Re: Antw: [EXT] Symas openldap 2.5 RPMs / openssl cert trust

2021-10-25 Thread Paul B. Henson
On 10/25/2021 12:33 PM, Quanah Gibson-Mount wrote: Symas OpenLDAP 2.5 (and soon 2.6) reflect how we would package the software.  Note that in 2.6, you can specify multiple paths to find CA certs in, so you could configure it to use the system CAs as well as your own local certificate

Re: Compound indexing with

2021-10-25 Thread thomaswilliampritchard
Okay thanks for the information. Re-reading the docs I mistakenly thought olcDbIndex: member,description eq would create a compound index with those two fields, but it appears it is actually equivalent to olcDbIndex: member eq olcDbIndex description eq

Re: Compound indexing with

2021-10-25 Thread Howard Chu
thomaswilliampritch...@gmail.com wrote: > Thanks for the response Howard. > > Will the openldap search filter logging contain information about query plans > / work? There are no compound indices nor query plans. This is not an RDBMS. -- -- Howard Chu CTO, Symas Corp.

Re: Antw: [EXT] Symas openldap 2.5 RPMs / openssl cert trust

2021-10-25 Thread Quanah Gibson-Mount
--On Monday, October 25, 2021 12:33 PM -0700 "Paul B. Henson" wrote: On 10/24/2021 11:19 PM, Ulrich Windl wrote: Some time ago the way to install root certificates had changed You mean on the server side? There's nothing wrong with the certificate chain on the server, everything

Re: Antw: [EXT] Symas openldap 2.5 RPMs / openssl cert trust

2021-10-25 Thread Paul B. Henson
On 10/24/2021 11:19 PM, Ulrich Windl wrote: Some time ago the way to install root certificates had changed You mean on the server side? There's nothing wrong with the certificate chain on the server, everything trusts that properly including the ldapsearch included with the Symas openldap

Re: Compound indexing with

2021-10-25 Thread thomaswilliampritchard
Thanks for the response Howard. Will the openldap search filter logging contain information about query plans / work? Could I expect better performance using a composite index with higher cardinality first where assuming description was the same on 90% of groups and then I add indexes such

Re: contextCSN not updated

2021-10-25 Thread Quanah Gibson-Mount
--On Monday, October 25, 2021 1:29 PM + bourgu...@gmail.com wrote: Dears, I found the cause if I can tell it like this, in fact, it's only for cn=config for which there are replication settings set for the 4MMR but not for the replica, then the contextCSN of replica isn't modified when

Re: contextCSN not updated

2021-10-25 Thread bourguijl
Dears, I found the cause if I can tell it like this, in fact, it's only for cn=config for which there are replication settings set for the 4MMR but not for the replica, then the contextCSN of replica isn't modified when I do any kind of modification to its cn=config. I still have a question

Re: Problem with SSL/TLS on CentOS 7 after upgrading to 2.4.59

2021-10-25 Thread Bastian Tweddell
On 21Oct21 18:39+0300, Nick Milas wrote: > It shows that the CA/cert has issues. Yet, everything was working fine > until last upgrade! Check your ldaprc for TLS_REQCERT. Maybe that changed in the upgrade? -- Bastian TweddellJuelich Supercomputing Centre smime.p7s Description: