How to get updated Fedora 31 Cloud Image?

2020-05-27 Thread Rich Megginson
The Fedora 31 qcow2 cloud image e.g. http://mirrors.rit.edu/fedora/fedora/linux/releases/31/Cloud/x86_64/images/ was built with a buggy grub bootloader which causes problems like https://bugzilla.redhat.com/show_bug.cgi?id=1669252 How do I request a new Fedora 31 cloud image to be built and

Re: GRUB prompt after F29 to F30 upgrade

2019-05-02 Thread Rich Emberson
This morning I got the dreaded grub prompt on boot. Took me 3 hours to understand what https://fedoraproject.org/wiki/Common_F30_bugs#GRUB_boot_menu_is_not_populated_after_an_upgrade was talking about. I did a bunch of searching and trying things out before I hit upon the configfile grub command.

[389-users] Re: disk i/o: very high write rates and poor search performance

2018-08-15 Thread Rich Megginson
On 08/15/2018 10:56 AM, David Boreham wrote: On 8/15/2018 10:36 AM, Rich Megginson wrote: Updating the csn generator and the uuid generator will cause a lot of churn in dse.ldif.  There are other housekeeping tasks which will write dse.ldif But if those things were being done so

[389-users] Re: disk i/o: very high write rates and poor search performance

2018-08-15 Thread Rich Megginson
On 08/15/2018 10:13 AM, David Boreham wrote: in strace.log: [pid 8088] 12:55:39.739539 poll([{fd=435, events=POLLOUT}], 1, 180 [pid 8058] 12:55:39.739573 <... write resumed> ) = 1 <0.87> [pid 8088] 12:55:39.739723 <... poll resumed> ) = 1 ([{fd=435, revents=POLLOUT}]) <0.000168>

[389-users] How to use lib389 to create an instance?

2018-01-11 Thread Rich Megginson
I keep getting this error: Traceback (most recent call last):   File "/home/rmeggins/scripts/repltest.py", line 53, in     m1 = tools.DirSrvTools.createInstance(createargs)   File "/home/rmeggins/ds/ds.git/src/lib389/lib389/tools.py", line 627, in createInstance     cfgdn = lib389.CFGSUFFIX

[389-users] Re: [389-devel] Anyone still building 389 on HPUX?

2017-03-31 Thread Rich Megginson
On 03/31/2017 07:58 AM, Mark Reynolds wrote: On 03/30/2017 09:05 PM, William Brown wrote: On Thu, 2017-03-16 at 15:16 -0400, Mark Reynolds wrote: Just curious if anyone is building 389 on HPUX? There is very old code in our server that is specific to HPUX that we'd like to remove. Most of

[389-users] Re: Need help to tune 389 DS

2017-02-23 Thread Rich Megginson
On 02/23/2017 01:11 AM, William Brown wrote: On Wed, 2017-02-22 at 22:20 -0800, Gordon Messmer wrote: On 02/22/2017 09:25 PM, William Brown wrote: Default indexes only apply to new databases (It's a template iirc). You need to edit the index on the cn=userRoot,cn=ldbm

[389-users] Re: performance degrades over time on CentOS 7

2016-11-16 Thread Rich Megginson
On 11/15/2016 05:51 PM, Gordon Messmer wrote: On 11/15/2016 12:08 PM, Rich Megginson wrote: It is also useful to get a few stacktraces which will give us detailed information about what the server is doing. For example, if you can "catch" the server while it is misbehavin

[389-users] Re: performance degrades over time on CentOS 7

2016-11-15 Thread Rich Megginson
On 11/15/2016 12:58 PM, Marc Sauton wrote: What is the test filter like? Can we see a sanitized sample of the access log with the SRCH and RESULT? If using SSL, review the output of cat /proc/sys/kernel/random/entropy_avail Do we have replication? (and large attribute values?) You may want to

[389-users] Re: Is it possible to bind using nsview as part of DN?

2016-06-20 Thread Rich Megginson
On 06/19/2016 06:18 AM, kash...@arissystem.com wrote: In a normal setup environment I have created an organizationUnit named View, which is an nsView object. using nsViewFilter, I have several users in this organizationUnit. I can bind to these users with their actual DN with no problem :

[389-users] Re: x-forwarded-for

2016-05-18 Thread Rich Megginson
AM, Rich Megginson <rmegg...@redhat.com <mailto:rmegg...@redhat.com>> wrote: On 05/17/2016 02:04 PM, Robert Viduya wrote: We run a cluster of directory servers (4 masters, 2 hubs, 14 slaves) behind a set of F5 Bigip load balancers. Our Bigip admins recently decided to switch the b

[389-users] Re: x-forwarded-for

2016-05-18 Thread Rich Megginson
On 05/17/2016 02:04 PM, Robert Viduya wrote: We run a cluster of directory servers (4 masters, 2 hubs, 14 slaves) behind a set of F5 Bigip load balancers. Our Bigip admins recently decided to switch the boxes to "one-armed" mode and that services would have to use X-Forwarded-For headers or

