Re: (ITS#8920) OpenLDAP

2018-09-24 Thread quanah
advise a first step of upgrading to OpenLDAP 2.4.46. Warm regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#8917) OpenLDAP

2018-09-22 Thread quanah
the person who filed ITS#8914 to give more information on what issue(s) they faced since it works for me. Warm regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#8914) OpenLDAP and OpenSSL v1.1.1

2018-09-21 Thread quanah
46 linked to OpenSSL 1.1.1 > without issue. Hi Neal, See above. Warm regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#8914) OpenLDAP and OpenSSL v1.1.1

2018-09-21 Thread quanah
SL v1.1.1 due to > SSLv3 being disabled. Please provide the configure options you used with OpenSSL v1.1.1 and OpenLDAP, as I as able to build OpenLDAP 2.4.46 linked to OpenSSL 1.1.1 without issue. Warm regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, ce

Re: (ITS#8917) OpenLDAP

2018-09-21 Thread quanah
dn't expect any Linux distribution OpenLDAP based ldapsearch binary to support it for quite some time. GnuTLS also only recently added TLS 1.3 support in the 3.6.3 release as of July 2018, so this would not work in debian based distributions either unless running the very bleeding edge. Warm regards, Quana

(ITS#8905) Client side debug log should include timestamps

2018-08-21 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.46 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) When specifying full debug on the client side (-d -1), there are no timestamps provided. This is problematic when trying to diagnose where the client side

(ITS#8902) man page update for slapadd(5)

2018-08-20 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.46 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) The man page for slapadd's -w option needs to be updated to note that it's generally only safe to use with a cold slapcat.

(ITS#8900) contextCSN issue for export if last op was to delete an entry

2018-08-17 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.46 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) When making an export for backup using slapcat there could be issues on restore if the last operation logged was for a delete entry operation, as the contextCSN

Re: (ITS#8897) Delta syncrepl + refreshOnly segfault if 2 servers receive same group modification operation within interval

2018-08-10 Thread quanah
I suggest applying this patch: <https://www.openldap.org/devel/gitweb.cgi?p=openldap.git;a=commit;h=cc24cf620470e600d31fd68f63decae82b9745f3> --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#8892) ISC dhcpd cannot start TLS session to 389-DS after updating openldap rpm

2018-08-06 Thread quanah
g an unmodified version of OpenLDAP. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#8875) [Patch] Performance problems in back-mdb with large DITs and many aliases

2018-07-06 Thread quanah
> This is a followup to > http://www.openldap.org/lists/openldap-technical/201805/msg00065.html Note that this is duplicate of ITS#7657. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

(ITS#8874) --with-fetch incorrectly links libcom_err

2018-07-06 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.46 OS: FreeBSD 11 URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) When building OpenLDAP on FreeBSD where the fetch library is available, slapd picks up a dependency on libcom_err which shouldn't exist. This comes

(ITS#8873) slapd-meta/ldap - Remove deprecated options

2018-07-05 Thread quanah
Full_Name: Quanah Gibson-Mount Version: HEAD OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) For OpenLDAP 2.5, we should remove the deprecated configuration options for back-ldap/meta/asyncmeta that have been marked as deprecated for multiple release series

Re: (ITS#8870) SASL_NOCANON changing default to ON

2018-06-22 Thread quanah
/index.cgi/?findid=5812>. If you prefer to > have it turned off Turned on, even. ;) --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#8870) SASL_NOCANON changing default to ON

2018-06-22 Thread quanah
The project will not be changing long-standing behavior. But I appreciate your time in filing the ITS. Warm regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

(ITS#8868) Inefficiency when processing certain search filters

2018-06-21 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.46 OS: Linux URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) Certain search filters are not processed efficiently in the back-{bhm}db code base. An example is: "(|(&(subscriberid=1)(objectClass=XYZ))(&(s

(ITS#8861) slapd-(async)meta(5) tls option missing ldaps

2018-06-01 Thread quanah
Full_Name: Quanah Gibson-Mount Version: HEAD OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) The slapd-asyncmeta(5) and slapd-meta(5) man pages are missing the fact that they support the "ldaps" option to the "tls" keyword. This secti

