Openldap doesn't force password change and other related problems

2013-03-04 Thread Francesco Belli
Hello All, I probably have something misconfigured on my openldap server, but it seems that this is not so easy to debug (for me). I use openldap 2.4.23 with ppolicy and accesslog overlays. I have the following behaviours: - when pwdMustChange and pwdReset are set to true, after login, user

Re: Combining AD and Local DB into single 'virtual' tree

2013-03-04 Thread Howard Chu
Mailing Lists wrote: Hello, I posted a question along these lines a few months ago and received replies, but never understood enough to implement them. I've done more research in the meantime and hopefully have learned enough to ask this question intelligently. I'm working on a project proposal

Mirror mode and cn=config replication

2013-03-04 Thread John Baker
Hi, We have been using mirror mode for some time as a simple way for us to have an up to date copy in case of a crash and load balancing. We have been using the older slapd.conf configuration in Ubntu Hardy and are now moving up to 2.4.28 in Ubuntu Precise. The documentation for N-way multi

Re: Mirror mode and cn=config replication

2013-03-04 Thread Quanah Gibson-Mount
--On Monday, March 04, 2013 3:39 PM -0500 John Baker john...@marlboro.edu wrote: Hi, We have been using mirror mode for some time as a simple way for us to have an up to date copy in case of a crash and load balancing. We have been using the older slapd.conf configuration in Ubntu Hardy and

Re: Mirror mode and cn=config replication

2013-03-04 Thread John Baker
Thanks for the reply, gnutls is a pain but we've been able to make it work and the boss hates it when we use source so I'm kind of stuck with it as it is unless I can make a better case than ssl. So mirror mode is really defined by the load balancer in front? I guess this is a bit confusing in

Re: Mirror mode and cn=config replication

2013-03-04 Thread Quanah Gibson-Mount
--On Monday, March 04, 2013 4:45 PM -0500 John Baker john...@marlboro.edu wrote: Thanks for the reply, gnutls is a pain but we've been able to make it work and the boss hates it when we use source so I'm kind of stuck with it as it is unless I can make a better case than ssl.  You need to

Re: Mirror mode and cn=config replication

2013-03-04 Thread Quanah Gibson-Mount
--On Monday, March 04, 2013 2:03 PM -0800 Quanah Gibson-Mount qua...@zimbra.com wrote: --On Monday, March 04, 2013 4:45 PM -0500 John Baker john...@marlboro.edu wrote: Thanks for the reply, gnutls is a pain but we've been able to make it work and the boss hates it when we use source so I'm