Re: understanding ldap

2013-06-25 Thread Michael Ströder
Howard Chu wrote: Michael Ströder wrote: Rodney Simioni wrote: /etc/openldap/ldap.conf # this config file is openldap server's ldap config file? No, it's a LDAP client config. Mostly likely for OpenLDAP ldap* command-line tools but sometimes also for other components. /etc/ldap.conf #

Defining search depth for mod_ldap.

2013-06-25 Thread Mangesh Sawant
Hi, when searching a user mod_ldap returns only parent node attributes. Is there any setting so that search will return parent node attributes as well. LDAP URS is as follows: LdapUrl=ldap:// 172.16.100.237/ou=radiusUserProfile,dc=mtnl,dc=com?uid,userPassword,cn,sn? Here I could get back only

SASL Proxy Authorization

2013-06-25 Thread Vishesh kumar
Hi Members, I am trying to get SASL Proxy Authorization in work. GSSAPI authentication is already in place SASL/GSSAPI authentication started SASL username: admin@LINUXMANTRA.LOCAL SASL SSF: 56 SASL data security layer installed. dn:uid=admin,cn=gssapi,cn=auth

Re: SASL Proxy Authorization

2013-06-25 Thread Dan White
On 06/25/13 18:04 +0530, Vishesh kumar wrote: Hi Members, I am trying to get SASL Proxy Authorization in work. GSSAPI authentication is already in place SASL/GSSAPI authentication started SASL username: admin@LINUXMANTRA.LOCAL SASL SSF: 56 SASL data security layer installed.

Re: SASL Proxy Authorization

2013-06-25 Thread Vishesh kumar
I able to resolve it. Thanks for info. On Tue, Jun 25, 2013 at 7:49 PM, Dan White dwh...@olp.net wrote: On 06/25/13 18:04 +0530, Vishesh kumar wrote: Hi Members, I am trying to get SASL Proxy Authorization in work. GSSAPI authentication is already in place SASL/GSSAPI

RE: openldap and MozNSS

2013-06-25 Thread Rodney Simioni
I'm getting further, I went to http://ltb-project.org and downloaded a newer version of openldap. BTW, thank you, it's a nice site. But when I do a 'ldapsearch -d -1 -x -LLL -ZZ', I'm getting unsupported extended operation Does anybody have a clue? read1msg: ld 0x22f9b60 0 new referrals

RE: openldap and MozNSS

2013-06-25 Thread Quanah Gibson-Mount
--On Tuesday, June 25, 2013 11:40 AM -0400 Rodney Simioni rodney.simi...@verio.net wrote: I'm getting further, I went to http://ltb-project.org and downloaded a newer version of openldap. BTW, thank you, it's a nice site. But when I do a 'ldapsearch -d -1 -x -LLL -ZZ', I'm getting

RHEL 6.3 /Openldap-2.4.35

2013-06-25 Thread Darouichi, Aziz
Hi All, I am trying to compile Openldap-2.4.35 on RHEL 6.3 to enable SSL/TLS and I get the following error: -configure: WARNING: Could not locate TLS/SSL package -configure: WARNING: TLS data protection not supported! - I installed openssl-1.0.1e - gnutls-2.8.6 -

Re: RHEL 6.3 /Openldap-2.4.35

2013-06-25 Thread Quanah Gibson-Mount
--On Tuesday, June 25, 2013 12:41 PM -0400 Darouichi, Aziz adaro...@post03.curry.edu wrote: Hi All, I am trying to compile Openldap-2.4.35 on RHEL 6.3 to enable SSL/TLS and I get the following error: -configure: WARNING: Could not locate TLS/SSL package -configure: WARNING: TLS

RE: RHEL 6.3 /Openldap-2.4.35

2013-06-25 Thread Darouichi, Aziz
Thanks for the tip. I was able to build after I installed openssl-development packages -Original Message- From: Quanah Gibson-Mount [mailto:qua...@zimbra.com] Sent: Tuesday, June 25, 2013 1:20 PM To: Darouichi, Aziz; openldap-technical@openldap.org Subject: Re: RHEL 6.3

High load times with mdb

2013-06-25 Thread Bill MacAllister
With the release of Debian 7 (wheezy) I was rebuilding a couple test systems and was surprised to find that the load times I am seeing for populating the mdb database with slapd have gone up dramatically. The load for a master server that was taking about 10 minutes just took 35 minutes. The

RE: openldap and MozNSS

2013-06-25 Thread Rodney Simioni
Comment below. -Original Message- From: Quanah Gibson-Mount [mailto:qua...@zimbra.com] Sent: Tuesday, June 25, 2013 12:27 PM To: Rodney Simioni; openldap-technical@openldap.org Subject: RE: openldap and MozNSS --On Tuesday, June 25, 2013 11:40 AM -0400 Rodney Simioni

RE: openldap and MozNSS

2013-06-25 Thread Quanah Gibson-Mount
--On Tuesday, June 25, 2013 2:01 PM -0400 Rodney Simioni rodney.simi...@verio.net wrote: Comment below. -Original Message- From: Quanah Gibson-Mount [mailto:qua...@zimbra.com] Sent: Tuesday, June 25, 2013 12:27 PM To: Rodney Simioni; openldap-technical@openldap.org Subject: RE:

Re: High load times with mdb

2013-06-25 Thread Quanah Gibson-Mount
--On Tuesday, June 25, 2013 10:29 AM -0700 Bill MacAllister w...@stanford.edu wrote: With the release of Debian 7 (wheezy) I was rebuilding a couple test systems and was surprised to find that the load times I am seeing for populating the mdb database with slapd have gone up dramatically. The

Re: High load times with mdb

2013-06-25 Thread Bill MacAllister
--On Tuesday, June 25, 2013 11:06:50 AM -0700 Quanah Gibson-Mount qua...@zimbra.com wrote: --On Tuesday, June 25, 2013 10:29 AM -0700 Bill MacAllister w...@stanford.edu wrote: With the release of Debian 7 (wheezy) I was rebuilding a couple test systems and was surprised to find that the

RE: openldap and MozNSS

2013-06-25 Thread Rodney Simioni
-Original Message- From: openldap-technical-boun...@openldap.org [mailto:openldap-technical-boun...@openldap.org] On Behalf Of Quanah Gibson-Mount Sent: Tuesday, June 25, 2013 2:05 PM To: Rodney Simioni; openldap-technical@openldap.org Subject: RE: openldap and MozNSS --On Tuesday,

Re: High load times with mdb

2013-06-25 Thread Quanah Gibson-Mount
--On Tuesday, June 25, 2013 12:38 PM -0700 Bill MacAllister w...@stanford.edu wrote: The load starts out at a rate of about 2 M/s. In the past I remember that dropping to something like 900 k/s and staying there. Now the load starts in the same place, but after 30 seconds it alternates

Question on assigning a new user with admin role

2013-06-25 Thread Kumar, Amit
Hi, I have little experience with managing LDAP servers. Previously with just one file slapd.conf it was lot easier to assign a user a role of an admin, just by giving access to attrs=...by With newer version of openldap-servers-2.4.23-26 on RHEL 6.x this is not the same, and hope you can

Re: High load times with mdb

2013-06-25 Thread Bill MacAllister
--On Tuesday, June 25, 2013 12:58:54 PM -0700 Quanah Gibson-Mount qua...@zimbra.com wrote: --On Tuesday, June 25, 2013 12:38 PM -0700 Bill MacAllister w...@stanford.edu wrote: The load starts out at a rate of about 2 M/s. In the past I remember that dropping to something like 900 k/s and

unsupported extended operation

2013-06-25 Thread Rodney Simioni
Hi, I just compiled openldap with: ./configure --prefix=/usr/local/openldap --enable-ldap --with-tls=openssl --with-cyrus-sasl --enable-crypt I did a 'make depend', 'make', and a 'make install'; I didn't see any errors. I fired up ldap with: './slapd -d127 -h ldap:///;' Then I went

Re: unsupported extended operation

2013-06-25 Thread Quanah Gibson-Mount
--On Tuesday, June 25, 2013 5:34 PM -0400 Rodney Simioni rodney.simi...@verio.net wrote: Hi, I just compiled openldap with: ./configure --prefix=/usr/local/openldap --enable-ldap --with-tls=openssl --with-cyrus-sasl --enable-crypt Did you actually configure certs for the server to use?

Re: unsupported extended operation

2013-06-25 Thread Philip Guenther
On Tue, 25 Jun 2013, Rodney Simioni wrote: I just compiled openldap with: ./configure --prefix=/usr/local/openldap --enable-ldap --with-tls=openssl --with-cyrus-sasl --enable-crypt I did a 'make depend', 'make', and a 'make install'; I didn't see any errors. I fired up ldap with: './slapd

Re: unsupported extended operation

2013-06-25 Thread Howard Chu
Rodney Simioni wrote: Hi, I just compiled openldap with: ./configure --prefix=/usr/local/openldap --enable-ldap --with-tls=openssl --with-cyrus-sasl --enable-crypt I did a ‘make depend’, ‘make’, and a ‘make install’; I didn’t see any errors. I fired up ldap with: ‘./slapd -d127 -h ldap:///’

RE: unsupported extended operation

2013-06-25 Thread Rodney Simioni
-Original Message- From: Howard Chu [mailto:h...@symas.com] Sent: Tuesday, June 25, 2013 6:36 PM To: Rodney Simioni; openldap-technical@openldap.org Subject: Re: unsupported extended operation Rodney Simioni wrote: Hi, I just compiled openldap with: ./configure

RE: unsupported extended operation

2013-06-25 Thread Quanah Gibson-Mount
--On Tuesday, June 25, 2013 8:34 PM -0400 Rodney Simioni rodney.simi...@verio.net wrote: This is my slapd.ldif This is my /usr/local/openldap/etc/openldap/slapd.conf Are you using slapd.conf or cn=config? If you are using cn=config, then you have not provided any indication that you

Re: High load times with mdb

2013-06-25 Thread Bill MacAllister
--On Tuesday, June 25, 2013 03:10:17 PM -0700 Howard Chu h...@symas.com wrote: Bill MacAllister wrote: --On Tuesday, June 25, 2013 12:58:54 PM -0700 Quanah Gibson-Mount qua...@zimbra.com wrote: --On Tuesday, June 25, 2013 12:38 PM -0700 Bill MacAllister w...@stanford.edu wrote: The