Re: slapd cores

2007-04-23 Thread Howard Chu
y help me? WBR Dmitriy -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: Syncrepl, and some objectClass errors

2007-04-23 Thread Howard Chu
her or not the new version fixes it, but I have built the new version and am now running it on a test server. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: Best practise for syncrepl security & latency?

2007-04-23 Thread Howard Chu
k over the documentation. Are you sure? Howard suggested I use it in his response to ITS #4691 (which, now that I have a failover site again, I may be able to reproduce again to test this). I probably missed whether you were using refreshOnly or refreshAndPersist... -- -- Howard Chu

Re: Syncrepl, and some objectClass errors

2007-04-23 Thread Howard Chu
Lesley Walker wrote: Howard Chu wrote: This is most likely ITS#4813, fixed in 2.3.34. As noted in that ITS, it's a bit tricky to manually reproduce the problem since it's quite timing dependent. Many thanks for the confirmation. Is the fix in the provider or the consumer? Or b

Re: Replication failure after error fixed

2007-04-24 Thread Howard Chu
rly soon. In the meantime, I expect to finish merging GNUtls support in the next few days so that we can release a 2.4 beta. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: Pcache overlay bug or undocumented "feature"?

2007-04-24 Thread Howard Chu
ic proxyattrset, but i'm curious about if this behaviour is the intended one or if I should fill an ITS with a patch (the change in code would be minimal), what do you think? No, just delete the other proxyattrset directive, you don't need it at all. -- -- Howard Chu Chief Archi

Re: TLS/SSL problem - unsupported certificate purpose

2007-04-24 Thread Howard Chu
Jean-Claude wrote: Hello, I found a very similar and recent post on the Mailing List but no solution. May be I missed something. The solution was in this post: http://www.openldap.org/lists/openldap-software/200704/msg00129.html -- -- Howard Chu Chief Architect, Symas Corp. http

Re: Ppolicy DIGEST-MD5 ignore expired password

2007-04-25 Thread Howard Chu
defined in LDAP only affect Simple Binds. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: slapd becoming mysteriously slow

2007-04-25 Thread Howard Chu
uld try out this package and see if they can explain the behavior (or reproduce it at all, as the case may be). Thanks in advance Johan Jönemo -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Archite

Re: Sort ldap results

2007-04-25 Thread Howard Chu
is a no-op, which is in full compliance with the SSS spec. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: Ppolicy DIGEST-MD5 ignore expired password

2007-04-25 Thread Howard Chu
is certainly desirable, but pushing the SASL specification is really outside the scope of LDAP. So yes, we are pushing for this, but have no idea how long it will take. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com

Re: back-config: close database, keep suffix

2007-05-02 Thread Howard Chu
ients seeing its subtree temporarily disappear. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

SambaXP talk

2007-05-03 Thread Howard Chu
x27;s not marketing hype; we can prove every point. AMD and Intel make a big deal about piddly 20% differences between their products. We are over 300% faster than the next closest offering. Other projects and vendors talk about how superior they are (or hope to be) but it's pretty clear

Re: SambaXP talk

2007-05-05 Thread Howard Chu
Tony Earnshaw wrote: Howard Chu skrev, on 03-05-2007 17:14: For anyone curious, the slides from my presentation at the SambaXP conference last week are now up on my web site. http://highlandsun.com/hyc/SambaXP.pdf Thanks, wish I could have been there - this is a real eye-opener

Re: Overlay documentation

2007-05-08 Thread Howard Chu
Guide is still being revised. Some overlay tech tips are available here http://www.connexitor.com/forums/viewforum.php?f=6&sid=fdfc1407c56063c929743b30e0079b2b You can also examine the test scripts in the test suite to see how various features are used. -- -- Howard Chu Chief Architec

Re: Search replies processed twice?

2007-05-10 Thread Howard Chu
subsearch invokes your overlay again, therefore the callback exists twice in the callback stack so it runs twice. You need to check earlier for this case and return if you're already inside your subsearch. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Hi

Re: cn=schema,cn=config schema insertion

2007-05-11 Thread Howard Chu
onsidered modifying right now. So: yes, it's a > missing feature, but it's known (and I think it's documented, although > I'm unable to point you to the right docs right now). It is implemented in 2.4. The changes will not be backported to 2.3. -- Howard Chu Chief

Re: Compiling for the Win32 platform?