Re: (ITS#8616) olcSpNopresent and olcSpReloadHint can't be modified dynamically

2018-05-24 Thread quanah
as loaded) > > Couldn't reproduce this, works for me. I realized the issue I'd hit was with replicating cn=config when modifying this attribute. Likely the missing matching rules issue that's tracked under another ITS I need to address. --Quanah -- Quanah Gibson-Mount Product Architec

Re: (ITS#8854) Memory leak in modify transaction case

2018-05-14 Thread quanah
low up and the ITS will be reopened. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

(ITS#8845) Cannot preserve existing controls with new extended operations

2018-05-04 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.46 OS: Linux URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) As noted in the OpenLDAP source (http://www.openldap.org/devel/gitweb.cgi?p=openldap.git;a=blob;f=servers/slapd/controls.c;hb=refs/heads/OPENLDAP_REL_ENG_2_4

(ITS#8843) null modlist with MMR > 2 can cause segv

2018-05-02 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.46 OS: Linux URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) There is a race condition with MMR >2 that can cause slapd to segv, due to the op->modlist being set to NULL for a change that's already been pro

Re: (ITS#8616) olcSpNopresent and olcSpReloadHint can't be modified dynamically

2018-05-01 Thread quanah
--On Tuesday, March 14, 2017 6:58 PM + elecha...@symas.com wrote: Also fails for olcSpSessionLog (if it wasn't defined when the cn=config db was loaded) --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered

Re: (ITS#6300) Issues with kqueue after fork

2018-04-24 Thread quanah
--==C0CB1C4A269A2DB8FD87== Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: quoted-printable Content-Disposition: inline Date: Monday, October 23, 2017 12:43 AM -0700 From: Xin Li To: Quanah Gibson-Mount Hi Quanah, I finally got some time

Re: (ITS#8840) domainScope control is not properly implemented

2018-04-23 Thread quanah
ed69b388ad7fb0c696e185f593 Author: Kurt Zeilenga <k...@openldap.org> Date: Fri Apr 20 22:32:58 2007 + Distinguish absent control value from empty control value. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LD

Re: (ITS#8827) lmdb from master fails to build with Visual Studio 2015.

2018-03-29 Thread quanah
--On Thursday, March 29, 2018 9:20 PM + rion...@gmail.com wrote: > Why do you use this mail-based crap? We won't be for much longer: <http://www.openldap.org/lists/openldap-devel/201801/msg00017.html> There are valid reasons to avoid Github. --Quanah -- Quanah Gibson-Moun

(ITS#8826) Contrib dsaschema module needs updating for cn=config

2018-03-27 Thread quanah
Full_Name: Quanah Gibson-Mount Version: HEAD OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) The dsaschema contrib module needs updating so that it support cn=config

Re: (ITS#8825) slapo-memberof: memberof-memberof-ad doesn't work correctly

2018-03-27 Thread quanah
ntrib overlay requires development to support cn=config. The alternative to using an operational attribute is to have a custom objectClass where the custom attribute desired is defined as an optional ("MAY") attribute. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packa

(ITS#8825) slapo-memberof: memberof-memberof-ad doesn't work correctly

2018-03-27 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.45 OS: Linux URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) Per the slapo-memberof man page, you can define a different attribute than "memberOf" to hold the group membership information for an entry

Re: (ITS#8810) speeling-error

2018-02-24 Thread quanah
ian Lintian found a typo in libraries/libldap/os-local.c: "errror" > should be "error" > Patch attached Hi Andreas, Please always check OpenLDAP head before filing a report. :) commit c1512eea5818c81ff19d81d8aeae1967bab7e64f Author: Quanah Gibson-Mount <qua...@openlda

Re: (ITS#8809) tls_o failure when linking to OpenSSL 1.0.2 with "no-deprecated" compile flag

2018-02-23 Thread quanah
--On Friday, February 23, 2018 5:07 PM + Howard Chu <h...@symas.com> wrote: > qua...@openldap.org wrote: >> Full_Name: Quanah Gibson-Mount >> Version: HEAD >> OS: N/A >> URL: ftp://ftp.openldap.org/incoming/ >> Submission from: (NULL) (47.208.14

(ITS#8809) tls_o failure when linking to OpenSSL 1.0.2 with "no-deprecated" compile flag