[389-users] Re: Sync problems with AD 2012 R2

2016-05-17 Thread Rich Megginson
On 05/17/2016 08:01 AM, Alberto Viana wrote: Noriko, Just to let you know, after I replicated/created the exactly same OU structure on both side, the replication seems to works fine. I'm still not sure that is the expected behavior: Yes, it is. Winsync does _not_ sync the OU structure -

[389-users] Re: ldap dbmon output questions

2016-04-25 Thread Rich Megginson
On 04/25/2016 01:24 PM, ghiureai wrote: Hello List, I am running some search performance tests , basic ldapsearch augument "cn" , on local ldap host with rsearch, and seeing readwaiters: values chainng , here is a sample from dbmon This is not from dbmon. This is from cn=monitor:

[389-users] Re: ldap-ping with 389-ds version

2016-04-07 Thread Rich Megginson
On 04/07/2016 10:45 AM, ghiureai wrote: Hello Gurus, I was searching the web for some scripts to monitor DS performance , and found the Open Ldap: ldap-ping.pl script, I wonder if there is a version for 389-DS or if are other similar performance measure scripts available for 389-ds? Looks

[389-users] Re: Replication + SSLCLIENTAUTH failure: setup_ol_tls_conn - failed: unable to create new TLS context

2016-03-30 Thread Rich Megginson
On 03/30/2016 06:45 PM, Graham Leggett wrote: On 31 Mar 2016, at 12:25 AM, Graham Leggett wrote: [30/Mar/2016:17:19:19 +] setup_ol_tls_conn - failed: unable to create new TLS context [30/Mar/2016:17:19:19 +] slapi_ldap_bind - Error: could not configure the server

[389-users] Re: locking performance and scalability (eye candy gnuplots inside!)

2016-03-22 Thread Rich Megginson
On 03/08/2016 03:36 PM, liblfds admin wrote: On 08/03/16 22:35, Howard Chu wrote: Even though it's a VM, numactl -H may still show something relevant. I'll try it next time I have one running. BerkeleyDB did adaptive locking, using a spinlock before falling back to a heavier weight system

[389-users] Re: Can't use local time format on a Generalized Time attribute

2016-02-18 Thread Rich Megginson
On 02/18/2016 02:52 PM, jfill...@central1.com wrote: Hi Rich, Is the code your referenced found in 389-ds-base-1.2.11 ? yes https://git.fedorahosted.org/cgit/389/ds.git/tree/ldap/servers/plugins/syntaxes/cis.c?h=389-ds-base-1.2.11#n694 -- 389 users mailing list 389-users@%(host_name)s http

[389-users] Re: Synchronize Active Directory custom extension attributes to 389 DS

2016-01-25 Thread Rich Megginson
On 01/25/2016 02:59 AM, Mor Ndoye wrote: Hi, Using WinSync, is there any way to synchronize Active Directory custom extension attributes. Here is what I read from the Red Hat documentation: Only a subset of Directory Server and Active Directory attributes are synchronized. These attributes

[389-users] Re: 389 Windows Console

2016-01-04 Thread Rich Megginson
On 01/04/2016 09:23 AM, Phil Daws wrote: Hello Rich, Have ran in debug mode and connected to the admin interface which has been secured with a cert: {SUBJECT_DN=CN=ads01-admin.lab, SUBJECT={CN=ads01-admin}, SERIAL=8741097289627376099, AFTERDATE=Tue Dec 19 14:05:35 2017, ISSUER={CN=LAB-CA, O

[389-users] Re: ldapsearch question

2015-12-15 Thread Rich Megginson
On 12/14/2015 11:16 PM, Frank Munsche wrote: Hi Guys, I'm trying to understand why ldapsearch returns some objects of the dit only when the dn is set to the object I'm looking for and the search scope has to be base, e.g.: There is an object at the dn: cn=repl keep alive

[389-users] Re: upgrade to 389-ds-base-1.3.4 Q

2015-12-02 Thread Rich Megginson
On 12/02/2015 09:58 AM, ghiureai wrote: Hi Rich, Yes I totally agree I should see the prompt as you put here, this is working in my case only when running: setup-ds.pl -u but not for ds-admin. If you are (or can find) a perl hacker, you can use perl -d /usr/sbin/setup-ds-admin.pl and see

[389-users] Re: upgrade to 389-ds-base-1.3.4 Q

2015-12-01 Thread Rich Megginson
On 12/01/2015 03:07 PM, ghiureai wrote: Rich, still see bellow : and bellow only for ds no admin _setup-ds-admin.pl -u -d_ == This program will set up the 389 Directory and Administration Servers

[389-users] Re: upgrade to 389-ds-base-1.3.4 Q

2015-12-01 Thread Rich Megginson
On 12/01/2015 11:42 AM, ghiureai wrote: Thank you Rich for reply one more related issues I see : When need to run the ds admin update I do not see the options for update, seems goes back and asks all the Q's as a new fresh installation ( ??) setup-ds-admin.pl -u What we are missing