2007-05-14 Thread Howard Chu
and a decent regex library first. I use Henry Spencer's regex. Thanks! Joe . -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: configuration in the db

2007-05-14 Thread Howard Chu
7;t fix/available at that time. Has this been fixed/ready now. Replication of LDAP configuration is available in 2.4. Is any one using it ? Comments ? I think if you check the archives you'll see a couple people reporting success with it. It works fine. -- -- Howard Chu Chief Architec

Re: Compiling for the Win32 platform?

2007-05-15 Thread Howard Chu
/regex/rxspencer-alpha3.8.g3.tar.gz -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: logleven pcache

2007-05-16 Thread Howard Chu
used in test020; that test cannot succeed without it. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: slurpd replication problem

2007-05-17 Thread Howard Chu
="ldap://ldap.intelligraphics.com"; slapd.conf directives don't use "=" equal signs. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: slapd hanging on startup, apparently in BDB mutex lock?

2007-05-19 Thread Howard Chu
known bugs in both. In the current OpenLDAP releases we detect unclean shutdowns and recover automatically, among other things. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: IDL cache and a mix of index/unindexed attrs in a query

2007-05-22 Thread Howard Chu
rms, the resulting candidate list can only be zero or one entries long, regardless of any other indexing. So in this case, you'd save memory and update times by leaving the other attributes unindexed. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director,

Re: ber_scanf and ber_printf strangeness

2007-05-23 Thread Howard Chu
ode example on the end shows that '{v}' should be used. So what is the right way? It looks like the manpage example is wrong. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: ber_scanf and ber_printf strangeness

2007-05-23 Thread Howard Chu
Howard Chu wrote: Szombathelyi György wrote: Hi! I'm developing kldap, a Qt wrapper for LDAP-functions. When I tested ber_scanf and ber_printf functions, I found this strangeness: Encode a sequence of octet strings via ber_printf ber_printf(ber,"{v}",list_of_strings); Bu

Re: Building OpenLDAP with VS.NET2003

2007-05-24 Thread Howard Chu
ld script. (Also I've only done this with VC6; VC8 will probably require some more tweaks of its own. At this point there are so many different MSVC CRT DLLs to keep track of it's just not worth the effort any more.) I suspect the wgcc tool may work as well but I haven't used it o

Re: duplicate attributetype: 2.5.4.2

2007-05-25 Thread Howard Chu
r slapd, and it's not just a warning, it's a fatal error. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: how to create db files

2007-05-25 Thread Howard Chu
coming from a slaptest invocation in your init script. Comment out the slaptest, or start slapd by hand. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: server startup overhead

2007-05-25 Thread Howard Chu
will hit every entry in the DB and fully prime the DN cache (and the DN-related info in the IDL cache). It will cycle the full contents of the dn2id and id2entry DBs through the BDB cache as well. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sun

Re: server startup overhead

2007-05-25 Thread Howard Chu
all the info about the entry cache. The bdb->bi_idl_* fields records the info about the IDL cache. In 2.4 some of these counters are exposed via back-monitor. We can add more to the monitor entry as needed. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Hi

Re: referential integrity

2007-05-25 Thread Howard Chu
want... -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: ldap_sasl_interactive_bind_s

2007-05-29 Thread Howard Chu
n't affect it at all. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: ppolicy and others attributes

2007-06-06 Thread Howard Chu
Raphaël 'SurcouF' Bordet wrote: Hi, Can we use ppolicy with another attribut than userPassword, userCertificate by example ? Using userCertificate would make no sense. Currently the ppolicy code only works with the userPassword attribute. -- -- Howard Chu Chief Architect,

Re: ldap manual "other stuff"

2007-06-10 Thread Howard Chu
and don't mess with any of it. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: Problem with Schema in Openldap 2.3.19

2007-06-10 Thread Howard Chu
? Some ideia? Could you please be a bit more verbose on the error? Something like debugging -d-1 would probabely be of help. -Dieter Modifications to the cn=schema,cn=config entry are not allowed. To add new schema elements you must create a new entry underneath that point. -- -- Howard

Re: "make test" failed on test019 1st & then all subsequent tries: test017 failure.

