Re: About ppolicy

2013-05-06 Thread Jacques Foucry
Le 03/05/2013 17:04, Aaron Richton a écrit : Aaron, Any shadowAccount concepts and slapo-ppolicy are independent. Your local implementation can consider the usage of one/both/neither in a coordinated fashion, but slapd won't help you in this manner. Ok. Note that slapo-ppolicy operates

Using LDAP how to restrict users to certain applications only

2013-05-06 Thread Geo P.C.
Hi We are using many applications like zabbix, phabricator, AC etc. We need to integrate LDAP in all these applications. These application support LDAP but not group based authentication. Please let us know is there any option to restrict selected users to login. We created all users under ou

Re: Use LDAP netgroup to control NFS exports?

2013-05-06 Thread Vishesh kumar
Hello Jupitor, What I know is NFS4 implementation where user/group based ACL can be applied. Not sure if NFS3 support other than host based ACL. Thanks Vishesh Kumar http://linuxmantra.com On Thu, May 2, 2013 at 6:24 PM, jupiter jupiter@gmail.com wrote: Hi, I am running LDAP server and

invalid value for attributeType olcSuffix while restoring cn=config (slapd-2.4.33)

2013-05-06 Thread Igor Zinovik
Hello, openldap-technical@ readers. I backed up cn=config from openldap-2.4.33 and now i try to restore it, but with no success. I made backup copy this way: ldap1# sudo slapcat -b cn=config -F /etc/openldap/slapd.d -l config.ldif After this i created new clean VM with opensuse 12.3 and slapd

Unable to use TLS in a 2-WayMaster/MirrorMode Setup

2013-05-06 Thread Thomas Macaigne
Hi, It's been a few days I'm trying to replicate my actual LDAP server on a new one. @(#) $OpenLDAP: slapd 2.4.21 (Dec 19 2011 15:18:58) $ buildd@roseapple:/build/buildd/openldap-2.4.21/debian/build/servers/slapd and @(#) $OpenLDAP: slapd  (Oct 17 2012 19:48:41) $

Re: Unable to use TLS in a 2-WayMaster/MirrorMode Setup

2013-05-06 Thread Quanah Gibson-Mount
--On Monday, May 06, 2013 4:15 PM +0200 Thomas Macaigne t.macai...@beware.fr wrote: Hi, It's been a few days I'm trying to replicate my actual LDAP server on a new one. @(#) $OpenLDAP: slapd 2.4.21 (Dec 19 2011 15:18:58) $

cleaning HDB after an unclean shutdown

2013-05-06 Thread Benin Technologies
Hi, I'm doing some tests on a perl backend, which causes sometimes my OpenLDAP to hang. I then kill the process, but when I try to restart openldap it won't, because of my HDB backend. I get the following message : db_db_open: database dc=mycompany: database already in use. After rebooting

Re: cleaning HDB after an unclean shutdown

2013-05-06 Thread Howard Chu
Benin Technologies wrote: Hi, I'm doing some tests on a perl backend, which causes sometimes my OpenLDAP to hang. I then kill the process, but when I try to restart openldap it won't, because of my HDB backend. I get the following message : db_db_open: database dc=mycompany: database already

Re: cleaning HDB after an unclean shutdown

2013-05-06 Thread Benin Technologies
nope, Debian 6.0.4 Le 06/05/2013 20:25, Howard Chu a écrit : Benin Technologies wrote: Hi, I'm doing some tests on a perl backend, which causes sometimes my OpenLDAP to hang. I then kill the process, but when I try to restart openldap it won't, because of my HDB backend. I get the following

Re: cleaning HDB after an unclean shutdown

2013-05-06 Thread Quanah Gibson-Mount
--On Monday, May 06, 2013 8:36 PM +0100 Benin Technologies benintechnolog...@yahoo.fr wrote: nope, Debian 6.0.4 Try the related db_recover command for the version of BDB your openldap is compiled for, and if that doesn't work, also remove the alock file. Then try starting slapd.

Re: cleaning HDB after an unclean shutdown

2013-05-06 Thread Howard Chu
Benin Technologies wrote: nope, Debian 6.0.4 The only reason for slapd to say the database is already in use is because a file lock still exists. In this case it implies that the original slapd process is still there. You said you already killed it but it sounds like the process hasn't gone

dynamic group perfs

2013-05-06 Thread Jephte Clain
hello all, I have a weird perf problem with a dynamic group. I wonder if it is normal, and if I can improve the situation. jump to the line marked - for the impatients, JUMP HERE :-) if you want to skip the details This is openldap 2.4.35 on debian 6 (built from source with

Re: Using LDAP how to restrict users to certain applications only

2013-05-06 Thread Geo P.C.
Please let me know is it possible to implement this idea?. Also please let me know your thoughts. Thanks Geo *Thanks Regards Geo P.C. www.geopc.co.cc* On Mon, May 6, 2013 at 3:51 PM, Geo P.C. pcge...@gmail.com wrote: Hi We are using many applications like zabbix, phabricator, AC etc.