2018-02-23 Thread quanah
Full_Name: Quanah Gibson-Mount Version: HEAD OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) When attempting to link OpenLDAP to OpenSSL 1.0.2 series, where OpenSSL has been built with deprecated API's disabled, the build will fail. This is because RSA_F4

Re: (ITS#8486) Syncprov sessionlog is inefficient, kills perf

2018-02-10 Thread quanah
switching to REFRESH Feb 10 19:09:54 anvil2 slapd[5580]: do_syncrep2: rid=100 (4096) Content Sync Refresh Required --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#8800) MMR: out of date master will ignore history of its own changes

2018-01-30 Thread quanah
--On Tuesday, January 30, 2018 9:04 PM + qua...@openldap.org wrote: > Full_Name: Quanah Gibson-Mount > Version: 2.4.45 > OS: Linux > URL: ftp://ftp.openldap.org/incoming/ > Submission from: (NULL) (47.208.148.239) > > > Did the following test: > > 4-way MMR

(ITS#8800) MMR: out of date master will ignore history of its own changes

2018-01-30 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.45 OS: Linux URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) Did the following test: 4-way MMR setup, database populated from an initial DB that has history to it Make several thousand MODs to serverID 1 only Stop

Re: (ITS#8100) Empty accesslog causes issues with delta-syncrepl MMR configurations

2018-01-29 Thread quanah
--On Monday, January 29, 2018 10:23 AM -0800 Quanah Gibson-Mount <qua...@symas.com> wrote: > I'll continue testing for the other half of the fix (Deleting all but the > most recent entry from the accesslog during purge) This part appears to work as desired. I set the purge in

Re: (ITS#8100) Empty accesslog causes issues with delta-syncrepl MMR configurations

2018-01-29 Thread quanah
--On Friday, January 26, 2018 8:23 PM + h...@symas.com wrote: > A patch which skips deleting the final entry, and creates an initial > dummy log entry if needed, is available in > https://github.com/quanah/openldap-scratch/tree/its8100 for testing. Hi Howard, When reinstalling a

(ITS#8799) slaptest fails to properly convert chain configuration

2018-01-22 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.45 OS: Linux URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) The process for converting a slapd configuration to cn=config making use of slapo-chain at a global level is seriously broken. This can be trivially

Re: (ITS#8766) Version 2.4.45 vulnerable - CVE-2017-14159

2018-01-15 Thread quanah
Hi Muthamma, If you read the CVE and follow the link to the related OpenLDAP ITS, you will discover that the reported issue was marked invalid. I.e., what was reported is not a security vulnerability, or will it ever be fixed. Hope this helps! Regards, Quanah -- Quanah Gibson-Mount Product

(ITS#8790) N-Way MMR w/o serverID in at least one entry causes REFRESH

2017-12-11 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.45 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) If one has configured N-WAY MMR in such a fashion that only one master ever gets the write ops (whether this is mirrormode or other methodologies

(ITS#8789) syncrepl fallback can destabilize delta-sync MMR nodes

2017-12-11 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.45 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) In a N-Way MMR setup, one node falling back to syncrepl REFRESH may destabilize other nodes, as it will incorrectly record changes it is receiving from the master

(ITS#8788) slapd-pcache undef not compatible with mdb

2017-12-11 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.45 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) The pcache backend to slapd has the option for attr sets to note if an attribute that being cached is not defined in the local schema by prefixing it with "

Re: (ITS#8429) deadlock on a modification operation with replication

2017-12-08 Thread quanah
--On Thursday, May 19, 2016 12:31 PM + elecha...@apache.org wrote: > Full_Name: Emmanuel Lecharny > Version: 2.4.44 > OS: Linux CentOS 6 > URL: ftp://ftp.openldap.org/incoming/ > Submission from: (NULL) (92.169.142.218) This should be fixed now, tracked under ITS#8752. --Qua

Re: (ITS#8774) [PATCH] EVP_MD_CTX_create and EVP_MD_CTX_destroy have been replaced by EVP_MD_CTX_new and EVP_MD_CTX_free in openssl v1.1 and above.

2017-11-17 Thread quanah
he 7th of November broke the build for > openssl < 1.1, as the patch used the newer versions of these functions. Thanks for the report! This issue has now been fixed in openldap head without the necessity of a configure check. Regards, Quanah -- Quanah Gibson-Mount Product Archit

(ITS#8773) slapo-deref: man page and test suite needed

2017-11-16 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.45 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) The slapo-deref overlay is missing a man page and a corresponding test in the test suite. These should be added to the project.

