(ITS#9180) Update slapo-memberOf man page about replication

2020-03-09 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.49 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.128.236) After discussion with Howard, slapo-memberOf should be replication compatible on REFRESH as long as the dangling option is set to ignore. The man page should

Re: (ITS#9175) ldapsearch segfault

2020-02-21 Thread quanah
Thanks for the report, suggested fix has been applied. Regards, Quanah --On Friday, February 21, 2020 8:38 PM + lha...@meditech.com wrote: > --3b4d37059f1c0189 > Content-Type: text/plain; charset="UTF-8" > Content-Transfer-Encoding: quoted-printable > &g

Re: (ITS#9173) Openldap configuration

2020-02-17 Thread quanah
is ITS will be closed. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#9168) Memory Leak in LDAP search operation

2020-02-13 Thread quanah
--On Thursday, February 13, 2020 4:50 PM + bananashake2...@yahoo.de wrote: > Full_Name: Stefan Koch > Version: 2.4.44 Hello, The 2.4.44 release is over 4 years old. Please use a current OpenLDAP release prior to reporting bugs. This ITS will be closed. Regards, Quanah --

Re: (ITS#9167) Using OpenLDAP as Proxy

2020-02-13 Thread quanah
tions such as this. This ITS will be closed. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#9164) back-monitor returning non-requested attributes

2020-02-06 Thread quanah
--On Thursday, February 6, 2020 8:47 PM + qua...@openldap.org wrote: > This appears to be because they (IMHO) incorrectly SUP monitoredInfo or > monitorCounter Or, thinking on it further, I think this is ok, just not what I expected. I'll close the ITS. ;) --Quanah -- Quanah

(ITS#9164) back-monitor returning non-requested attributes

2020-02-06 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.49 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.128.236) The new additions to back-monitor to expose more data from back-mdb are returning unrequested attributes. For example: ldapsearch -x -LLL -H ldap:/// -s base -b

Re: (ITS#9162) dbMaxSize property does not as expected

2020-02-03 Thread quanah
with an already broken database. This ITS will be closed. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#9161) Codespell report for "OpenLDAP" (on fossies.org)

2020-01-30 Thread quanah
> > > The FOSS server fossies.org - also supporting "OpenLDAP" - offers a new > feature "Source code misspelling reports": This is very nice, thank you. Definitely some items in here that need fixing. Regards, Quanah -- Quanah Gibson-Mount Product

Re: (ITS#9159) mdb_put failed: MDB_MAP_FULL: Environment mapsize limit reached(-30792)

2020-01-30 Thread quanah
--On Thursday, January 30, 2020 2:38 PM +0530 Vijay Kumar wrote: > > > Thank you Quanah, > > I am not familiar about your process of subscribing to lists. > I have gone though the documentation to understand the mdb size for > windows. Can you please share me the do

Re: (ITS#9159) mdb_put failed: MDB_MAP_FULL: Environment mapsize limit reached(-30792)

2020-01-29 Thread quanah
on. This system is for bug reports only. > No reply to us.! I did reply. This is clearly shown in the ITS. > Please let us know answer to solve a issue.! I already provided you the answer in my earlier response. Set an approprate maxsize setting, the default of 10MB is clearly too low. Reg

Re: (ITS#9159) mdb_put failed: MDB_MAP_FULL: Environment mapsize limit reached(-30792)

2020-01-29 Thread quanah
e parameter determines what the allowed maximum size of the database is. If you do not set the parameter, it limits the database to 10MB in size (The default value). Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions

(ITS#9152) Configuring autoca before database exists crashes slapd

2020-01-13 Thread quanah
Full_Name: Quanah Gibson-Mount Version: HEAD OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.143.26) If you configure autoca via cn=config when the underlying DB does not yet exist, slapd will crash. i.e., I added this entry to my cn=config db: dn: olcOverlay

Re: (ITS#9143) Segfault in libcrypto.so.1.1

2019-12-19 Thread quanah
ld, you'll need to dig deeper into the issues, as you're a bit outside of what Debian/Ubuntu do with OpenLDAP. I would note that at least for Ubuntu 18, there is already a backport provided of the 2.4.48 release that does not appear to exhibit the issues you describe. Regards, Quanah -