2007-06-12 Thread Howard Chu
ion-cascade failed (exit 1) make[2]: *** [bdb-yes] Error 1 make[2]: Leaving directory `/home/Joe/openldap-2.3.35/tests' make[1]: *** [test] Error 2 make[1]: Leaving directory `/home/Joe/openldap-2.3.35/tests' make: *** [test] Error 2 [EMAIL PROTECTED] /home/Joe/openldap-2.3.35 $ ----

Re: is it possible to configure openldap to return latest modified entries first without using sorting feature?

2007-06-13 Thread Howard Chu
displayed last. (project requirement is: last modified entries are displayed first.) That must be pure coincidence. Entries are returned in their order of creation, not order of modification. There is no configuration that will change this ordering. -- -- Howard Chu Chief Architect, Sy

Re: BDB checkpointing overhead

2007-06-13 Thread Howard Chu
changes, does anything get written to disk or logged in any way when the checkpointing code wakes up? A timestamp will be written to the transaction log files. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief

Re: bdb_index_read: failed (-30989)

2007-06-18 Thread Howard Chu
DB version number, it's impossible to tell what the actual problem is. Don't just throw out random guesses when you don't have enough information to answer a question. Ask more questions and get the necessary info. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.c

Re: Question about ldap_init, ldap_initialize, start_tls, LDAP_OPT_X_TLS_ALLOW and TLS/SSL

2007-06-18 Thread Howard Chu
, the LDAP_OPT_X_TLS option is deprecated and should not be used at all. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: Question about ldap_init, ldap_initialize, start_tls, LDAP_OPT_X_TLS_ALLOW and TLS/SSL

2007-06-18 Thread Howard Chu
to control my client options without the use of config files. Go ahead and do that then. But don't waste time with options that don't actually have any meaning. Regards Markus ----- Original Message - From: "Howard Chu" <[EMAIL PROTECTED]> To: "Markus Moel

Re: Question about ldap_init, ldap_initialize, start_tls, LDAP_OPT_X_TLS_ALLOW and TLS/SSL

2007-06-18 Thread Howard Chu
g:bad certificate TLS: unable to get peer certificate. Successfully set up TLS protected connection to ldap server w2k3.windows2003.home:389 So, this setting definitely does something !! -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp:/

Re: Backend meta as a module errors

2007-06-19 Thread Howard Chu
pw are not supported anymore. No, that's just a warning. The real error is "symbol lookup error: ..." (note the tell-tale presence of the word "error" in the message...) Unfortunately that part of the message is cut off, so we have no idea what symbol it's h

Re: Recovery after system shutdown

2007-06-20 Thread Howard Chu
early missing a large amount of data. The BDB transaction support can't help you if your hardware fails to preserve the transaction log data. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect

Re: ldap_start_tls_s and automatic CA certificate searching

2007-06-22 Thread Howard Chu
ace multiple CA certs in a single file, and you typically need to do this on clients anyway. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: multi-value attribute search result

2007-06-24 Thread Howard Chu
entry has multiple "cn" values, like "cn=foo", "cn=joe", "cn=foobar", "cn=foobarX", "cn=bob", "cn=nofoobar" - is it possible to have "cn" returned, but only these values, which actually matched the filter ? Or, i

Re: Problem with ldapmodify: Internal (implementation specific) error (80)

2007-06-25 Thread Howard Chu
ssword -H "ldap://hostname:port"; -b "cn=config"): Questions = - Has anyone come across this behaviour ? - Any hints / suggestions / tips ? No idea, but it works perfectly for me on 2.3.36. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com

Re: WARNING: No dynamic config support for MODULE

2007-06-30 Thread Howard Chu
No support" means no support. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: c_get lo failure

2007-07-02 Thread Howard Chu
Gibson-Mount Principal Software Engineer Zimbra, Inc Zimbra :: the leader in open source messaging and collaboration -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: cmusaslsecretPLAIN attribute

2007-07-03 Thread Howard Chu
pd[1342]: slap_ap_lookup: str2ad(cmusaslsecretPLAIN): attribute type undefined Jul 3 07:50:49 Hodgkin slapd[1342]: send_ldap_result: conn=5 op=1 p=3 Jul 3 07:50:49 Hodgkin slapd[1342]: send_ldap_result: err=0 matched="" text="" Jul 3 07:50:49 Hodgkin slapd[1342]: SAS

Re: force use of start_tls: how?