(ITS#8771) slapd.backends(5) needs updating

2017-11-08 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.45 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) The man page for slapd.backends(5) says that back-hdb is the "recommended primary backend". This needs to be updated to note that back-mdb is the &q

Re: (ITS#8461) Unable to import LDIF from back-hdb DB to back-mdb db

2017-11-08 Thread quanah
DB_BAD_VALSIZE: Too big key/data, key is empty, or wrong=20 DUPFIXED size (-30781) --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#7042) [PATCH] allow unsetting of tls_* options for syncrepl

2017-10-19 Thread quanah
Hi Patrick, What we need is for you to simply reply to this ITS with your IPR statement, and the patch attached. This will allow us to include it. IPR guidelines are here: <https://www.openldap.org/devel/contributing.html#notice> Thanks, Quanah -- Quanah Gibson-Mount Product Arc

Re: (ITS#8671) Declare ldap_init_fd() in ldap.h to help external consumers

2017-10-19 Thread quanah
--On Thursday, October 19, 2017 10:20 AM +0300 Alexander Bokovoy <aboko...@redhat.com> wrote: > Hi Quanah, > > On ti, 12 syys 2017, Quanah Gibson-Mount wrote: >> Hi Alexander, >> >> Your submission appears to be missing an IPR statement as noted at &

(ITS#8752) MMR delta-sync deadlock using slapd.conf

2017-10-04 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.45 OS: Linux URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) There is a reproducible lockup with delta-sync based multimaster replication. The more masters exist the easier it is to trigger, with 100% reproducibility

Re: (ITS#8748)

2017-09-29 Thread quanah
the public domain. Hence, > these modifications may be freely used and/or redistributed for any > purpose with or without attribution and/or other notice. Thanks! --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solut

(ITS#8743) slaptest segfault with invalid back-meta configuration

2017-09-27 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.45 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) When converting a slapd.conf file to cn=config, where the back-meta backend has an invalid configuration for the "filter" directive, slaptest wil

(ITS#8742) slapd.conf/slapd-config divergence

2017-09-26 Thread quanah
Full_Name: Quanah Gibson-Mount Version: HEAD OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) The slapd.conf(5) and slapd-config(5) man pages have some significant divergence that need fixing. Examples: slapd.conf(5): Used by the authentication framework

Re: (ITS#8687) openldap fails to link w/ openssl 1.1 built w/ no-egd

2017-09-22 Thread quanah
enldap/fi > les/openldap-2.4.45-no-EGD.patch Ok, I'll take a look at your patch as well. Mine is at: <https://github.com/quanah/openldap-scratch/commit/e126bf7ea3c2c7046b0884269= 4fdbf750200894f> Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certi

Re: (ITS#8687) openldap fails to link w/ openssl 1.1 built w/ no-egd

2017-09-19 Thread quanah
on that didn't have /dev/urandom available? --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#6300) Add kqueue support to slapd

2017-09-13 Thread quanah
Hi Bryan, I managed to track down a copy of your patch, and uploaded it to the OpenLDAP FTP server as bryan-duncan-its6300.patch. I will see about getting this updated for current OpenLDAP, for possible inclusion in OpenLDAP 2.5. Regards, Quanah --On Monday, September 11, 2017 11:45 PM

Re: (ITS#8671) Declare ldap_init_fd() in ldap.h to help external consumers

2017-09-12 Thread quanah
Hi Alexander, Your submission appears to be missing an IPR statement as noted at <https://www.openldap.org/devel/contributing.html#notice>. This is required for your submission to be evaluated. Please add an IPR at your earliest convenience. Thanks! --Quanah --On Wednesday, June 07

Re: (ITS#8707) slapd: Add systemd service notification support

2017-09-12 Thread quanah
ourse the unit file should only be installed if the configure switch > for systemd is enabled, and I believe the latest patch does this. I'll leave it to hyc to weigh in. It's not been the policy of the project so far to include such items. --Quanah -- Quanah Gibson-Mount Product Architect Sym

Re: (ITS#8692) back-sock does not create LDAP_MOD_INCREMENT message

2017-09-08 Thread quanah
ail to -devel soon covering all the ITSes I have queued up needing review. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#7996) Global initialisation race in ldap_int_initialize