[389-users] Re: upgrade to 389-ds-base-1.3.4 Q

2015-12-01 Thread Rich Megginson
On 12/01/2015 02:23 PM, ghiureai wrote: On 12/01/2015 11:42 AM, ghiureai wrote: Rich, pls see the answers to your Q's ( the DS upgrade worked but the DS Admin set up will not behave same way ) ... <https://lists.fedoraproject.org/archives/list/389-users%40lists.fedoraproject.org/thr

[389-users] Re: upgrade to 389-ds-base-1.3.4 Q

2015-12-01 Thread Rich Megginson
On 12/01/2015 10:07 AM, ghiureai wrote: Hi List, we are tying to upgrade to 389-ds 1.3.4 from 1.2.2 , after rpm installed and update the server , when restarting the DS geting the following in DS errorlog, there is no such "entryallowWeakCipher" in cfg file , what should we dissable see

[389-users] Re: multimaster replication and index corruption

2015-11-24 Thread Rich Megginson
On 11/24/2015 10:28 AM, ghiureai wrote: On 11/24/2015 09:11 AM, Rich Megginson wrote: On 11/24/2015 10:02 AM, ghiureai wrote: Rich and the List Thank for your continue support, We are still seeing a index issues with memberof plugging, we are not sure at this point if this is related

[389-users] Re: DS:caseIgnoreOrderingMatch-defaul messages

2015-11-19 Thread Rich Megginson
On 11/19/2015 10:02 AM, ghiureai wrote: Rich the version for 389-base is :( I know is old ,we are planing upgrading in next future, but I do not see this messages on all DS hosts running same DS version) 389-ds-base-1.2.11.15-34.el6_5.x86_64 Not sure. Either this is something we fixed

[389-users] Re: DS:caseIgnoreOrderingMatch-defaul messages

2015-11-19 Thread Rich Megginson
On 11/19/2015 09:00 AM, ghiureai wrote: HI LIst, I am looking for clues to solve this messages after a export or DS reboot we are seeing this messages, I checked the 2 plugins: caseExactString and CaseIgnore String theya re both enabled , where else should I look? DS version:

Re: [389-users] multimaster replication and index corruption

2015-11-10 Thread Rich Megginson
On 11/10/2015 10:14 AM, Adrian Damian wrote: Rich, Thanks for your help. Let me jump in with more details. We've seen index corruption on a number of occasions. It seems to affect searchable attributes for which there are indexes. Queries on an attribute in LDAP that used to work suddenly

Re: [389-users] multimaster replication and index corruption

2015-11-10 Thread Rich Megginson
On 11/10/2015 12:12 PM, ghiureai wrote: Rich, thank you for all support for last day , unfortunately there is a strong wave in developers team:" the multimaster replication is creating issues with UI" ( I do not totally agree since can not be reproduce+ full describe

Re: [389-users] multimaster replication and index corruption

2015-11-09 Thread Rich Megginson
On 11/09/2015 11:05 AM, ghiureai wrote: Hi List, We have cfg multimaster replication /fractional replication memberof plugging excluded ,we are seeing from time to time index corruption with some indexes , there is a strong feeling from developers this are related to DS multimaster

Re: [389-users] multimaster replication and index corruption

2015-11-09 Thread Rich Megginson
On 11/09/2015 05:47 PM, Ghiurea, Isabella wrote: Hi Rich, Thank you for your feedback , as always greatly appreciate when comes from 389-DS RH support. We are not using vm just plain hardware, here is the description I got from developers team related to the issues they are seeing when

Re: [389-users] nsAccountLock - Server is unwilling to perform

2015-10-21 Thread Rich Megginson
On 10/21/2015 01:00 AM, Mitja Mihelič wrote: On 20/10/15 15:57, Mark Reynolds wrote: On 10/20/2015 09:37 AM, Mitja Mihelič wrote: Hi! We are using using nsAccountLock=true to lock user accounts. We also have dovecot authenticating users against the 389DS. If we set nsAccountLock=true,

Re: [389-users] fractional replication and consumers Q

2015-10-19 Thread Rich Megginson
On 10/19/2015 09:43 AM, Mayberry, Alexander wrote: We refer to a dedicated consumer as "read only". (we use these in our security zones.) Though, I'm sure that's probably not strictly true, it captures the spirit of things. Yes. What the console means by "dedicated consumer" is a read only

Re: [389-users] fractional replication and consumers Q

2015-10-19 Thread Rich Megginson
On 10/19/2015 03:17 PM, Joel Levin wrote: Hi Rich: Can there be multiple-masters simultaneously? Yes. i.e. 5 masters - all 5 accepting read-writes simultaneously? Yes. Is there a maximum limit? Technically the limit is 65534 read-write masters, but you will probably run into memory

Re: [389-users] uid case sensitivity

2015-10-12 Thread Rich Megginson
On 10/09/2015 12:33 AM, Juan Ramón Moral wrote: Hi, is it possible to change config to make uid case insensitive? this search return no entries. ldapsearch -x -D "uid=*U*ser01,cn=users,dc=XXX,dc=XXX" -w XXX -s base -b "cn=users,dc=XXX,dc=XXX" ldap_bind: No such object (32) matched

Re: [389-users] Question RE: 389DS

2015-10-07 Thread Rich Megginson
On 10/07/2015 02:45 PM, Paul Whitney wrote: When SSL-enabling the directory server, am I allowed to use a wildcard certificate or is it mandatory the certificate include the FQHN? You can use a wildcard, but you are strongly recommended to use subject alt name instead. Thanks, Paul M.

