Re: Problems importing ppolicy LDIF: LDAP_INVALID_SYNTAX

2011-01-13 Thread Dieter Kluenter
Am Thu, 13 Jan 2011 11:42:29 +0600 schrieb Konstantin Boyandin temmo...@gmail.com: Hello, OpenLDAP version: 2.3.43-12 (CentOS 5.5), 64-bit. In order to enable ppolicy overlay, I am trying to create the relevant entries, as specified in

Re: LDAP and PAM: account is expired, but pam_ldap allows authentification

2011-01-13 Thread Howard Chu
Indexer wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 shadowExpire shadowLastChange shadowMin shadowMax to make the account expired (OpenLDAP used to run NT domain), but when I ssh to a server using pam_ldap authentication, it is still allowed to login. This look to be a question

Re: Problems importing ppolicy LDIF: LDAP_INVALID_SYNTAX

2011-01-13 Thread Konstantin Boyandin
13.01.2011 13:39, Howard Chu writes: Konstantin Boyandin wrote: Hello, OpenLDAP version: 2.3.43-12 (CentOS 5.5), 64-bit. In order to enable ppolicy overlay, I am trying to create the relevant entries, as specified in http://www.openldap.org/doc/admin24/overlays.html#Password%20Policies

Re: LDAP and PAM: account is expired, but pam_ldap allows authentification

2011-01-13 Thread Indexer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 It was obvious that he was not asking why doesn't my pam_ldap talk to my OpenLDAP server. Missing elements from the user objects is a *data* problem, it is not an interoperability problem. He would have the same issue whether the server was

Re: Problems importing ppolicy LDIF: LDAP_INVALID_SYNTAX

2011-01-13 Thread Pierangelo Masarati
Chris Jacobs wrote: Perhaps try man slapo_ppolicy The man page name is slapo-ppolicy(5). - it should hopefully provide the limits and acceptable values and compare with your ldif to find the cause of Error description: An invalid attribute value was specified. Alternative: reduce the

Re: Problems importing ppolicy LDIF: LDAP_INVALID_SYNTAX

2011-01-13 Thread Konstantin Boyandin
13.01.2011 14:16, Pierangelo Masarati writes: Chris Jacobs wrote: Perhaps try man slapo_ppolicy The man page name is slapo-ppolicy(5). - it should hopefully provide the limits and acceptable values and compare with your ldif to find the cause of Error description: An invalid attribute

Re: Problems importing ppolicy LDIF: LDAP_INVALID_SYNTAX

2011-01-13 Thread Howard Chu
Konstantin Boyandin wrote: 13.01.2011 13:39, Howard Chu writes: Konstantin Boyandin wrote: Hello, OpenLDAP version: 2.3.43-12 (CentOS 5.5), 64-bit. In order to enable ppolicy overlay, I am trying to create the relevant entries, as specified in

Re: Problems importing ppolicy LDIF: LDAP_INVALID_SYNTAX

2011-01-13 Thread Howard Chu
Pierangelo Masarati wrote: Chris Jacobs wrote: Perhaps try man slapo_ppolicy The man page name is slapo-ppolicy(5). - it should hopefully provide the limits and acceptable values and compare with your ldif to find the cause of Error description: An invalid attribute value was specified.

Re: Problems importing ppolicy LDIF: LDAP_INVALID_SYNTAX

2011-01-13 Thread Pierangelo Masarati
Konstantin Boyandin wrote: Or check the archives, e.g. http://www.openldap.org/lists/openldap-software/200802/msg00337.html: for some time, in OpenLDAP 2.3, the pwdAttribute could only contain OIDs. Thank you very much! After I changed the string to pwdAttribute: 2.5.4.35 the import was a

Re: Problems importing ppolicy LDIF: LDAP_INVALID_SYNTAX

2011-01-13 Thread Howard Chu
Pierangelo Masarati wrote: Konstantin Boyandin wrote: Or check the archives, e.g. http://www.openldap.org/lists/openldap-software/200802/msg00337.html: for some time, in OpenLDAP 2.3, the pwdAttribute could only contain OIDs. Thank you very much! After I changed the string to pwdAttribute:

Re: Evolution Contacts Schema

2011-01-13 Thread Bjørn Ruberg
On 01/12/2011 11:14 PM, Peter L. Berghold wrote: Now the trouble I'm having (now that the schema is set) is when I attempt to add an entry from Evolution I get error: other which doesn't tell much. From the phpLDAPAdmin tool I get the error Could not perform ldap_modify operation. LDAP said:

Re: Evolution Contacts Schema

2011-01-13 Thread Stefan Palme
On Thu, 2011-01-13 at 10:04 +0100, Bjørn Ruberg wrote: On 01/12/2011 11:14 PM, Peter L. Berghold wrote: Now the trouble I'm having (now that the schema is set) is when I attempt to add an entry from Evolution I get error: other which doesn't tell much. From the phpLDAPAdmin tool I get

Hello, how

2011-01-13 Thread Alexey Shalin
Good afternoon, Tell me how to exclude the user's search from thesecurity policies The user is located in the ou =users Ou=policy also located in ou=users The reason that I need to exclude the user, is that when I set the pwdMaxAge and pwdGraceAuthNLimit. I can not log into the