Re: (ITS#9143) Segfault in libcrypto.so.1.1

2019-12-19 Thread quanah
advise contacting the Debian/Ubuntu project and their GnuTLS package maintainers specifically. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#9144) Remove ICU detection

2019-12-19 Thread quanah
--On Thursday, December 19, 2019 9:36 PM + qua...@openldap.org wrote: > Full_Name: Quanah Gibson-Mount > Version: 2.4.48 > OS: N/A > URL: ftp://ftp.openldap.org/incoming/ > Submission from: (NULL) (47.208.143.26) > > > In 2005, ICU library detection was added to th

(ITS#9144) Remove ICU detection

2019-12-19 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.48 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.143.26) In 2005, ICU library detection was added to the build process, however nothing was ever added to use it. This can result in an unwanted dependency when building

Re: (ITS#9142) LDAP Connection Close

2019-12-15 Thread quanah
nly. Questions about OpenLDAP functionality should be directed to the openldap-technical mailing list. Your log shows no issues. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#8980) Async mode and TLS Non-Blocking Issue

2019-12-05 Thread quanah
--On Thursday, December 5, 2019 9:27 PM + "Sun, Wei" wrote: > It seems to be that on the 2.4.48 release, in file tls2.c, > LDAP_USE_NON_BLOCKING_TLS is tied to LDAP_DEVEL, however, on the main > branch, it is enabled by default? Because it is a 2.5 feature. Regards,

(ITS#9122) slapadd with dry run fails with back-mdb

2019-11-25 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.48 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.143.26) When testing an slapadd import with back-mdb as the database backend, it errors out incorrectly with a unknown attribute error: slapadd -F /tmp/slapd.d -l slapd

(ITS#9121) dynlist enhancements

2019-11-20 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.143.26) There are some enhancements to dynlist that would make it more useful/versatile: a) Be able to do (unique)member= searches to find all groups a given group member

(ITS#9119) back-monitor can miscount monitorOpCompleted

2019-11-15 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.43 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.143.26) When querying the monitor backend for monitorOpCompleted, the results are inconsistent. The code that calculates this value is also inefficient

(ITS#9118) Add support for MAP_NOSYNC

2019-11-15 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.48 OS: FreeBSD 11 URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.143.26) To improve back-mdb performance on LMDB when dbnosync is set, it would be useful to support MAP_NOSYNC as documented at http://nixdoc.net/man-pages/FreeBSD

Re: (ITS#9115) It seems like the parameters about tlsCipherSuite not work

2019-11-07 Thread quanah
e redirect your question to the openldap-technical list for further assistance. <https://www.openldap.org/lists/mm/listinfo/openldap-technical> Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions power

Re: (ITS#9113) i can not find memberOf.la file

2019-11-07 Thread quanah
e redirect your question to the openldap-technical list for further assistance. <https://www.openldap.org/lists/mm/listinfo/openldap-technical> Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#9114) pagedResultsControl not available in openldap search response

2019-11-07 Thread quanah
quests. Please redirect your question to the openldap-technical list for further assistance. <https://www.openldap.org/lists/mm/listinfo/openldap-technical> Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#9107) new feature

2019-10-28 Thread quanah
--On Monday, October 28, 2019 2:33 AM + ydgd...@163.com wrote: > Full_Name: Nannan Song I would ask in the future that you not spam the bug system with 8 copies of the same report. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and suppor

(ITS#9102) Update sasl-secprops ssf wording

2019-10-25 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.48 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.154.120) The slapd.conf(5)/slapd-config(5) man pages contain this wording for the sasl-secprops keyword: 0 (zero) implies no protection, 1 implies integrity

Re: (ITS#9101) man pages don't reflect some global options are actually global/database

2019-10-25 Thread quanah
--On Friday, October 25, 2019 10:09 PM + qua...@openldap.org wrote: > Full_Name: Quanah Gibson-Mount > Version: 2.4.48 > OS: N/A > URL: ftp://ftp.openldap.org/incoming/ > Submission from: (NULL) (47.208.154.120) > > > The slapd.conf(5)/slapd-config(5) man