Re: [389-users] 389-users Digest, Vol 125, Issue 3

2015-10-07 Thread Rich Megginson
On 10/07/2015 08:34 AM, Karel Lang AFD wrote: hi, In reply to my own question (presented as topic no. 1 in vol.125 -see below- chainmail): It is solved, problem is the script, that is recommended by fedora wiki (setupssl2.sh) as a way for automatic SSL generation for 389-DS server, is not

Re: [389-users] memberOf pluging and multimaster replication

2015-10-02 Thread Rich Megginson
On 10/02/2015 12:16 PM, ghiureai wrote: Hi List and Rich, as per last documentation update I am trying to cfg fractional replication ( excluding memberOf plunging) for a multimaster cfg server 3 ldap server, when starting with first one aftr mentioning "memberOf " to b

Re: [389-users] memberOf pluging and multimaster replication

2015-10-01 Thread Rich Megginson
On 10/01/2015 12:49 PM, ghiureai wrote: Hi List ,Rich Here is the URL for the doc mentioned in this email, please can you confirm if this is the case for multimaster replication and memberOf plugin , is this the last update doc version ? Here is the latest doc version https

Re: [389-users] Performance with macro acis

2015-10-01 Thread Rich Megginson
On 10/01/2015 02:58 PM, Adrian Damian wrote: Hello Rich and Noriko, Is there a work around to slow listing or children problem? You could use cn=Directory Manager which is not affected by ACIs. All I need is to list their IDs (entrydn or cn or uid), To what does "their" refer

Re: Can not install mariadb Error: Transaction check error: ....

2015-09-26 Thread Rich Emberson
Thanks, that worked On Sat, Sep 26, 2015 at 8:07 AM, Jon Ingason <jon.inga...@telia.com> wrote: > Den 2015-09-26 kl. 16:42, skrev Rich Emberson: > > # dnf install mariadb mariadb-server > > Last metadata expiration check performed 0:19:25 ago on Sat Sep 26 > > 07:1

Can not install mariadb Error: Transaction check error: ....

2015-09-26 Thread Rich Emberson
Seems like a rather fundmental problem: $ uname -a Linux medusa 4.1.7-200.fc22.x86_64 #1 SMP Mon Sep 14 20:19:24 UTC 2015 x86_64 x86_64 x86_64 GNU/Linux $ rpm -qa --qf '%{NAME} %{VERSION}-%{RELEASE} %{ARCH}\n' | grep -i mariadb # dnf install mariadb mariadb-server Last metadata expiration

Re: [389-users] Performance with macro acis

2015-09-17 Thread Rich Megginson
On 09/16/2015 03:11 PM, Adrian Damian wrote: Hi There, The scenario is simple: we have a subtree in the DIT with a few thousand children node. The parent node of the subtree has a few acis including a couple of macro acis that apply to each of the child nodes. We've observed a significant

Re: [389-users] performance indexes questions "memberOf" performance

2015-09-17 Thread Rich Megginson
On 09/17/2015 10:22 AM, ghiureai wrote: Rich, I turn the error log level to "Plug-ins" seeing this in ldap error log now: Why did you turn the error log level to "Plug-ins"? I'm trying to find out if the issue is related to unindexed searches. The plug

Re: [389-users] performance indexes questions "memberOf" performance

2015-09-17 Thread Rich Megginson
On 09/17/2015 09:41 AM, ghiureai wrote: Rich, which internal logging you are referring ? I have auditing and access log on ,are other loggin option ? https://access.redhat.com/documentation/en-US/Red_Hat_Directory_Server/10/html/Administration_Guide/Configuring_Logs.html#configuring-log

Re: [389-users] Recommended method to remove DB path?

2015-09-17 Thread Rich Megginson
On 09/17/2015 09:50 AM, Striker Leggette wrote: Greetings, What is the recommended way to remove a database with the following example path?: 5G /db/slapd-389/db/testentry Would it be simply stopping slapd, remove the path and start slapd? Did you do

Re: [389-users] Performance with macro acis

2015-09-17 Thread Rich Megginson
, Adrian Damian wrote: 389-ds-base-1.2.11.15-34.el6_5.x86_64 On 09/17/2015 09:56 AM, Rich Megginson wrote: On 09/17/2015 10:52 AM, Adrian Damian wrote: Hi Rich, Sorry for missing this info. It's 1.2.11 running on SL6. We need the exact version, which is why I asked for the output of rpm -q 389-ds

Re: [389-users] Performance with macro acis

2015-09-17 Thread Rich Megginson
On 09/17/2015 10:52 AM, Adrian Damian wrote: Hi Rich, Sorry for missing this info. It's 1.2.11 running on SL6. We need the exact version, which is why I asked for the output of rpm -q 389-ds-base Adrian On 09/17/2015 08:54 AM, Rich Megginson wrote: On 09/16/2015 03:11 PM, Adrian Damian

