Re: How to determine olcDbMaxSize

2021-08-27 Thread Quanah Gibson-Mount
on the filesystem, minus any space you want to leave for other applications. This is why the man page literally says to set it to as large of a value as possible. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered

Re: OpenLDAP 2.5.7 dies

2021-08-27 Thread Quanah Gibson-Mount
the process is executing. Start slapd gdb /path/to/slapd PID (gdb) cont execute the command that crashes slapd at the gdb prompt: gdb thr apply all bt full --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: OT: Net:LDAPapi / LDAPS-Support?

2021-08-26 Thread Quanah Gibson-Mount
--On Thursday, August 26, 2021 8:57 PM +0200 "A. Schulze" wrote: Am 25.08.21 um 17:43 schrieb Quanah Gibson-Mount: I took over a service using the Perl NET::LDAPapi. Now I fail to establish an LDAPS connection. Does anybody know if that's even supported and if so, how I'v

Re: /usr/local/etc/openldap/slapd.conf: line 39: scheme not available ({SHA512})

2021-08-26 Thread Quanah Gibson-Mount
module has no dependencies on any radius libraries. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: /usr/local/etc/openldap/slapd.conf: line 39: scheme not available ({SHA512})

2021-08-26 Thread Quanah Gibson-Mount
. ;) If you have it instantiated and things aren't working, it would appear it's not actually loading as desired. But it's worked fine for me with existing 2.4 -> 2.5 configuration migrations, so this would be something different on your end. --Quanah -- Quanah Gibson-Mount Product Architect Sy

Re: openSUSE/SLE users, migrate to back-mdb now!

2021-08-26 Thread Quanah Gibson-Mount
clue what is being refernced here either. It is true in some early releases of back-mdb there were some issues with fragmentation but that's been dealt with. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenL

Re: /usr/local/etc/openldap/slapd.conf: line 39: scheme not available ({SHA512})

2021-08-26 Thread Quanah Gibson-Mount
ds, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: 2.5.7 for RHEL8 - Question

2021-08-25 Thread Quanah Gibson-Mount
on upgrading, specifically: <https://www.openldap.org/doc/admin25/appendix-upgrading.html#ppolicy%20overlay> which directly answers your question. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by Op

Re: 2.5.7 for RHEL8 - Question

2021-08-25 Thread Quanah Gibson-Mount
-- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: 2.5.7 for RHEL8 - Question

2021-08-25 Thread Quanah Gibson-Mount
OSes have not. Additionally, RedHat has not stopped shipping the 2.4 libldap, so we still need isolation at that level. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: OT: Net:LDAPapi / LDAPS-Support?

2021-08-25 Thread Quanah Gibson-Mount
d has been as long as I've used it (about 2 decades now). For ldaps:// connections, you need to pass in an ldaps:/// URI. It will pull its defaults for TLS like any other libldap linked ldap application. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged,

Re: OpenLDAP 2.5.5 PPA for Ubuntu 20.04 LTS

2021-08-24 Thread Quanah Gibson-Mount
. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: OpenLDAP 2.5.5 PPA for Ubuntu 20.04 LTS

2021-08-23 Thread Quanah Gibson-Mount
of a problem. I just can't find the proper deb package for Ubuntu. Hi Saša-Stjepan Bakša, Symas OpenLDAP 2.5 can be obtained from: <https://repo.symas.com/soldap/ubuntu20/> Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supporte

Re: Antw: [EXT] Re: migrate from 2.4 to 2.5, determine existing MDB format

2021-08-20 Thread Quanah Gibson-Mount
for cn=config replication. The fact that 2.5's ppolicy no longer uses a schema file for example. But again, people should not be using cn=config replication in 2.4. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered

Re: migrate from 2.4 to 2.5, determine existing MDB format

2021-08-19 Thread Quanah Gibson-Mount
"knowledge" of it, and it would not appear in an LDIF created by slapcat. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: pwdHistory setting not being honored

2021-08-19 Thread Quanah Gibson-Mount
ported release for many reasons. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: migrate from 2.4 to 2.5, determine existing MDB format

2021-08-19 Thread Quanah Gibson-Mount
? LDAP is a protocol, the internal change to the MDB database structure is immaterial. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Antw: [EXT] Re: Index seems to return wrong amount of candidate causing really poor search performance

2021-08-19 Thread Quanah Gibson-Mount
of 2, but the point was the max value is always a power of 2. I would also note that every increment will cause slapd to require more memory. Larger values (such as 30) would require several terrabytes of RAM for slapd to function. --Quanah -- Quanah Gibson-Mount Product Architect Symas

Re: Antw: [EXT] Re: Index seems to return wrong amount of candidate causing really poor search performance

2021-08-18 Thread Quanah Gibson-Mount
must be in the range of 16-31. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Index seems to return wrong amount of candidate causing really poor search performance

2021-08-18 Thread Quanah Gibson-Mount
ce indeed. :) Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Index seems to return wrong amount of candidate causing really poor search performance

2021-08-16 Thread Quanah Gibson-Mount
93480d] 5f94a42e <= mdb_index_read 6463387 candidates So now we can see there are 4 candidate sets that are smaller than "all entries": 906,885 415,219 99,550 293,028 Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Index seems to return wrong amount of candidate causing really poor search performance

2021-08-16 Thread Quanah Gibson-Mount
documentation as to what the idlexp command does to the admin guide for OpenLDAP 2.5.6. You may want to read it, it applies to OpenLDAP 2.4 as well. <https://www.openldap.org/doc/admin25/slapdconf2.html#MDB%20Database%20Directives> Section 5.2.6.1 --Quanah -- Quanah Gibson-Mount P

RE25 testing call #1 (OpenLDAP 2.5.7)

2021-08-16 Thread Quanah Gibson-Mount
of deprecated options from client tools (ITS#9200) Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: migrate from 2.4 to 2.5, determine existing MDB format

2021-08-07 Thread Quanah Gibson-Mount
--On Saturday, August 7, 2021 3:48 PM +0200 Michael Ströder wrote: On 8/7/21 1:34 PM, Howard Chu wrote: Michael Ströder wrote: On 8/7/21 9:58 AM, Michael Ströder wrote: On 8/7/21 12:02 AM, Quanah Gibson-Mount wrote: With OpenLDAP 2.5.7 and later it is possible to export a 2.4 database

Re: migrate from 2.4 to 2.5, determine existing MDB format

2021-08-06 Thread Quanah Gibson-Mount
--On Friday, August 6, 2021 11:49 PM +0100 Howard Chu wrote: Michael Ströder wrote: On 8/6/21 11:01 PM, Quanah Gibson-Mount wrote: --On Saturday, July 31, 2021 7:05 PM +0200 Michael Ströder wrote: Can I find out the disk format version in any way, e.g. with python-lmdb? The id2v DB

Re: migrate from 2.4 to 2.5, determine existing MDB format

2021-08-06 Thread Quanah Gibson-Mount
--On Saturday, July 31, 2021 7:05 PM +0200 Michael Ströder wrote: Can I find out the disk format version in any way, e.g. with python-lmdb? The id2v DB only exists in OpenLDAP 2.5 databases. However, stay tuned... --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation

Re: Modify memberOf olcAttributetype in schema

2021-08-05 Thread Quanah Gibson-Mount
to work with the application developer to fix their broken product. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Antw: [EXT] Re: Modify memberOf olcAttributetype in schema

2021-08-05 Thread Quanah Gibson-Mount
--On Thursday, August 5, 2021 8:45 AM +0200 Ulrich Windl wrote: So "X-ORIGIN 'iPlanet Delegated Administrator'" is part of the built-in schema? Yes, it documents the ORIGIN of the attribute. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged,

Re: ldap utils: option dropped

2021-08-04 Thread Quanah Gibson-Mount
=2.5.0_milestone=2.5.1_milestone=2.5.2_milestone=2.5.3_milestone=2.5.4_milestone=2.5.5_milestone=2.5.6> Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Generating a memberOf attribute for posixGroups (dynlist module)

2021-08-03 Thread Quanah Gibson-Mount
--On Tuesday, August 3, 2021 4:42 PM +0200 Benjamin Renard wrote: Hello, Le 30/07/2021 à 18:37, Quanah Gibson-Mount a écrit : You want OpenLDAP 2.5's version of dynlist. Just be sure, could-you please resume me the benefits when using OpenLDAP 2.5's version of dynlist overlay ? It's

Re: Antw: [EXT] Re: migrate from 2.4 to 2.5, determine existing MDB format

2021-08-02 Thread Quanah Gibson-Mount
of BerkeleyDB) had format changes. Those type of format changes always require a reload regardless of the underlying database software being used. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <h

Re: Generating a memberOf attribute for posixGroups (dynlist module)

2021-07-30 Thread Quanah Gibson-Mount
--On Friday, July 30, 2021 2:21 PM -0700 Quanah Gibson-Mount wrote: --On Friday, July 30, 2021 4:16 PM -0300 Eduardo Lúcio Amorim Costa wrote: Hi people! My version is the one below... ``` [root@ldap_provider ~]# slapd -VV     @(#) $OpenLDAP: slapd 2.4.44 (Apr 28 2021 13:32:00

Re: Generating a memberOf attribute for posixGroups (dynlist module)

2021-07-30 Thread Quanah Gibson-Mount
-2.4.44/ openldap-2.4.44/servers/slapd As I already stated, you want to use the slapo-dynlist from the OpenLDAP 2.5 release series. The current version is OpenLDAP 2.5.6. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions

Re: Generating a memberOf attribute for posixGroups (dynlist module)

2021-07-30 Thread Quanah Gibson-Mount
for a legacy OpenLDAP LDAP and with several applications using it. So, this seems to me the best solution to be able to use the memberOf as a filter. You want OpenLDAP 2.5's version of dynlist. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified

Re: Configure openldap 2.5.6 on CentOS7 with TLS

2021-07-29 Thread Quanah Gibson-Mount
h-tls=openssl" option, but my understanding was that TLS was essential for OpenLDAP. You seem to have told it where to find the OpenSSL 1.1.1 header files but not the development libraries. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supp

Re: Much Higher Latency With Paged Results Asked

2021-07-28 Thread Quanah Gibson-Mount
the option it's around 105ms. Question is why ? Because specifying paged results requires the server to do additional work. And how I can get back to 5 ms when using the option ? You can't. Generally, using paged results indicates a poorly written application. --Quanah -- Quanah Gibson

Re: Much Higher Latency With Paged Results Asked

2021-07-28 Thread Quanah Gibson-Mount
--On Tuesday, July 27, 2021 8:13 PM +0200 Romain Madala wrote: Please provide additional details of the issue. Thanks, but you didn't answer the above. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions

Re: Much Higher Latency With Paged Results Asked

2021-07-27 Thread Quanah Gibson-Mount
-- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: adding a new module smbkrb5pwd - error missingAttributeDescription

2021-07-22 Thread Quanah Gibson-Mount
E and here https://github.com/opinsys/smbkrb5pwd) I would suggest contacting the author of that module for support as it is not a part of the OpenLDAP software distribution, not even the contrib/ modules. I would note that the module in general seems to be abandonware. Regards, Quanah -- Qua

RE25 testing call #1 (OpenLDAP 2.5.6)

2021-07-20 Thread Quanah Gibson-Mount
) Build Fixed library symbol versioning on Solaris (ITS#9591) Fixed compile warning in libldap/tpool.c (ITS#9601) Fixed compile wraning in libldap/tls_o.c (ITS#9602) Contrib Fixed ppm module for sysconfdir (ITS#7832) Regards, Quanah --

Re: Replacing memberof with dynlist

2021-07-16 Thread Quanah Gibson-Mount
suite configurations for dynlist. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Symas OpenLDAP for Linux 2.5

2021-07-15 Thread Quanah Gibson-Mount
. Other packagers have different statuses. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Symas OpenLDAP for Linux 2.5

2021-07-14 Thread Quanah Gibson-Mount
--On Wednesday, July 14, 2021 12:29 PM -0400 Dave Macias wrote: But looks like the baseurl for 2.5 is now: https://repo.symas.com/repo/rpm/SOLDAP/release25/ Yes? Yes, although we haven't yet announced it since it's still a WIP. --Quanah -- Quanah Gibson-Mount Product Architect

Re: Symas OpenLDAP for Linux 2.5

2021-07-14 Thread Quanah Gibson-Mount
t upgraded to, or is it going to be a different package name or a new repo that will require manual intervention in order to upgrade? Symas OpenLDAP packages for 2.5 will be an entirely different beast. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and

Re: Consumer Delta Sync Lost After Provider Restarted

2021-07-06 Thread Quanah Gibson-Mount
still on 2.4.56? I seem to recall a fix for something like this, but I don't recall if it went into 2.4 or was 2.5 only. I'd definitely update to 2.4.59 as a first step if not there yet. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported

Re: Consumer Delta Sync Lost After Provider Restarted

2021-07-06 Thread Quanah Gibson-Mount
systems do this) closes the syncrepl connection, slapd can detect this and re-establish it. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Are Password Expired and Password Expiry warning (2.16.840.1.113730.3.4.5) controls supported in OpenLDAP

2021-07-06 Thread Quanah Gibson-Mount
me how to configure openldap to return that control? I suggest reading the slapo-ppolicy(5) man page, which clearly documents how to enable that control. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered

Re: enable WiredTiger not defaulting to no

2021-06-25 Thread Quanah Gibson-Mount
it to no. If that's not happening then something else on your system enabled it. I would suspect that there is more to the configure options being used than was shown. I routinely run ./configure with no options and WT is not enabled. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation

Re: totp1andpw

2021-06-17 Thread Quanah Gibson-Mount
with 2.5 and whatever your favorite password hashing scheme is (I advise ARGON2) to do this. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: pw-totp

2021-06-07 Thread Quanah Gibson-Mount
, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: 2.57 to 2.58 update no structural objectClass in configuration table

2021-06-07 Thread Quanah Gibson-Mount
the syncprov module built in statically, while the newer build has it built in dynamically, so at this point you would need to moduleload syncprov. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <h

Re: pw-totp

2021-06-07 Thread Quanah Gibson-Mount
test083 closely, as it uses cn=config to set up and configure ARGON2 with cn=config. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: unable to add DB DIT , getting value #0 invalid per syntax error in alpine Linux.

2021-06-06 Thread Quanah Gibson-Mount
One either uses slapd.conf OR cn=config. You clearly need to add an additional moduleload for the syncprov module to your cn=config configuration. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: unable to add DB DIT , getting value #0 invalid per syntax error in alpine Linux.

2021-06-05 Thread Quanah Gibson-Mount
export of your cn=config database on Alpine to examine, so there's no ability to tell if it's actually correctly configured to load the MDB database module. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP

Re: pw-totp

2021-06-05 Thread Quanah Gibson-Mount
Factor auth. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Symas OpenLDAP for Linux 2.4.59 Released

2021-06-04 Thread Quanah Gibson-Mount
The latest version of Symas OpenLDAP for Linux is now available for RHEL7, RHEL8, Ubuntu18 LTS, and Ubuntu 20 LTS. <https://repo.symas.com/sofl/> for installation instructions. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supporte

Re: OpenLDAP 2.4.x branch support

2021-06-04 Thread Quanah Gibson-Mount
strongly advise investigating migrating to 2.5 when you can. There may be future OpenLDAP 2.4.x releases if a critical CVE etc comes up, but outside of that it's essentially done with. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified

Re: unable to add DB DIT , getting value #0 invalid per syntax error in alpine Linux.