(ITS#9101) man pages don't reflect some global options are actually global/database

2019-10-25 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.48 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.154.120) The slapd.conf(5)/slapd-config(5) man pages list the security/olcSecurity configuration option as a "GLOBAL" only config option. However, inspection o

Re: (ITS#9098) assert fails in meta_back_search in some cases after reconnect

2019-10-16 Thread quanah
4.48 to pick up this fix: Fixed slapd-meta assertion when network interface goes down (ITS#8841) --Quaanh -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#9018) dynlist don't close connection

2019-10-14 Thread quanah
Decoded we have: "I have changed back-meta to the back-ldap, and it resolved this problem." --On Tuesday, September 24, 2019 11:59 AM + i.har...@a1.by wrote: -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered b

Re: (ITS#9092) LDAP server out of memory

2019-10-10 Thread quanah
org/support/> This ITS will be closed. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

RE: (ITS#9088) Concurrency not seen in OpenLDAP 2.4.44

2019-09-27 Thread quanah
--On Friday, September 27, 2019 10:50 AM + Rajalakshmi Jayaraman wrote: > > > Hi Quanah, > > Can we have a solution for the issue reported at the earliest. Since we > have a release and the fix needs to be done. Hello Raji, If you need an immediate fix to an i

RE: (ITS#9088) Concurrency not seen in OpenLDAP 2.4.44

2019-09-26 Thread quanah
--On Thursday, September 26, 2019 3:11 PM + Rajalakshmi Jayaraman wrote: > > > Hi, > > The FTP "ftp://ftp.openldap.org/incoming/; is not working. Hence pasted > the pcap details, hope this helps It's working just fine: quanah@ub18:~$ ftp ftp.openldap.org Connec

RE: (ITS#9088) Concurrency not seen in OpenLDAP 2.4.44

2019-09-26 Thread quanah
l. (pl. find attached the pcap) for > reference Please put your pcap file on the FTP server rather than sending it via the ITS system. Then respond to the ITS with a link to the file. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supporte

Re: (ITS#9088) Concurrency not seen in OpenLDAP 2.4.44

2019-09-23 Thread quanah
.org/documentation/openldap-rpm#yum_repository> Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#9082) Issues while upgrading to 2.4.48

2019-09-17 Thread quanah
nldap.org/lists/mm/listinfo/openldap-technical> <https://www.openldap.org/lists/openldap-technical/> <https://www.openldap.org/lists/openldap-technical/201908/msg00157.html> This ITS will be closed. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packag

Re: (ITS#9079 documentation: slapo-unique syntax explanation unclear

2019-09-13 Thread quanah
--On Friday, September 13, 2019 6:07 PM + g...@nxg.name wrote: > Full_Name: Norman Gray > Version: 2.4.48 > OS: FreeBSD 12.0 > URL: ftp://ftp.openldap.org/incoming/ > Submission from: (NULL) (130.209.45.140) Note: this is now ITS#9079. --Quanah -- Quanah Gibson-Mount Pr

Re: (ITS#9078) Indices MDB

2019-09-13 Thread quanah
/mm/listinfo/openldap-technical> --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#9077) slapo-unique spins its wheels on a non-trivial olcUniqueURI spec

2019-09-13 Thread quanah
--On Friday, September 13, 2019 4:34 PM + g...@nxg.name wrote: > Full_Name: Norman Gray > Version: 2.4.48 > OS: FreeBSD 12.0 > URL: ftp://ftp.openldap.org/incoming/ > Submission from: (NULL) (130.209.45.140) Unrelated side note, ITS number fixed to be 9077. --Quanah --

Re: (ITS#9072) openLdap client problem

2019-08-30 Thread quanah
op filing ITSes until such a time as you have upgraded to a current release. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#9070) Failing to include openssl1.1.1c with openLDAP

2019-08-29 Thread quanah
nldap.org/lists/mm/listinfo/openldap-technical> This ITS will be closed. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