Re: [389-users] performance Q with ldapsearch

2015-09-14 Thread Rich Megginson
On 09/14/2015 09:42 AM, ghiureai wrote: Please keep replies on-list. HI Rich, here is some details and Q from developers which designed the DS tree , has performance issues, any input from you much appreciate it: The slow query problem seems to be related to the acis. Please send

Re: [389-users] DS not responding , but no errors in logfile

2015-09-14 Thread Rich Megginson
On 09/14/2015 09:10 AM, ghiureai wrote: Hi , we are having issues with one of our DS , part of multimaster replication , after was onlin for several hours and brought up the DS is not respoding running a basic ldapsearch to count the users or grous will hang not results or messages in error

Re: [389-users] performance Q with ldapsearch

2015-09-11 Thread Rich Megginson
On 09/11/2015 08:50 AM, ghiureai wrote: Fast query: ldapsearch -x -h xxx -b "ou=ds,dc=cb,dc=net" -W -D "uid=axxx,ou=Users,ou=ds,dc=cb,dc=net" "(objectclass=groupofuniquenames)" "cn" | sort -u | wc Slow query: ldapsearch -x -h xxx-b "ou=groups,ou=ds,dc=cb,dc=net" -W -D

Re: [389-users] performance Q with ldapsearch

2015-09-10 Thread Rich Megginson
On 09/10/2015 04:00 PM, ghiureai wrote: Hi Gurus, we are seening some performance issues when running ldapsearch with tree ou=Groups, ou=ds , dc=abc, dc=net takes longer than when looking for same user but from one level up of tree up aka :ou=ds, dc=abc,dc=net, the difference in time very

Re: [389-users] Random dirsrv freezes and high CLOSE_WAITs

2015-09-03 Thread Rich Megginson
On 09/02/2015 09:45 PM, Prashant Bapat wrote: Hi, We have been using 389-ds as part of FreeIPA. In one of our environments, we have 2 389-ds installations with replication. What version? rpm -q 389-ds-base Randomly, the 389-ds on either of them completely freezes and there are high

Re: [389-users] Random dirsrv freezes and high CLOSE_WAITs

2015-09-03 Thread Rich Megginson
On 09/03/2015 09:02 AM, Prashant Bapat wrote: Rich, Version is 389-ds-base-1.3.3.8-1.fc21.x86_64 Below is the "ldapsearch" command that works on the LDAP server. ldapsearch -x -b "uid=testuser,cn=users,cn=accounts,dc=example,dc=com" In python this would be l

Re: [389-users] replica from DS to AD

2015-08-28 Thread Rich Megginson
On 08/28/2015 04:46 AM, Fabien Gasbayet wrote: Hi, I have 2 questions. 1 - On this diagram : https://access.redhat.com/documentation/en-US/Red_Hat_Directory_Server/9.0/html/Administration_Guide/Windows_Sync.html#Windows_Sync-About_Windows_Sync Password replication seems bi-directional… But

Re: F22: KDE to Gnome?

2015-08-13 Thread Rich Emberson
Well, after decades of KDE my solution was: dnf groupinstall Xfce Xfce works On Tue, Aug 11, 2015 at 3:14 PM, Rich Emberson emberson.r...@gmail.com wrote: Upgraded from F20 KDE environment using fedup --network 22 --product=nonproduct and X/KDE has rendering/refresh/redraw issues

F22: KDE to Gnome?

2015-08-11 Thread Rich Emberson
Upgraded from F20 KDE environment using fedup --network 22 --product=nonproduct and X/KDE has rendering/refresh/redraw issues. Application widgets and KDE pop menus are not draw, or, at best some edge or corner is drawn. In an xterm, the line being entered is drawn, but nothing else - move the

Re: fedup 20 - 22 - improper X rendering

2015-08-09 Thread Rich Emberson
. So, somehow Fedora 22's nouveau-based rendering seems to have an issue .. or something On Sat, Aug 8, 2015 at 6:42 PM, Rich Emberson emberson.r...@gmail.com wrote: I used to update: fedup --network 22 --product=nonproduct Coming up in graphical target as default.target, KDE X does not render

Re: fedup 20 - 22 - improper X rendering

2015-08-09 Thread Rich Emberson
I might add that logging in remotely to this machine and then launching an X-application that displays on the remote machine works. So, it seems to be purely a X rendering issue on the machine, the X protocol works fine. Richard On Sat, Aug 8, 2015 at 6:42 PM, Rich Emberson emberson.r

Re: fedup 20 - 22 - improper X rendering

2015-08-09 Thread Rich Emberson
x86_64 kmod-libs 21-1.fc22 x86_64 kmod 21-1.fc22 x86_64 On Sun, Aug 9, 2015 at 4:34 AM, fedora2015 fedora2...@videotron.ca wrote: On 08/08/2015 09:42 PM, Rich Emberson wrote: I used to update: fedup --network 22 --product=nonproduct Coming up in graphical target as default.target, KDE X does

fedup 20 - 22 - improper X rendering

2015-08-08 Thread Rich Emberson
I used to update: fedup --network 22 --product=nonproduct Coming up in graphical target as default.target, KDE X does not render properly. With right click I a small box appears under the cursor, navigating to what I guess is the first menu item, I can start a console. A box appears. I click