2021-06-04 Thread Quanah Gibson-Mount
lid syntax (21) additional info: objectClass: value #0 invalid per syntax Then the value in the LDIF you are loading is invalid. This often is seen if there is a character such as a trailing space after the objectClass name, etc. Regards, Quanah -- Quanah Gibson-Mount Product Archi

Re: hdb to mdb

2021-06-03 Thread Quanah Gibson-Mount
--On Thursday, June 3, 2021 6:02 PM -0400 Dave Macias wrote: So therefore i dont need to worry about back_mdb since it's already loaded.  Yes? Right. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered

Re: hdb to mdb

2021-06-03 Thread Quanah Gibson-Mount
    monitor     bdb     hdb     mdb Not sure what to look for... "mdb" is that is? Yes, that indicates mdb was built statically. -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: hdb to mdb

2021-06-03 Thread Quanah Gibson-Mount
with slapadd as well. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: unable to add DB DIT , getting value #0 invalid per syntax error in alpine Linux.

2021-06-03 Thread Quanah Gibson-Mount
c/openldap # moduleloadback_mdb.la # moduleloadback_ldap.la Looks like you failed to moduleload back_mdb. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Replication between 2.4.x 2.5.x versions

2021-06-02 Thread Quanah Gibson-Mount
: Is there a script or other way to check possible config incompatibilities with 2.5.x (in order to avoid surprises)? Have you read the upgrade appendix of the admin guide? <https://www.openldap.org/doc/admin25/appendix-upgrading.html> Regards, Quanah -- Quanah Gibson-Mount Product Architect

Re: radlib.h: No such file or directory - passwd slapd-module

2021-05-28 Thread Quanah Gibson-Mount
from libradius, which is from the FreeBSD project. Patches welcome to update the code to use freeradius. There are some forks of libradius for linux on github you might want to try. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported

Re: Openldap trying to setup mozillaAbPersonAlpha.schema

2021-05-28 Thread Quanah Gibson-Mount
--On Saturday, May 29, 2021 12:23 AM + b...@gunas.co.uk wrote: I think the core schema is in use as it is in the It is not. You're telling slaptest to use the ldap.conf file you created, which in turn ignores everything in /etc/ldap/ --Quanah -- Quanah Gibson-Mount Product

RE25 testing call #1 (OpenLDAP 2.5.5)

2021-05-28 Thread Quanah Gibson-Mount
Documentation ldap_first_attribute(3) - Document ldap_get_attribute_ber (ITS#8820) ldap_modify(3) - Delete non-existent mod_next parameter (ITS#9559) Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

RE24 testing call #1 (OpenLDAP 2.4.59)

2021-05-28 Thread Quanah Gibson-Mount
Fixed slapo-autogroup to not thrash thead context (ITS#9494) Documentation ldap_modify(3) - Delete non-existent mod_next parameter (ITS#9559) Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP sol

Re: Openldap trying to setup mozillaAbPersonAlpha.schema

2021-05-28 Thread Quanah Gibson-Mount
for the ldap client, slapd.conf is for the slapd server. Obviously slaptest won't care. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: unable to add DB DIT , getting value #0 invalid per syntax error in alpine Linux.

2021-05-26 Thread Quanah Gibson-Mount
validation of the configuration and generating the error. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: How to enable argon2 module

2021-05-10 Thread Quanah Gibson-Mount
-- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: pbkdf2 module install does not honour --prefix=/opt/openldap

2021-05-08 Thread Quanah Gibson-Mount
in the configure on the src root. I am pretty sure it worked fine on openldap-2.4.* (at the beginning it didn't but then it was fixed). No, it is a contrib module, it has never been tied to configured. Read the makefile for how to set the prefix correctly. Regards, Quanah -- Quanah Gibson

Re: MDB page growth

2021-05-07 Thread Quanah Gibson-Mount
to configure both that and sortvals on your deployment once you're on OpenLDAP 2.5. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Migrating From DSEE7 to OpenLDAP; Base64 Values Fail To Import Using ldapadd

2021-05-06 Thread Quanah Gibson-Mount
rrent copy. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Migrating From DSEE7 to OpenLDAP; Base64 Values Fail To Import Using ldapadd

2021-05-06 Thread Quanah Gibson-Mount
ema/rfc2307bis.ldif> or slapd.conf: <https://gitlab.symas.net/symas-public/openldap/-/raw/ubuntu/focal/debian/schema/rfc2307bis.schema> Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by Ope