2017-09-08 Thread quanah
e the original diff to = > work from. If you can send me a copy of the FTP submission I can = > reformat it and resubmit it. Hi Arran, The diff is in your github issues tracker. ;) <https://github.com/arr2036/ldapperf/issues/2#issuecomment-66242732> Thanks, Quanah -- Quanah

Re: (ITS#8427) Incorrect value of tls_reqcert in syncrepl

2017-09-07 Thread quanah
bmissions in the ITS system. This report is missing an IPR which is required for it to be included in the project. Please see <http://www.openldap.org/devel/contributing.html> and update this ITS with your IPR when possible. Thanks, Quanah -- Quanah Gibson-Mount Product Architect Symas Corpo

Re: (ITS#8578)

2017-09-07 Thread quanah
<http://www.openldap.org/devel/contributing.html>. Thanks, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#8508) PATCH - ucgendat.c properly add title-case characters without upper-case equivalents (e.g. greek letters with iota subscript)

2017-09-07 Thread quanah
Hello Zebediah, Thanks for your submission. However your report is missing an IPR which is required for it to be included with OpenLDAP. Please see <http://www.openldap.org/devel/contributing.html> for futher information on how to provide the required IPR information. Thanks,

Re: (ITS#8349) fix ppolicy issue

2017-09-07 Thread quanah
atching up on old ITS submissions. This submission is missing an IPR and cannot be included until it is provided. Please see <http://www.openldap.org/devel/contributing.html> for information on the IPR requirements. Thanks, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation

Re: (ITS#7996) Global initialisation race in ldap_int_initialize

2017-09-07 Thread quanah
t FTP server (include the URL in your email), then I can pull it in. Thanks, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#8436) slapadd hang in bdb_tool_entry_close / ldap_pvt_thread_cond_wait

2017-09-07 Thread quanah
ttp://www.openldap.org/devel/contributing.html> for the correct procedure for submitting your fix if you would like it to be included. Thanks, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#8724) slapo-pcache truncates remote results

2017-09-06 Thread quanah
sure you follow the contribution guidelines: <https://www.openldap.org/devel/contributing.html> Thanks, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#8724) slapo-pcache truncates remote results (fwd)

2017-09-06 Thread quanah
like to see a change in relation to this, patches welcome. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com> -- Quanah Gibson-Mount Product Architect Symas Corporation Pa

Re: (ITS#8724) slapo-pcache truncates remote results

2017-09-06 Thread quanah
t to the maxsize limitation. This ITS will be closed. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#6835) extend pwFailureTime timestamp to microsecond resolution to improve pwdMaxFailure enforcement

2017-08-30 Thread quanah
Hi Brian, I just wanted to follow up and let you know this was taken care of in ITS#7161 and the fix was part of the OpenLDAP 2.4.40 release. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <h

Re: (ITS#8716) Install error

2017-08-21 Thread quanah
gt;> &5 > cc: error: unrecognized command line option '-R' Hope that helps! This ITS will be closed. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

(ITS#8713) Delete slapd-ldbm.5 man page

2017-08-16 Thread quanah
Full_Name: Quanah Gibson-Mount Version: HEAD OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) We should delete the stub man page for slapd-ldbm(5) from our repository, as it died with OpenLDAP 2.3.

Re: (ITS#8690) syncprov memory leak

2017-08-03 Thread quanah
sd 30 5983d09b conn=1013 op=1 SEARCH RESULT tag=101 err=80 duration=-1427710511.244ms nentries=0 text=internal error Aug 3 18:40:43 ub16 kernel: [42374.949965] slapd[30897]: segfault at 804e ip 00007f93bccb5cc0 sp 7f93ba1aaa10 error 4 in libc-2.23.so[7f93bcc67000+1c] --Quanah --

(ITS#8705) Windows registry key creation incorrect

2017-08-02 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.45 OS: Windows 10 64-bit URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) When installing OpenLDAP on windows, it creates a registry key for the Eventlog to map startup/shutdown events. There was an attempt to fix