Re: [389-users] RHDS query directReports

2015-08-07 Thread Rich Megginson
On 08/05/2015 06:23 AM, Alpesh Shinde wrote: Hi Team, How to get the directReport values for a particular manager using RHDS queries? I am new to RHDS however have mostly worked on Microsoft AD and there is a powershell cmdlet to get this value. Can someone please help me with this? Or may

Closure: fedup 20 - 21 - No Mouse or Keyboard

2015-08-02 Thread Rich Emberson
Review my post from previous week or so for background First Laptop: Having failed to upgrade Fedora 22 using fedup on my KDE-base Fedora 20, I reinstalled Fedora 20. I downloaded the Workstation Live dvd twice, each time it passed the 256sha and both time the burned dvd passed the media test

FAIL: Thunderbird: Replying to thread

2015-07-28 Thread Rich Emberson
I use gmail. When I reply to a thread using Thunderbird, the response never shows up, but, if I include the email of the person who wrote the thread I am responding to, that person gets the email. On the other hand, if I log in to my gmail account, the I can post a response, that that response

fedup 20 - 21 - xinit - KDE - No mouse/keyboard input

2015-07-27 Thread Rich Emberson
Thanks for the suggestion. Contents of /var/cache/akmods/akmods.log START 2015/07/25 16:06:18 akmods: Checking kmods exist for 4.0.8-200.fc21.x86_64 2015/07/25 16:06:18 akmods: Building and installing nvidia-340xx-kmod 2015/07/25 16:06:18 akmods: Building RPM using the command '/bin/akmodsbuild

fedup 20 - 21 - xinit - error setting MTRR

2015-07-26 Thread Rich Emberson
What is causing the MTRR error in the xinit output? cat /proc/mtrr reg00: base=0x0 (0MB), size= 4096MB, count=1: write-back reg01: base=0x1 ( 4096MB), size= 1024MB, count=1: write-back reg02: base=0x0c000 ( 3072MB), size= 1024MB, count=1: uncachable Part of xinit output

fedup 20 - 21 - xinit - KDE - open /dev/fb0: No such file or directory

2015-07-26 Thread Rich Emberson
Still no mouse or keyboard. Don't know if this is the problem. from /var/log/Xorg.0.log START [96.019] (II) Loading sub module fb [96.019] (II) LoadModule: fb [96.020] (II) Loading /usr/lib64/xorg/modules/libfb.so [96.030] (II) Module fb: vendor=X.Org Foundation [96.030]

fedup 20 - 21 - 22 - Plasma closed unexpectedly

2015-07-26 Thread Rich Emberson
Also see MTRR issue below. On 07/25/2015 07:01 PM, Ed Greshko wrote: You're a KDE user and quite a bit has changed. One question and one suggestion Q. Just for information... Are you using kdm or sddm as your display manager? How does one find which display manager is being used?

fedup 20 - 21 - xinit - KDE - No mouse/keyboard input

2015-07-26 Thread Rich Emberson
So, I am now at the point where xinit (calling startkde) has the KDE screen appearing, but ... The pointer-cursor appears but can not be moved by the mouse, and (after some timeout and the login screen appears) keyboard entry fails. What does one do to enable both the mouse and keyboard. Thanks

fedup 20 - 21 - No X

2015-07-25 Thread Rich Emberson
Ah, fedora upgrades using fedup ... Starting with Fedora 20, did yum update and then fedup --network 21 --product=nonproduct Took a while but there were no issues but remember, as root export PATH=$PATH:$HOME/bin:/sbin:/usr/sbin or use su - to become root otherwise fedup has an issue.

fedup 20 - 21 - 22 - Plasma closed unexpectedly

2015-07-25 Thread Rich Emberson
Again, fedora upgrades using fedup ... Starting with Fedora 20, did ... stuff ... fedup --network 21 --product=nonproduct ... stuff ... fedup --network 22 --product=nonproduct So, now rebooted and it started. I have all my machines in multi-user mode just in case there is an issue with

Re: [389-users] How to use Host Based Attributes with Class of Service

2015-07-22 Thread Rich Megginson
On 07/22/2015 07:10 AM, Paul Tobias wrote: On 21/07/15 15:21, Rich Megginson wrote: On 07/21/2015 06:19 AM, Paul Tobias wrote: Hi guys, In short: Can I use Class of Service[1] together with Host Based Attributes[2]? It doesn't work for me. The directory server uses Host Based Attributes

Re: [389-users] How to use Host Based Attributes with Class of Service

2015-07-21 Thread Rich Megginson
On 07/21/2015 06:19 AM, Paul Tobias wrote: Hi guys, In short: Can I use Class of Service[1] together with Host Based Attributes[2]? It doesn't work for me. The directory server uses Host Based Attributes to give different loginshell on servers and desktops. The idea is that on a desktop