Re: Migrating From DSEE7 to OpenLDAP; Base64 Values Fail To Import Using ldapadd

2021-05-06 Thread Quanah Gibson-Mount
it. No, the problem is that the attribute value is not valid for the attribute defined SYNTAX. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Migrating From DSEE7 to OpenLDAP; Base64 Values Fail To Import Using ldapadd

2021-05-06 Thread Quanah Gibson-Mount
has the appropriate permission, manage, as far as I can tell but have also used SASL EXTERNAL--same results. Does the decoded version actually import successfully? You note it decodes just fine, but you didn't say if you can actually import it at that point. --Quanah -- Quanah Gibso

Re: idletimeout setting is not working

2021-05-06 Thread Quanah Gibson-Mount
system even use slapd.conf, or is it actually using cn=config? etc. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Antw: [EXT] Re: SyncProv checkpointing

2021-05-06 Thread Quanah Gibson-Mount
--On Thursday, May 6, 2021 10:01 AM +0200 Ulrich Windl wrote: Quanah Gibson-Mount schrieb am 05.05.2021 um 18:09 in Nachricht : ‑‑On Wednesday, May 5, 2021 9:37 AM +0200 Ulrich Windl wrote: schrieb am 04.05.2021 um 17:27 in I just wonder: Are you talking about a slapcat‑type

Re: Antw: [EXT] Re: SyncProv checkpointing

2021-05-05 Thread Quanah Gibson-Mount
. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: SyncProv checkpointing

2021-05-04 Thread Quanah Gibson-Mount
is more frequent than the accesslog purge configuration. It would be useful to have a copy of your configuration for the two nodes (passwords redacted, if you can send them to me directly). I'd like to see if I can create a reproduction case. Regards, Quanah -- Quanah Gibson-Mount Product

Re: SyncProv checkpointing

2021-05-04 Thread Quanah Gibson-Mount
to ignore duplicate sessionlog entries (ITS#9394) OpenLDAP 2.4.58 Release (2021/03/16) Fixed slapd syncrepl to check all contextCSNs (ITS#9282) Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenL

Re: SyncProv checkpointing

2021-05-04 Thread Quanah Gibson-Mount
--On Tuesday, May 4, 2021 4:27 PM + thomaswilliampritch...@gmail.com wrote: Provision Process: 1. Take backup of database with mdb_copy on initial provider. Is slapd stopped when you run mdb_copy, or running? Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas

Re: SyncProv checkpointing

2021-05-03 Thread Quanah Gibson-Mount
point: 1 1). Are there any concerns with having this frequent of checkpointing? Too little information here. What OpenLDAP release are you on? Do you use standard syncrepl or delta-syncrepl? What is your restore process? --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged,

Re: Unable to delete root entry

2021-04-26 Thread Quanah Gibson-Mount
. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Unable to delete root entry

2021-04-26 Thread Quanah Gibson-Mount
as a runtime alternative. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Unable to delete root entry

2021-04-26 Thread Quanah Gibson-Mount
. Creating a default database is a function of how debian does the packaging. I believe there's an option you can pass to have it not do that. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <h

Re: Unable to delete root entry

2021-04-26 Thread Quanah Gibson-Mount
--On Monday, April 26, 2021 10:46 AM -0700 Quanah Gibson-Mount wrote: --On Saturday, April 24, 2021 11:04 PM +0300 Николай Данилов wrote: When installing openldap with database mdb, root entry cannot be deleted. This is a bug with back-mdb that was not present with back-bdb/hdb

Re: Unable to delete root entry

2021-04-26 Thread Quanah Gibson-Mount
couldn't delete the rootDSE, which would be correct. This is an issue with deleting the root of the database DIT, which is different. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <h

Re: OpenLDAP 2.5 Release Candidate Testing (OpenLDAP 2.5.4)

