@ssaihq.com wrote:  On 10/07/2010 11:20 AM, Rich Megginson wrote: 20 is type or value exists - I think this means that it is attempting to set a referral for the

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-08 Thread Dan Scott
On Fri, Oct 8, 2010 at 11:39, James Roman james.ro...@ssaihq.com wrote: So does anyone have any more suggestions? Or should I just configure a new replica with new hostname and IP? Thanks, Dan I've seen the initial problem where the memberof elements stop updating on my own FreeIPA v1

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-08 Thread James Roman
On 10/08/2010 01:49 PM, Dan Scott wrote: On Fri, Oct 8, 2010 at 13:18, Rich Megginsonrmegg...@redhat.com wrote: Dan Scott wrote: On Fri, Oct 8, 2010 at 11:39, James Romanjames.ro...@ssaihq.com wrote: So does anyone have any more suggestions? Or should I just configure a new replica with

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-08 Thread Rich Megginson
Dan Scott wrote: On Fri, Oct 8, 2010 at 13:18, Rich Megginson rmegg...@redhat.com wrote: Dan Scott wrote: On Fri, Oct 8, 2010 at 11:39, James Roman james.ro...@ssaihq.com wrote: So does anyone have any more suggestions? Or should I just configure a new replica with new

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-08 Thread Nathan Kinder
On 10/08/2010 12:08 PM, Dan Scott wrote: On Fri, Oct 8, 2010 at 14:52, James Romanjames.ro...@ssaihq.com wrote: On 10/08/2010 01:49 PM, Dan Scott wrote: On Fri, Oct 8, 2010 at 13:18, Rich Megginsonrmegg...@redhat.comwrote: Dan Scott wrote: On Fri, Oct 8,

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-08 Thread Dan Scott
On Fri, Oct 8, 2010 at 16:28, Nathan Kinder nkin...@redhat.com wrote: On 10/08/2010 12:08 PM, Dan Scott wrote: On Fri, Oct 8, 2010 at 14:52, James Romanjames.ro...@ssaihq.com  wrote:  On 10/08/2010 01:49 PM, Dan Scott wrote: On Fri, Oct 8, 2010 at 13:18, Rich Megginsonrmegg...@redhat.com

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-07 Thread Dan Scott
On Wed, Oct 6, 2010 at 22:02, Rich Megginson rmegg...@redhat.com wrote: Dan Scott wrote: Hi, On Wed, Oct 6, 2010 at 18:30, Rich Megginson rmegg...@redhat.com wrote: Dan Scott wrote: I'm not sure which group this is referring to. Admins only contains 3 users, no nested groups. The

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-07 Thread James Roman
Sorry about that, I now get: adding new entry cn=memberOf_fixup_2010_10_7_10_41_11, cn=memberOf task, cn=tasks, cn=config ldap_add: Insufficient access I have an admin Kerberos ticket and I know the password is correct because otherwise I get 'ldap_simple_bind: Invalid credentials'. Thanks,

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-07 Thread Dan Scott
On Thu, Oct 7, 2010 at 11:32, James Roman james.ro...@ssaihq.com wrote:  On 10/07/2010 11:20 AM, Rich Megginson wrote: 20 is type or value exists - I think this means that it is attempting to set a referral for the master, but there already is one. Curie contains the same log entry. But,

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-07 Thread Nathan Kinder
On 10/06/2010 07:03 PM, Rich Megginson wrote: Dan Scott wrote: Hi, On Wed, Oct 6, 2010 at 19:29, Nathan Kinder nkin...@redhat.com wrote: On 10/06/2010 03:08 PM, Dan Scott wrote: I'm not sure which group this is referring to. Admins only contains 3 users, no nested groups. Do any other

[Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Dan Scott
Hi, I have master and slave FreeIPA servers. I recently upgraded the slave by wiping, re-installing Fedora 13 and re-creating the replication using ipa-replica-prepare and ipa-replica-install. For some reason, the slave is having difficulty replicating the memberOf attribute. I can attach an

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Simo Sorce
On Wed, 6 Oct 2010 10:26:48 -0400 Dan Scott danieljamessc...@gmail.com wrote: Hi, I have master and slave FreeIPA servers. I recently upgraded the slave by wiping, re-installing Fedora 13 and re-creating the replication using ipa-replica-prepare and ipa-replica-install. For some reason,

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Dan Scott
Hi, On Wed, Oct 6, 2010 at 11:32, Simo Sorce sso...@redhat.com wrote: On Wed, 6 Oct 2010 10:26:48 -0400 Dan Scott danieljamessc...@gmail.com wrote: Hi, I have master and slave FreeIPA servers. I recently upgraded the slave by wiping, re-installing Fedora 13 and re-creating the replication

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Rob Crittenden
Dan Scott wrote: Hi, On Wed, Oct 6, 2010 at 11:32, Simo Sorcesso...@redhat.com wrote: On Wed, 6 Oct 2010 10:26:48 -0400 Dan Scottdanieljamessc...@gmail.com wrote: Hi, I have master and slave FreeIPA servers. I recently upgraded the slave by wiping, re-installing Fedora 13 and re-creating

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Dan Scott
Hi, ohm_admins.ldif and curie_admins.ldif attached. I added a '-h $hostname' to the command to ensure that I queried both servers. The results look identical to me, apart from the ordering. Thanks, Dan On Wed, Oct 6, 2010 at 15:34, Rob Crittenden rcrit...@redhat.com wrote: Dan Scott wrote:

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Dan Scott
I'm not sure which group this is referring to. Admins only contains 3 users, no nested groups. The problem appears to be related to the users, rather than the groups. None of the users on ohm have a 'memberOf'. Curie has the correct memberOf attributes. The groups themselves appear to be correct

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Dan Scott
Hi, On Wed, Oct 6, 2010 at 18:30, Rich Megginson rmegg...@redhat.com wrote: Dan Scott wrote: I'm not sure which group this is referring to. Admins only contains 3 users, no nested groups. The problem appears to be related to the users, rather than the groups. None of the users on ohm have

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Nathan Kinder
On 10/06/2010 03:08 PM, Dan Scott wrote: I'm not sure which group this is referring to. Admins only contains 3 users, no nested groups. Do any other groups have a member attribute that points to your cn=admins group's DN? The error message indicates that some other group has your admins

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Rich Megginson
Dan Scott wrote: Hi, On Wed, Oct 6, 2010 at 18:30, Rich Megginson rmegg...@redhat.com wrote: Dan Scott wrote: I'm not sure which group this is referring to. Admins only contains 3 users, no nested groups. The problem appears to be related to the users, rather than the groups. None of