Re: [389-users] DNA Plugin Causes 389-DS to Crash if Large Number of Candidates

2015-07-16 Thread Rich Megginson
On 07/16/2015 05:47 PM, Fong, Trevor wrote: Hi Guys, We’re running 389-ds 1.2.11.29-1.el6 Can you upgrade to a newer version? There have been several releases since then. and are experimenting with the DNA plugin. When trying to set an existing account’s uidNumber to the magic regen

Re: [389-users] 389-ds access.log parsing - turning LDAP request type into an audit event

2015-07-13 Thread Rich Megginson
On 07/11/2015 09:29 PM, Burn Alting wrote: On Mon, 2015-07-06 at 08:00 -0600, Rich Megginson wrote: On 07/03/2015 05:49 AM, Burn Alting wrote: Has anyone authored code to parse a 389 Directory Server's access.log file(s) with an aim of generating audit events based around the LDAP request

Re: [389-users] winsyncsubtreepair

2015-07-07 Thread Rich Megginson
On 07/07/2015 10:07 AM, Mark Boyce wrote: Good Morning, Has anyone else seen this behavior; after configuring Winsync I add one or perhaps two “pairs” to the sync agreement (ds:AD) Firstly - what version of 389-ds-base? rpm -q 389-ds-base What version of Windows/AD? 2012 R2? I don't

Re: [389-users] winsyncsubtreepair

2015-07-07 Thread Rich Megginson
On 07/07/2015 11:49 AM, Mark Boyce wrote: Rich, The version of 389-ds-base is 1.3.3.10-1.fc22.x89-64 and it’s the same behavior running the agreement against AD 2003 or AD 2012. By “two pairs” in mean to indicate that I have two winsyncsubtree pair attributes; i.e ou=people,dc=example,dc

Re: [389-users] winsyncsubtreepair

2015-07-07 Thread Rich Megginson
On 07/07/2015 05:35 PM, Mark Boyce wrote: Rich, I am able to get the core dump and it appears to be a segmentation fault when modifying the replication agreement… anything specific from the dump that would be helpful? Not sure. Can you provide the full stack trace? Be sure to obscure

Re: [389-users] 389-ds access.log parsing - turning LDAP request type into an audit event

2015-07-06 Thread Rich Megginson
On 07/03/2015 05:49 AM, Burn Alting wrote: Has anyone authored code to parse a 389 Directory Server's access.log file(s) with an aim of generating audit events based around the LDAP request type. Basically, take the log sequence [21/Apr/2007:11:39:51 -0700] conn=11 fd=608 slot=608

Re: [389-users] Unit testing LDAP acis for fun and profit

2015-07-06 Thread Rich Megginson
On 07/04/2015 02:06 AM, William wrote: Hi, I am going to publish this as a blog post in the next few days on http://firstyear.id.au However, as it's relevant for this audience I decided to re-post it here. My workplace is a reasonably sized consumer of 389ds. We use it for storing pretty

Re: [389-users] Unit testing LDAP acis for fun and profit

2015-07-06 Thread Rich Megginson
On 07/06/2015 05:18 PM, William wrote: I will clean up and publish the usl tool set in the future to help other people test their own LDAP secuity controls. Nice! This would be a good addition to our admin/management tools, if you would like to submit it. Please open a ticket and attach the

Re: [389-users] Access to 389/636

2015-06-26 Thread Rich Megginson
On 06/26/2015 12:30 AM, Joshua Brodie wrote: Hi: Is it possible to source IP address restrict ldap transactions to ports 389 and 636 - outside of using external firewall or IP tables? Something like this?

Re: [389-users] Python3 support

2015-06-24 Thread Rich Megginson
On 06/24/2015 06:05 AM, Robert Kuska wrote: Hello everyone, I am Robert Kuska, I am a python co-maintainer and co-owner of change Python3 as default which aims to provide python3 only packages by default across different fedora platform releases[0]. The reason why I am contacting you is, that

Re: [389-users] Announcing 389 Directory Server version 1.3.4.0

2015-06-22 Thread Rich Megginson
On 06/22/2015 05:13 PM, Thomas Spuhler wrote: On Saturday, June 20, 2015 04:40:58 PM Noriko Hosoi wrote: 389 Directory Server 1.3.4.0 The 389 Directory Server team is proud to announce 389-ds-base version 1.3.4.0. Fedora packages are available from the Fedora 22 and Rawhide repositories.

Re: [389-users] _cl5CompactDBs: failed to compact

2015-06-19 Thread Rich Megginson
On 06/19/2015 04:29 AM, Ivanov Andrey (M.) wrote: Hi Noriko, There are three MMR replicating servers. It's one month of uptime and the servers wanted to trim the replication log. Here is what i've

Re: [389-users] 389-admin-1.1.36

2015-06-12 Thread Rich Megginson
On 06/12/2015 09:44 AM, Derek Belcher wrote: Where can I go to see the difference between: 389-admin-1.1.36 and 389-admin-1.1.35-1.el6.x86_64 If you checkout the repo from git: https://git.fedorahosted.org/cgit/389/admin.git You could do $ git diff 389-admin-1.1.35..389-admin-1.1.36

Re: [389-users] sourceforge hijack 389 directory server page?

2015-06-03 Thread Rich Megginson
On 06/03/2015 03:54 AM, Sharuzzaman Ahmat Raslan wrote: Hi 389 developers, I was reading news about Sourceforge is hijacking nmap page in Sourceforge. When I listed the page owned by user sf-editor1, it looks like 389 directory server was also hijacked. Are you aware of this? I was not

Re: [389-users] flag user must change password at next logon remains active after PassSync

2015-05-20 Thread Rich Megginson
On 05/20/2015 05:28 AM, Mihai Carabas wrote: Hello, We've setup an 389 Directory Server on a Fedora21 and configured synchronization with an Active Directory (running on an Windows2012R2 Datacenter). We've managed to synchronize all the accounts from the 389DS to AD (about 44000). All the

Re: [389-users] DS querying members groups not showing recent/updated members

2015-05-15 Thread Rich Megginson
On 05/15/2015 12:36 PM, Ghiurea, Isabella wrote: HI LIst, we are seeing some strange behavoiurs in our DS ( members of pluging is enabled) if we add a user to a group we can't see that new user in group for some minutes /days , the follwing curl returns 0 members in group but ( there were

Re: [389-users] selinux problem with centos 7.1

2015-04-17 Thread Rich Megginson
On 04/17/2015 08:19 AM, Angel Bosch wrote: I went through this with Mageia. You either need to enable selinux (permissive) or compile 389-ds without selinux. do you mean I won't be able to execute it without selinux? or is just the installer? Please file a ticket -

Re: [389-users] 389 DS merged with AD?

2015-04-14 Thread Rich Megginson
On 04/14/2015 12:41 PM, Gary Algier wrote: Hello, I am in search of a tool to solve a new directory server issue in relation to Active Directory... For a long time here at work, we have had LDAP as our authentication source and nsswitch source for Solaris and Linux. First it was the

Re: [389-users] No results from nsContainer subtree search

2015-04-07 Thread Rich Megginson
On 04/07/2015 12:00 AM, William wrote: I ran the following search: ldapsearch -H ldap://localhost -b 'cn=nsAccountInactivationTmp,dc=example' -s sub -Z -x -D 'cn=Directory Manager' -W '(objectClass=*)' '*' I was trying to locate the object:

Re: [389-users] Retro ChangeLog

2015-03-20 Thread Rich Megginson
On 03/20/2015 11:28 AM, Joshua Brodie wrote: https://access.redhat.com/documentation/en-US/Red_Hat_Directory_Server/8.2/html/Administration_Guide/Managing_Replication-Using_the_Retro_Changelog_Plug_in.html You should use the latest docs -

Re: [389-users] GUI console and Kerberos

2015-03-12 Thread Rich Megginson
On 03/11/2015 11:54 AM, Paul Robert Marino wrote: Hey every one I have a question I know at least once in the past i setup the admin console so it could utilize Kerberos passwords based on a howto I found once which after I changed jobs I could never find again. today I was looking for

Re: [389-users] Review 389-ds install/upgrade procedures and requisites on http://directory.fedoraproject.org/docs/389ds/download.html

2015-03-10 Thread Rich Megginson
, then yes, for changes to the core 389-ds-base package. On Mar 9, 2015, at 8:01 PM, Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com wrote: On 03/09/2015 05:54 PM, Rich Megginson wrote: On 03/09/2015 04:44 PM, Robert Viduya wrote: On Mar 9, 2015, at 5:30 PM, Noriko Hosoi nho

Re: [389-users] Review 389-ds install/upgrade procedures and requisites on http://directory.fedoraproject.org/docs/389ds/download.html

2015-03-09 Thread Rich Megginson
On 03/09/2015 12:39 AM, Juan Carlos Camargo wrote: I'd like to see an updated install/upgrade procedure for 389-ds. The info on the web page is outdated, links for coprs are not working either , maybe they are not valid anymore. They are not, and have been removed. It was just too difficult

Re: [389-users] Review 389-ds install/upgrade procedures and requisites on http://directory.fedoraproject.org/docs/389ds/download.html

2015-03-09 Thread Rich Megginson
using the old rmeggins repo or a copr repo, see http://www.port389.org/docs/389ds/releases/end-1-2-11.html Thanks. Is compiling from source our only option? Because, I can do that. I'd just rather not have to. On Mar 9, 2015, at 10:26 AM, Rich Megginson rmegg...@redhat.com mailto:rmegg

Re: [389-users] Review 389-ds install/upgrade procedures and requisites on http://directory.fedoraproject.org/docs/389ds/download.html

2015-03-09 Thread Rich Megginson
On 03/09/2015 05:54 PM, Rich Megginson wrote: On 03/09/2015 04:44 PM, Robert Viduya wrote: On Mar 9, 2015, at 5:30 PM, Noriko Hosoi nho...@redhat.com mailto:nho...@redhat.com wrote: Hello, On 03/09/2015 02:18 PM, Robert Viduya wrote: I'm in the same boat. We, as an enterprise, have

  1   2   3   4   5   6   7   8   9   10   >