(ITS#9071) Invalid olcDbStartTLS values generated on back-ldap conversion

2019-08-29 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.48 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.128.44) When converting this basic slapd.conf for back-ldap: include /usr/local/etc/openldap/schema/core.schema include /usr/local/etc/openldap/schema

Re: (ITS#9066) Missing custom attrs after restart slapd

2019-08-22 Thread quanah
ldap browser, but after > restart sldap daemon, custom attrs are missing (sorry, bad english) > OLC mode and mdb database Hello, That is not the correct way to modify the schema or add new attributes. Please use the openldap-techni...@openldap.org list for help. This ITS will be closed. Rega

(ITS#9065) slapo-ppolicy(5) man page refers to wrong attribute

2019-08-19 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.48 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.128.44) The slapo-ppolicy(5) man page has this statement in the description of pwdGraceUseTime: If too many grace logins have been used (please refer

Re: (ITS#9064) client tools not recognizing BINDDN from ldap.conf

2019-08-17 Thread quanah
sed. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#9062) Please have /build/mkdep respect TMPDIR if set

2019-08-13 Thread quanah
--On Sunday, August 11, 2019 7:34 PM + zag...@oclc.org wrote: > Would you please consider changing this to: > > TMP=${TMPDIR-/tmp}/mkdep$$ Thanks for the report, this is fixed in OpenLDAP master. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation

(ITS#9063) tls_reqcert in slapd.conf/slapd-config man pages should be bold

2019-08-12 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.48 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.128.44) When looking at the man pages, the tls_reqcert description in the section of the man page about syncrepl is missing a BOLD tag, unlike the other keywords. Trivial

Re: (ITS#9061) LDAP replication issue on a big network

2019-08-07 Thread quanah
ckports repo. This ITS will be closed. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#9059) session log parsing triggers cascading REFRESH

2019-08-01 Thread quanah
--On Thursday, August 01, 2019 4:16 PM + qua...@openldap.org wrote: > Full_Name: Quanah Gibson-Mount > Version: 2.4.47 > OS: N/A > URL: ftp://ftp.openldap.org/incoming/ > Submission from: (NULL) (47.208.128.44) > > > In investigating why a particular consumer went i

(ITS#9059) session log parsing triggers cascading REFRESH

2019-08-01 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.47 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.128.44) In investigating why a particular consumer went into REFRESH mode, I find that this was triggered by one of its providers currently parsing a sessionlog

Re: (ITS#9052) ACL protections get lost if same identity uses different SSF levels

2019-07-24 Thread quanah
--On Wednesday, July 24, 2019 3:45 PM -0700 Quanah Gibson-Mount wrote: > For informational purposes, here's additional detail as the subject and > original problem description do not fully capture the extend of the > problem. In all 2.x releases prior to 2.4.48 (I.e., 2.0.x, 2.1

Re: (ITS#9052) ACL protections get lost if same identity uses different SSF levels

2019-07-24 Thread quanah
to attrs=userPassword by self sasl_ssf=56 =xw by * auth Would allow a user to change their own password whether or not they had performed a SASL bind with a sasl_ssf of 56. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions

Re: (ITS#9056) Replication does not work with different schemas on primary and secondary LDAP

2019-07-23 Thread quanah
ema on replicas first, then on masters Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#7326) additional notes

2019-07-19 Thread quanah
//bugzilla.redhat.com/show_bug.cgi?id=699576> --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#7326) [PATCH] use AI_ADDRCONFIG if defined in the environment

2019-07-19 Thread quanah
bmit patches that depend on custom RedHat implementations of core libraries. Thanks. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#9055) contrib/slapd-modules/passwd/totp improvements

2019-07-18 Thread quanah
of the time slice is of course a security issue and should not be allowed by default (So the default value of the parameter should be 0). Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#9054) Add support for multiple EECDH curves

2019-07-16 Thread quanah
--On Tuesday, July 16, 2019 9:45 PM + qua...@openldap.org wrote: > Full_Name: Quanah Gibson-Mount > Version: 2.4.47 > OS: N/A > URL: ftp://ftp.openldap.org/incoming/ > Submission from: (NULL) (47.208.128.44) > > > Currently OpenLDAP only allows for a single EECD