2007-07-05 Thread Howard Chu
/ hard options, but it was never fully implemented. And then it was removed... -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: Building OpenLDAP client tools in Wintel platform - reg

2007-07-05 Thread Howard Chu
still valid: http://www.openldap.org/lists/openldap-devel/200701/msg2.html but it's also worth looking into if you go that route. Last I checked the 1.0.11 MSYS DLL has not yet been officially released, so this is still valid. -- -- Howard Chu Chief Architect, Symas Corp. http

Re: Lock is no longer valid / deferring operation

2007-07-05 Thread Howard Chu
he internal workings of Sleepycat/Oracle, so can't really say. They did apply the patch to later releases (it was found by Howard). Found/written by ... -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/

Re: error after OS upgrade

2007-07-05 Thread Howard Chu
;re referring to affects all platforms. It's just that we first discovered the problem on Linux. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: Help needed for testing OpenLDAP in Windows - reg.

2007-07-05 Thread Howard Chu
-compatible shell to run the scripts. As has already been stated multiple times on this list - use MSYS. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: using a proxy/rewrite to obviate the need for a legacy suffix?

2007-07-09 Thread Howard Chu
was designed to do. It is exactly intended for this purpose. Can anyone provide any hints, suggestions, or moral support on whether we're heading in the recommended direction, or whether there's a better way to obviate the need for our legacy suffix entry using some other kind of r

Re: str2entry: invalid value for attributeType userCertificate #0 (syntax 1.3.6.1.4.1.1466.115.121.1.8) ???

2007-07-11 Thread Howard Chu
at is happening? That's pretty unlikely. A userCertificate attribute requires its values to be in raw DER form, not PEM. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: cn=config: allow more users to access

2007-07-16 Thread Howard Chu
onfig. In OpenLDAP 2.4 you can set ACLs on cn=config just like any other database. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: [SOLVED] Re: multiple servers in DNS and TLS

2007-07-18 Thread Howard Chu
in the OpenSSL tools. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: client timeouts [was: Re: multiple servers in DNS and TLS]

2007-07-18 Thread Howard Chu
s URL basically has to do so in one thread or process and do the timing out in a separate thread or process. (Or reimplement that part of the OpenLDAP API, I suppose.) Philip Guenther Sendmail, Inc. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland

Re: force TLS and rootdn

2007-07-18 Thread Howard Chu
eartext. Is this expected? Is there a way to prevent this? Yes it is expected. I guess it's an unexpected consequence of how rootdn is implemented. Access controls are applied to entries, and rootpw is not in an entry. No. The rootdn always ignores ACLs. -- -- Howard Chu Chief Archit

Re: help adding a group

2007-07-19 Thread Howard Chu
ct some text fields to be encoded. Look for the double colons (::) after the attribute name to indicate that it's encoded. The only reason for base64 encoding in the example the original poster sent is that there must have been trailing whitespace on one of the input values. -- -- Howar

Re: moving ldap database and upgrading

2007-07-19 Thread Howard Chu
x data. In that respect, it can be painfully slow. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: OpenLdap search does not return all result set

2007-07-19 Thread Howard Chu
is obsolete and back-ldbm is known to spontaneously corrupt its indexes. Update to OpenLDAP 2.3/bdb, period. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: Connection timeout

2007-07-19 Thread Howard Chu
enerally there should be no delay. Again, this is normal, and any "network guru" should know that. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: ldapsearch on local attributes with slapo-translucent

2007-07-19 Thread Howard Chu
and make sure they match up (since they clearly don't, above). -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: c_get lo failure

2007-07-20 Thread Howard Chu
Howard Chu wrote: Quanah Gibson-Mount wrote: Anyone have any idea what would cause this error? You have a corrupted index. No idea how that happened. Delete the index files and run slapindex... => key_change(ADD,5bf) bdb_idl_insert_key: 5bf [0096defd] => bdb_idl_insert_key: c_

Re: Programmatic manner to determine version?

2007-07-20 Thread Howard Chu
system (e.g. 'rpm -qf --qf "%{VERSION}\n" /usr/lib64/libldap-2.3.so.0'). You shouldn't have any software installed except by your package management system :-P. All of this is basic system administration, nothing specific to OpenLDAP Software. re: shared library version n

Re: syncrepl, client certificate containing subjectAltName and non UTF-8 chars

2007-07-20 Thread Howard Chu
ad the OpenSSL documentation and fix your certificates. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: syncrepl, client certificate containing subjectAltName and non UTF-8 chars

2007-07-20 Thread Howard Chu
Emmanuel Dreyfus wrote: Howard Chu <[EMAIL PROTECTED]> wrote: From what you've posted above, I'm pretty sure you're not using "subjectAltName" correctly. It is not a component of the certificate's subject, it is an X.509 certificate extension. Read th

Re: syncrepl, client certificate containing subjectAltName and non UTF-8 chars

2007-07-20 Thread Howard Chu
Howard Chu wrote: Emmanuel Dreyfus wrote: Howard Chu <[EMAIL PROTECTED]> wrote: From what you've posted above, I'm pretty sure you're not using "subjectAltName" correctly. It is not a component of the certificate's subject, it is an X.509 certificate exten

Re: Connection timeout

2007-07-22 Thread Howard Chu
Dave Horsfall wrote: On Thu, 19 Jul 2007, Howard Chu wrote: What I am seeing is a timeout of a minute before switching to Server2. That would be normal when trying to contact a nonexistent host, and depends entirely on your kernel's TCP stack/connection timeouts. As already noted, yo

Re: Connection timeout

2007-07-22 Thread Howard Chu
Emmanuel Dreyfus wrote: Howard Chu <[EMAIL PROTECTED]> wrote: That is definitely something we consider to be application-specific. Building the setting into your app is the correct solution. In general, settings in the config file must always be overridable, so a new config option woul

Re: Expiring user passwords fails after first expiry

2007-07-23 Thread Howard Chu
10.2. Since you've just started testing, you should really be using the most recent release. 2.3.32 is quite old already. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDA

Re: failover config: servers with same DNS address and TLS, subjectAltName extension

2007-07-23 Thread Howard Chu
quirements in the SASL layer, allowing all insecure mechanisms to be used. A rather big mistake, after you've gone to the trouble of enabling secure authentication with certificates. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: failover config: servers with same DNS address and TLS, subjectAltName extension

2007-07-24 Thread Howard Chu
Emmanuel Dreyfus wrote: On Mon, Jul 23, 2007 at 09:58:37PM -0700, Howard Chu wrote: # Cannot get this working! #TLS_CRLCHECK peer This only works with recent OpenSSL 0.9.8 releases. You didn't mention which version of OpenSSL you're using. And since this entire subject is purely

Re: LDAPS vs. StartTLS ext. op.

2007-07-25 Thread Howard Chu
d any other implementor that wanted to claim that their LDAP product was fully IETF-compliant. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: failover config: servers with same DNS address and TLS, subjectAltName extension

2007-07-25 Thread Howard Chu
st add it to Faq-O-Matic? Yes, anybody can add entries to the FAQ (hasn't that been said enough times already?), and you're welcome to add your corrected writeup there. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlan

Re: failover config: servers with same DNS address and TLS, subjectAltName extension

2007-07-25 Thread Howard Chu
Emmanuel Dreyfus wrote: Howard Chu <[EMAIL PROTECTED]> wrote: Though I suspect that in the 7 or so years that OpenLDAP has supported OpenSSL, many people have been confronted with this problem, read the docs, and implemented the solution and moved on to the next thing, without any fuss

Re: failover config: servers with same DNS address and TLS, subjectAltName extension

2007-07-27 Thread Howard Chu
Emmanuel Dreyfus wrote: Howard Chu <[EMAIL PROTECTED]> wrote: This is getting rude. :-/ It seems to me that you cannot read what is plainly in front of your face, for whatever reason. While I acknowledge the quality of your work on the OpenLDAP project, I suspect you still hav

Re: olcPasswordHash scheme not available

2007-08-09 Thread Howard Chu
it's a general problem, then we're going to need to re-shuffle the layout of the cn=config tree so that global directives are processed after any modules are loaded. But I think password mechs are the only item that can be registered at runtime that currently have a problem. -- -- Ho

Re: olcPasswordHash scheme not available

2007-08-09 Thread Howard Chu
Pierangelo Masarati wrote: Howard Chu wrote: Pierangelo Masarati wrote: That sounds like a bug. In fact, {K5KEY} is loaded by smbk5pwd, so if in slapd.conf you correctly load the module __before__ using password-hash things work as expected. However, when the configuration is loaded from the

Re: Maximum size of the database.

