Re: [Freeipa-users] Replication attrlist_replace nsslapd-referral failed

2016-10-11 Thread Fil Di Noto
Things have been working better (so far) after taking some steps I read here: https://www.redhat.com/archives/freeipa-users/2016-January/msg00257.html On Mon, Oct 10, 2016 at 6:48 PM, Fil Di Noto wrote: > After an IPA server is re-initialized it immediately begins failing > incremental updates

Re: [Freeipa-users] Replication attrlist_replace nsslapd-referral failed

2016-10-11 Thread Ludwig Krispenz
Hi, you don't specify the version you are using: If it is 389-ds-base-1.3.4.0-33.el7_2.x86_64 the following may apply: >>> we have identified an issue with this version, it includes a fix for 389-ds ticket #48766, which was incomplete and resolved shortly after the release of this version (it i

[Freeipa-users] Replication attrlist_replace nsslapd-referral failed

2016-10-10 Thread Fil Di Noto
After an IPA server is re-initialized it immediately begins failing incremental updates. I checked the kerberos logs and things appear to be ok there, I can manually test LDAP from all servers against all other servers. There is an DS5ReplicaBindDN entry in "dn: cn=replica,cn=dc\3Dexample\2Cdc\3Dc