(ITS#9054) Add support for multiple EECDH curves

2019-07-16 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.47 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.128.44) Currently OpenLDAP only allows for a single EECDH curve to be configured. However, OpenSSL 1.0.2 released in January 2015 was the first release to implement

Re: (ITS#9051) slapo-accesslog fails to log compare, search

2019-07-08 Thread quanah
: reqStart=20190709001033.00Z,cn=accesslog objectClass: auditBind reqStart: 20190709001033.00Z reqEnd: 20190709001033.01Z reqType: bind reqSession: 1019 reqAuthzID: reqDN: cn=admin,dc=rb,dc=symas,dc=net reqResult: 0 reqVersion: 3 reqMethod: SIMPLE --Quanah -- Quanah Gibson-Mount

(ITS#9051) slapo-accesslog fails to log compare, search

2019-07-08 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.47 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.128.44) In testing out various logging scenarios with the accesslog overlay, it has been found that it fails to log certain operations in the underlying accesslog DB

Re: (ITS#8977) Make IDL sizes configurable in back-mdb

2019-07-08 Thread quanah
( 64 * 1024 * 1024 * sizeof(void *) ) Generally, this feature is simply unusuable (currently) as a tunable given the requirement for recompiling OpenLDAP to use it. --QUanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered

Re: (ITS#8875) [Patch] Performance problems in back-mdb with large DITs and many aliases

2019-06-27 Thread quanah
constants. Had a customer who was hitting this issue try out these patches -- It greatly decreases the search time (from unknown/infinite to 1 minute). Unfortunately slapd then segv's. Working on getting a test database to reproduce the issue with for a good backtrace. --Quanah -- Quanah Gib

Re: (ITS#8427) Incorrect value of tls_reqcert in syncrepl

2019-06-27 Thread quanah
Hello, Unfortunately this patch introduces a regression and breaks existing configurations where the protocol in use is ldaps:///. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <h

Re: Regression after ITS#8427 fix with back-ldap

2019-06-27 Thread quanah
9-06-27T20:46:07.613718+00:00 arrakis slapd-2.4-aa[14682]: conn=1011 > fd=12 closed (TLS negotiation failure) Thanks! Please include the openldap-its list in your replies so that they properly get associated with the relevant ITS. I'll raise this up as a priority for the 2.4.48 release.

Re: Regression after ITS#8427 fix with back-ldap

2019-06-27 Thread quanah
re noted on the openldap-devel list as well. Does the issue persist if you set: olcDbStartTLS: ldaps as documented in the slapd-ldap(5) man page? Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#8977) Make IDL sizes configurable in back-mdb

2019-06-27 Thread quanah
--On Thursday, June 27, 2019 8:35 PM + h...@symas.com wrote: > No, because order is irrelevant for these. Cool, thanks! I'll continue on with deeper testing then. :) --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP soluti

Re: (ITS#8977) Make IDL sizes configurable in back-mdb

2019-06-27 Thread quanah
:19 'olcDatabase={0}config.ldif' -rw--- 1 root root 859 Jun 27 12:19 'olcDatabase={1}mdb.ldif' I.e., I was rather expecting: olcBackend={1}mdb.ldif or similar. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powe

Re: (ITS#8977) Make IDL sizes configurable in back-mdb

2019-06-25 Thread quanah
lapd.conf to cn=config be fixed so that it works. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#9042) loglevel setting that allows seeing attribute values for MOD operations

2019-06-25 Thread quanah
ntrol of the client to > be able to set a loglevel that would expose this information. STATS2 would be the appropriate loglevel setting. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

(ITS#9042) loglevel setting that allows seeing attribute values for MOD operations

2019-06-25 Thread quanah
Full_Name: Quanah Gibson-Mount Version: HEAD OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.128.44) Currently there is no way to see what values a client is providing for a MOD operation outside of the "packets" debug level. It would be helpful for