2007-08-11 Thread Howard Chu
million DNs. Unfortunately there is no way to control the size of the DN cache in OpenLDAP 2.3, it simply grows without bound. A config keyword for the DN cache will be in OpenLDAP 2.4. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp

Re: Maximum size of the database.

2007-08-11 Thread Howard Chu
matthew sporleder wrote: On 8/11/07, Howard Chu <[EMAIL PROTECTED]> wrote: Sumith Narayanan wrote: Hi Group, We have a coorporate openldap database in production which has more than 4 million entries. The slapd process serves three different physical dabases of sizes 4 GB , 12 GB and

Re: High availability

2007-08-13 Thread Howard Chu
documentation regarding Linux. What about the case I explained, that we have clients that do read/write, how to send the writes to the masters and reads to slaves without having the clients chase referrals ? Use the chaining overlay. See test017 for an example configuration. -- -- Howard Chu Chief

Re: Problem changing passwords after import

2007-08-13 Thread Howard Chu
l back to file based data. Please carefully check the logs of your server before proceeding any further. It seems clear, from the little info you posted, that basic authentication (LDAP simple bind) is not working with the credentials you stored in your directory. -- -- Howard Chu Chief Arc

Re: preserve value order with referential integrity overlay?

2007-08-14 Thread Howard Chu
n you choose is going to require your clients to be modified to adapt to the solution. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: Problem changing passwords after import

2007-08-14 Thread Howard Chu
s own authentication checks. As pointed out in the FAQ http://www.openldap.org/faq/index.cgi?file=1041 if you're using OpenSSL it's very likely that you've got the wrong one. Thanks -Original Message----- From: Howard Chu [mailto:[EMAIL PROTECTED] Sent: Monday, August 13, 20

Re: preserve value order with referential integrity overlay?

2007-08-14 Thread Howard Chu
it. Having to require client modification might be the big reason to not having it implemented, I guess. 在 2007-08-14二的 02:01 -0700,Howard Chu写道: Zhang Weiwu wrote: Hello. I deployed an LDAP system and a set of applications around it that is highly sensitive to the order of values, e.g first telep

Re: preserve value order with referential integrity overlay?

2007-08-15 Thread Howard Chu
Zhang Weiwu wrote: 在 2007-08-14二的 10:30 -0700,Howard Chu写道: Zhang Weiwu wrote: One dump question, the draft you composed expires at end of 2006, does that mean this draft will no longer become RFC and (thus?) have no implementation yet? The draft is intended to document what we've al

Re: proxy auth and userpassword access

2007-08-22 Thread Howard Chu
he main server. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: slapo-dynlist search member=value search?

2007-08-23 Thread Howard Chu
ensive and/or CPU intensive. There's no good way to do this without sacrificing one or both. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: Strange error during TLS handshake

2007-08-23 Thread Howard Chu
pper Server-Edition. Looking forward to your answer! Thanks, Fabian P.S. We are using self-signed certificates of our own CA. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: slapo-dynlist search member=value search?

2007-08-23 Thread Howard Chu
Frankly the mention of slapd group caching here is bogus, since group caching only benefits ACL performance when processing multiple responses in a Search operation. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hy

Re: running DB on different machine than slapd

2007-08-24 Thread Howard Chu
ggest usable alternatives. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: FW: running DB on different machine than slapd

2007-08-24 Thread Howard Chu
ing seems pretty unrealistic to me. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

Re: Syntax Integer and leading zeros

2007-08-25 Thread Howard Chu
uld not be generating integer values with leading zeroes. If you don't like this, you have to change the LDAP spec first. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://w

Re: Syntax Integer and leading zeros

2007-08-25 Thread Howard Chu
Howard Chu wrote: So - to comply with the spec, clients should not be generating integer values with leading zeroes. If you don't like this, you have to change the LDAP spec first. Never mind, the Integer definition comes from ASN.1, and it's defined there with leading zeroes pro

Re: TLS configuration needs client certification (why?)

2007-08-25 Thread Howard Chu
omment the "TLSVerifyClient never" directive here to work around this problem. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sunhttp://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/

<    1   2   3   4   5   6   7   8   9   10   >