2021-04-24 Thread Quanah Gibson-Mount
--On Friday, April 23, 2021 9:49 AM -0700 Quanah Gibson-Mount wrote: --On Friday, April 23, 2021 9:05 AM -0700 Quanah Gibson-Mount wrote: Starting test043-delta-syncrepl for mdb... I was able to reproduce this one, thanks. ITS#9534. test043 issue should be fixed now. I still

Re: OpenLDAP 2.5 Release Candidate Testing (OpenLDAP 2.5.4)

2021-04-23 Thread Quanah Gibson-Mount
are set appropriately. For example, assuming openssl11 was installed into /usr/local: LD_FLAGS=-L/usr/local/lib -Wl,-rpath,/usr/local/lib CPP_FLAGS=-I/usr/local/include etc Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP

Re: OpenLDAP 2.5 Release Candidate Testing (OpenLDAP 2.5.4)

2021-04-23 Thread Quanah Gibson-Mount
--On Friday, April 23, 2021 9:05 AM -0700 Quanah Gibson-Mount wrote: Starting test043-delta-syncrepl for mdb... I was able to reproduce this one, thanks. ITS#9534. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP

Re: OpenLDAP 2.5 Release Candidate Testing (OpenLDAP 2.5.4)

2021-04-23 Thread Quanah Gibson-Mount
. Fixed in RE25 now. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: OpenLDAP 2.5 Release Candidate Testing (OpenLDAP 2.5.4)

2021-04-23 Thread Quanah Gibson-Mount
--On Friday, April 23, 2021 4:51 PM +0200 "A. Schulze" wrote: Am 22.04.21 um 18:56 schrieb Quanah Gibson-Mount: Execute the test suite (via make test) after it is built.  Optionally, cd tests && make its to run through the regression suite. ./configure

Re: OpenLDAP 2.5 Release Candidate Testing (OpenLDAP 2.5.4)

2021-04-22 Thread Quanah Gibson-Mount
--On Thursday, April 22, 2021 3:32 PM -0700 Quanah Gibson-Mount wrote: I'm not able to reproduce this, I'd need to have the contents of the testrun/ directory to get some idea why you're hitting it. Never mind, I can reproduce it, I misread the test #. --Quanah -- Quanah Gibson

Re: OpenLDAP 2.5 Release Candidate Testing (OpenLDAP 2.5.4)

2021-04-22 Thread Quanah Gibson-Mount
--On Friday, April 23, 2021 12:07 AM +0300 openldap-techni...@kolttonen.fi wrote: Hello, On Thu, 22 Apr 2021, Quanah Gibson-Mount wrote: Execute the test suite (via make test) after it is built. Optionally, cd tests && make its to run through the regression suite. On RHEL8 an

OpenLDAP 2.5 Release Candidate Testing (OpenLDAP 2.5.4)

2021-04-22 Thread Quanah Gibson-Mount
The new load balancer, which can either be built as a module for slapd (--enable-balancer=mod) or as a standalone server (--enable-balancer=yes) The libargon2 password module (--enable-argon2). Systemd notification support (--with-systemd=yes). Thanks! Regards, Quanah -- Quanah Gibson-Mount Pro

Re: performance tuning for n-way and heavy client load

2021-04-16 Thread Quanah Gibson-Mount
group when you do that, or only adding/deleting specific users? Either way, for 2.4 you definitely want to use sortvals. Likely what you need is OpenLDAP 2.5's multival feature as well. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified

Re: performance tuning for n-way and heavy client load

2021-04-16 Thread Quanah Gibson-Mount
that you frequently update? --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Problems setting up a proxy

2021-04-15 Thread Quanah Gibson-Mount
--On Thursday, April 15, 2021 8:58 PM +0200 Hans van Zijst wrote: On 15-04-2021 19:09, Quanah Gibson-Mount wrote: A few notes: A) the "backend meta" directive is not needed.  There's only one use case for a "backend" statement at this time that I'm aware of, fo

Re: Problems setting up a proxy

2021-04-15 Thread Quanah Gibson-Mount
still a lot of work to be done in regards to better documentation and examples when working with cn=config. Patches welcome once you get it working. ;) Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powere

<    2   3   4   5   6   7   8   9   10   11   >