Re: (ITS#9041) cyrus.c includes limits.h twice

2019-06-25 Thread quanah
--On Friday, June 21, 2019 10:58 PM + qua...@openldap.org wrote: > This should be cleaned up. Fixed in b02807ea2f5eaf85e57e67e5851931a116947b94 --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: &l

(ITS#9041) cyrus.c includes limits.h twice

2019-06-21 Thread quanah
Full_Name: Quanah Gibson-Mount Version: RE24 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.128.44) There appear to have been dueling commits on April 10, 2005 and April 9, 2005, so that we get: 3e800f20bd (Kurt Zeilenga 2005-04-10 19:32:14 + 28

Re: (ITS#7996) Tighten race in ldap_int_initialize

2019-06-17 Thread quanah
us any passwords and the=20 like)? Additionally, if you could get a full gdb backtrace of the hung slapd=20 process that would be useful as well. I.e.: start up slapd gdb /path/to/slapd at the gdb prompt: thr apply all bt full Thanks! --Quanah -- Quanah Gibson-Mount Product Architect

Re: (ITS#7996) Tighten race in ldap_int_initialize

2019-06-17 Thread quanah
c/openldap/ldap.conf ^C I.e., it started and then got as far as reading your ldap.conf file. What=20 is the contents of ldap.conf? Have you run the test suite (make test)? Does it pass? fail? Thanks, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#7996) Tighten race in ldap_int_initialize

2019-06-16 Thread quanah
--On Sunday, June 16, 2019 7:54 PM + qua...@symas.com wrote: > --On Sunday, June 16, 2019 4:06 PM +0200 Armin T=C3=BCting=20 > wrote: > >> Hello Quanah, >> >> I'm following OPENLDAP_REL_ENG_2_4. The commit >> 'cde56fad154fcd25e351c3cd84d8173d263b0a01' br

Re: (ITS#7996) Tighten race in ldap_int_initialize

2019-06-16 Thread quanah
--On Sunday, June 16, 2019 4:06 PM +0200 Armin T=C3=BCting=20 wrote: > Hello Quanah, > > I'm following OPENLDAP_REL_ENG_2_4. The commit > 'cde56fad154fcd25e351c3cd84d8173d263b0a01' breaks starting slapd. It > won't start at all... > > I'm using a fairly up-to-date CentOS

Re: (ITS#9033) Computer Object

2019-06-13 Thread quanah
s for reporting bugs, not asking usage questions. Please use the openldap-techni...@openldap.org mailing lists for questions such as those above (<https://www.openldap.org/lists/mm/listinfo/openldap-technical>). --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporatio

(ITS#9031) Guide updates for 2.4

2019-06-07 Thread quanah
Full_Name: Quanah Gibson-Mount Version: 2.4.47 OS: N/A URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.128.44) The admin guide for delta-syncrepl needs updating. For example, it is missing the reqDN attribute being indexed. Additionally, it should be updated to reference

Re: (ITS#8962) Dead links in FAQ page "Where can I find listings of schema items?"

2019-06-07 Thread quanah
it's time for the existing FAQ to die. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#8946) openldap bug

2019-06-06 Thread quanah
Hello, There is no bug here. Your configuration is invalid. If you need help with configuring OpenLDAP, then please use the openldap-techni...@openldap.org mailing list. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP

Re: (ITS#8962) Dead links in FAQ page "Where can I find listings of schema items?"

2019-06-06 Thread quanah
te an answer. I think the better solution is just to remove the FAQ software completely. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#8988) Undefined Behavior in slapadd

2019-06-06 Thread quanah
), LMDB doesn't use them. This ITS will be closed. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#9029) MDB_MAP_FULL error after removing some records from DB

2019-06-05 Thread quanah
noted in the documentation, the general expectation is one sets a very large mapsize from the start. Hope that helps! --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#9029) MDB_MAP_FULL error after removing some records from DB

2019-06-04 Thread quanah
.org/its/index.cgi/?findid=8969> --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#8417) mdb_load could use an option to specify the mapsize.