Re: (ITS#8690) syncprov memory leak

2017-08-01 Thread quanah
--On Tuesday, July 11, 2017 9:17 PM + qua...@symas.com wrote: > --On Tuesday, July 11, 2017 1:25 AM + qua...@openldap.org wrote: > >> Full_Name: Quanah Gibson-Mount >> Version: 2.4.45 >> OS: Linux >> URL: ftp://ftp.openldap.org/incoming/ >> Sub

Re: (ITS#8702) SLAPD_MAX_DAEMON_THREADS is too small

2017-08-01 Thread quanah
usage to dynamically allocated arrays. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

(ITS#8697) Remove refptr symbols from slapd.def

2017-07-20 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.45 OS: Windows 10 64-bit URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) When building OpenLDAP with a newer version of gcc, dlltool now exports a ton of ".refptr.FUNCTION" values out to the slapd.def file. T

(ITS#8695) _sleep is deprecated

2017-07-19 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.45 OS: Windows 10 64-bit URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) When building OpenLDAP, we find: C:/msys64/home/build/sold-master/openldap/tests/progs/slapd-read.c: In function 'do_read': C:/msys64/home/build

Re: (ITS#8694) Windows builds fail to install event information

2017-07-18 Thread quanah
--On Tuesday, July 18, 2017 5:15 PM + qua...@openldap.org wrote: > Full_Name: Quanah Gibson-Mount > Version: 2.4.45 > OS: Windows > URL: ftp://ftp.openldap.org/incoming/ > Submission from: (NULL) (47.208.148.239) > > > Running "slapd.exe install" is sup

(ITS#8694) Windows builds fail to install event information

2017-07-18 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.45 OS: Windows URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) Running "slapd.exe install" is supposed to add the event information in windows for startup/shutdown (1280/1281). However, this broke at

Re: (ITS#8690) syncprov memory leak

2017-07-11 Thread quanah
--On Tuesday, July 11, 2017 1:25 AM + qua...@openldap.org wrote: > Full_Name: Quanah Gibson-Mount > Version: 2.4.45 > OS: Linux > URL: ftp://ftp.openldap.org/incoming/ > Submission from: (NULL) (47.208.148.239) Better trace: ==1504== 20,123 bytes in 67 blocks are definite

(ITS#8690) syncprov memory leak

2017-07-10 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.45 OS: Linux URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) Setting up a 2-node MMR pair, using standard syncrepl in refreshAndPersist mode, shows there is a steady leak in syncprov on the master receiving write traffic

(ITS#8689) invalid rwm configuration causes slapd to SEGV

2017-07-10 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.45 OS: Linux URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) If you incorrectly configure slapo-rwm so that it has an invalid mapping, slapd will crash after a search is performed against the mapped base. For example

Re: (ITS#8688) Is it possible to control on the failover of backend LDAP?

2017-07-07 Thread quanah
ailing list. As this is not a bug report, this ITS will be closed. Please send your question(s) to the openldap-technical list. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

(ITS#8683) SLAPD_META_CLIENT_PR hidden behind LDAP_DEVEL

2017-07-05 Thread quanah
Full_Name: Quanah Gibson-Mount Version: RE24 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) The back-meta(5) man page discusses the following option: client-pr {accept-unsolicited|DISABLE|} This feature allows one to use RFC 2696

Re: (ITS#8680) OpenLDAP 2.4.45 for Windows

2017-06-30 Thread quanah
m for asking for that help would be the openldap-techni...@openldap.org list. Alternatively, I would note that my company (Symas) provides pre-built binaries of OpenLDAP for Windows with options for support. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certif

(ITS#8679) Update release download page

2017-06-23 Thread quanah
Full_Name: Quanah Gibson-Mount Version: N/A OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) Download page needs updating to: a) Have links to the checksums for the release tarballs b) Have an encrypted download link option

Re: (ITS#8100) Empty accesslog causes issues with delta-syncrepl MMR configurations

2017-06-22 Thread quanah
--On Thursday, April 09, 2015 5:42 AM + qua...@openldap.org wrote: > Full_Name: Quanah Gibson-Mount > Version: 2.4.39 > OS: Linux 2.6 > URL: ftp://ftp.openldap.org/incoming/ > Submission from: (NULL) (50.25.188.166) > > > When one has an MMR setup using delta-syncr

Re: (ITS#8664) lmdb fragmentation leads to DDoS for consumers

2017-06-09 Thread quanah
--On Thursday, June 01, 2017 12:22 AM + qua...@openldap.org wrote: > Full_Name: Quanah Gibson-Mount > Version: 2.4.44 > OS: Linux > URL: ftp://ftp.openldap.org/incoming/ > Submission from: (NULL) (47.208.148.239) Going to close this out, as the problem statement & other

(ITS#8673) Need duration logging for sync ops

2017-06-08 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.45 OS: Linux URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) We log the duration of an operation at stats level which allows being able to see how long a write OP took on a master. However we do not have any duration

Re: (ITS#8672) syncrepl with openldap 2.4.{40,42} and mdb backend

2017-06-08 Thread quanah
doing the modifications as well. Thanks! --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: ITS#8504 fix breaks Solaris builds

2017-06-07 Thread quanah
laris headers >> somewhere, >> maybe enabled by #define POSIX_C_SOURCE 1 or something like that? > > It's insanely long This patch fixed it on my box: quanah@sol11-3:~/git/sold-2445/openldap$ git diff diff --git a/libraries/liblmdb/mdb.c b/libraries/liblmdb/mdb.c index 8a62eff..1

Re: (ITS#8669) Slapd service becomes unresponsive intermittently

2017-06-07 Thread quanah
on your system (e.g. creating BDB's transaction > log files). Yep, there can be poorly written clients out there. I'd expect idletimeout = to be completely unrelated, given it's long standing existence and use. ;) --Quanah -- Quanah Gibson-Mount Product Architect Symas Corpora

Re: (ITS#8669) Slapd service becomes unresponsive intermittently

2017-06-07 Thread quanah
--On Wednesday, June 07, 2017 7:07 AM -0600 Joaquin Estrada=20 <jmestrad...@gmail.com> wrote: > Quanah, > > We are running the Berkley DB back-end, =C2=B3back-bdb=C2=B2 in the = slapd.conf > file. > > Our server vendor did the upgrade to version 2.4.39 last year in April.

Re: ITS#8504 fix breaks Solaris builds

2017-06-07 Thread quanah
return (__posix_sigwait(__setp, __signo)); } #endif /* !__lint */ #endif /* __PRAGMA_REDEFINE_EXTNAME */ #else /* (_POSIX_C_SOURCE - 0 >= 199506L) || ... */ extern int sigwait(); #endif /* (_POSIX_C_SOURCE - 0 >= 199506L) || ... */ #endif /* __STDC__ */ #endif /* defined(__EXTENSIO

Re: (ITS#8669) Slapd service becomes unresponsive intermittently

2017-06-06 Thread quanah
://ltb-project.org/wiki/download#openldap>), or if you require support for your deployment, Symas (my employer) offers packaged builds and various support options. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solution

ITS#8504 fix breaks Solaris builds

2017-06-06 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.45 OS: Solaris 11 URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) Building the liblmdb bundled with OpenLDAP 2.4.45 on Solaris 11 fails due to the fix for ITS#8504: quanah@ub16:~/git/openldap/openldap-2-4/libraries

Re: (ITS#8668) Cache overlay, unexpected behaviour and occasional segfaults

2017-06-06 Thread quanah
debuginfo etc bits are installed). You can grab pre-compiled packages for OpenLDAP 2.4.44 from the LTB project at <http://ltb-project.org/wiki/download#openldap>. I expect they'll have 2.4.45 packages available soon as well. Thanks, Quanah -- Quanah Gibson-Mount Product Architec

(ITS#8665) limits documentation update for glued databases

2017-06-01 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.43 OS: Linux URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) When using glued/subordinate databases, the "limits" directive needs to be set on the parent as well as subordinate dbs to be applied if there are glo

(ITS#8664) lmdb fragmentation leads to DDoS for consumers

2017-05-31 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.44 OS: Linux URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) If a back-mdb database becomes highly fragmented, it can spend a bit of time trying to find an open slot for an incoming write op. If it is a master server

(ITS#8663) slapo-memberof cannot replace "olcMemberOfRefInt"

2017-05-31 Thread quanah
Full_Name: Quanah Gibson-Mount Version: HEAD OS: Linux URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.148.239) While you can set olcMemberOfRefInt during an add operation when instantiating slapo-memberOf with cn=config, you cannot modify the value after that point

<    1   2   3   4   5   6   7   8   9   10   >