2019-06-04 Thread quanah
d for any > purpose with or without attribution and/or other notice. > > https://eriix.org/download_file/eric-monson-16-05-03.patch This URL is not accessible (requires a login?). I suggest uploading it to our FTP server as documented for contributed patches. Thanks! --Quanah -- Quanah Gi

Re: (ITS#9028) Not able to add 'syncprov' module

2019-05-26 Thread quanah
enldap-technical>) This ITS will be closed. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#9025) Suggested enhancement: Automatically order module loading according to dependencies

2019-05-18 Thread quanah
tioning as expected. I've never encountered a situation where the order in which moduleload executes matters. Can you please provide an example configuration exhibiting problematic behavior based on moduleload order? Thanks, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation P

Re: (ITS#8060) mdb_from_db (bdb import)

2019-05-17 Thread quanah
ubmission is missing a required IPR, as noted at <https://www.openldap.org/devel/contributing.html#notice> An IPR is necessary to consider this work. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#8986) [PATCH] Fix union semun undefined from FreeBSD 12 onward

2019-05-17 Thread quanah
--On Friday, May 17, 2019 5:30 PM + khng...@gmail.com wrote: > Bump. I've added this to the review list. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: (ITS#9024) [PATCH] Fix union semun undefined from FreeBSD 12 onward

2019-05-17 Thread quanah
e help close ITS#8986 as this version is a resend of the > patch. The correct path is to follow up to your original ITS, not submit a new one. This ITS will be closed. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions po

RE: (ITS#9023) crash using ppolicy chaining from slave to master

2019-05-17 Thread quanah
--On Friday, May 17, 2019 4:09 PM + "AYANIDES, JEAN-PHILIPPE" wrote: > > > Hello Quanah, > > I am not very familiar with gdb. Can you help me doing that? Start slapd on the server that's crashing Get the process ID of slapd gdb /path/to/slapd PID For example, if

Re: (ITS#9023) crash using ppolicy chaining from slave to master

2019-05-17 Thread quanah
d > updateref in order to sync failures in ppolicy coming from rada back to > simby. When I test that feature, with trying a bind with a wrong > password, openldap on the slave crashes. I failed in understanding why, > even with gdb. Ensure you have debugging symbols installed, and provide a

Re: (ITS#9008) module rpath incorrect

2019-05-13 Thread quanah
ng system. More work needed, either removing libtool from the build process for OpenLDAP, or modifications to this work to allow it to work properly with a non-custom version of libtool. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and suppor

Re: (ITS#8700) Compile error

2019-05-10 Thread quanah
--disable-slapd > --disable-slurpd > > Undefined symbols for architecture x86_64: > "_ERR_remove_thread_state", referenced from: > _tlso_destroy in libldap.a(tls_o.o) Hello, What version of OpenSSL were you linking against? Thanks! -

(ITS#9022) Force slapadd to rewrite all entryCSN values

2019-05-10 Thread quanah
Full_Name: Quanah Gibson-Mount Version: OpenLDAP 2.4 OS: 2.4.47 URL: ftp://ftp.openldap.org/incoming/ Submission from: (NULL) (47.208.128.44) Per the slapadd man page: -S SID Server ID to use in generated entryCSN. Also used for contextCSN if -w is set as well. Defaults

Re: (ITS#9021) TLS: can't connect: TLS: hostname does not match CN in peer certificate

2019-05-10 Thread quanah
value in the certificate, for example: subjectAltName=IP:1.2.3.4 > Also want to know if there is any open CVE which says it is > vulnerabilities to use LDAP server ip address instead of name in ldap > configuration. I'm not aware of any such CVE or why there would be one. --Quanah -- Quan

Re: (ITS#9021) TLS: can't connect: TLS: hostname does not match CN in peer certificate

2019-05-10 Thread quanah
ior was changed where we must > have to configure FQDN name mentioned in certificate in order to work LDAP > authentication... else TLS start failing. OpenLDAP has worked this way since I first started using it in 2002. This behavior is nothing new. And this is the correct behavior. This

Re: (ITS#8708) SASL EXTERNAL binds and sasl-secprops minssf

2019-05-09 Thread quanah
I've closed ITS#8708 and noted that the fix for ITS#8796 resolved it. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

  1   2   3   4   5   6   7   8   9   10   >