Re: otp vs totp

2024-02-02 Thread Bastian Tweddell
ution is in, we'd always welcome testing > of it. :) This is wonderful. Thank you very much. I added myself to Cc on that ticket. I'm looking forward to testing it :) Cheers, -- Bastian TweddellJuelich Supercomputing Centre phone: +49 (2461) 61-6586

Re: UNKNOWN attributeDescription "..." inserted.

2024-02-01 Thread Bastian Tweddell
rPassword schema '{TOTP1}'. Maybe I wrong or outdated here and slapo-opt also supports TOTP-only authentication now? Cheers, -- Bastian TweddellJuelich Supercomputing Centre phone: +49 (2461) 6

Re: UNKNOWN attributeDescription "..." inserted.

2024-02-01 Thread Bastian Tweddell
some follow-up questions here. If you > > prefer, I'll write another mail or I could open an issue on bugzilla. > > Open a separate issue in bugzilla. Will do. Many Thanks, -- Bastian TweddellJue

UNKNOWN attributeDescription "..." inserted.

2024-01-31 Thread Bastian Tweddell
ugh). Many thanks in advance, -- Bastian TweddellJuelich Supercomputing Centre phone: +49 (2461) 61-6586

Re: Transitioning from slapd.conf to slapd.d, best practices for maintaining configuration comments?

2023-11-30 Thread Bastian Tweddell
1: https://www.openldap.org/doc/admin26/slapdconf2.html Cheers, -- Bastian TweddellJuelich Supercomputing Centre

Re: How to get detailed connection error information?

2023-04-14 Thread Bastian Tweddell
y practical approach is to use `-d -1` on the ldap commands. -- Bastian TweddellJuelich Supercomputing Centre smime.p7s Description: S/MIME cryptographic signature

Re: Backup Mirrormode setup

2023-03-08 Thread Bastian Tweddell
pgrading your systems. And just to repeat that previous and important paragraph: I tested everthing in advance so I felt confident while doing it during production. I suggest you do testing as well. HIH, -- Bastian TweddellJuelich

Re: about slapo totp

2023-02-09 Thread Bastian Tweddell
On 18Jan23 16:53+, Howard Chu wrote: > Use the contrib module instead, it only does TOTP and nothing else. In the meahnwhile we have working testbed and I would like to thank you for your valuable input. Cheers, -- Bastian TweddellJuelich Supercomputing Centre phone: +49 (2

Re: about slapo totp

2023-01-18 Thread Bastian Tweddell
debug) Many thanks, -- Bastian TweddellJuelich Supercomputing Centre phone: +49 (2461) 61-6586 HPC in Neuroscience, HPS

Re: about slapo totp

2023-01-18 Thread Bastian Tweddell
Many thanks to all for your comments. I think I know how this feature can integrated into our infrastructure. I'll bring this into a testing environment now. Cheers, On 17Jan23 21:27+, Howard Chu wrote: > Bastian Tweddell wrote: > > On 17Jan23 17:33+, Howard Chu wrote: &g

Re: about slapo totp

2023-01-17 Thread Bastian Tweddell
ccessible hosts). Many thanks, Cheers, -- Bastian TweddellJuelich Supercomputing Centre phone: +49 (2461) 61-6586 HPC in Neuroscience, HPS smime.p7s Description: S/MIME cryptographic signature

about slapo totp

2023-01-17 Thread Bastian Tweddell
, no password) Does this make sense and can this be achieved? Thanks in advance, -- Bastian TweddellJuelich Supercomputing Centre phone: +49 (2461) 61-6586 HPC in Neuroscience, HPS

Re: Problem with SSL/TLS on CentOS 7 after upgrading to 2.4.59

2021-10-25 Thread Bastian Tweddell
On 21Oct21 18:39+0300, Nick Milas wrote: > It shows that the CA/cert has issues. Yet, everything was working fine > until last upgrade! Check your ldaprc for TLS_REQCERT. Maybe that changed in the upgrade? -- Bastian TweddellJuelich Supercomputing Centre smime.p7s Descript

Re: Symas OpenLDAP 2.5 RPMs run slapd as root?

2021-10-20 Thread Bastian Tweddell
SERVICE This is nice, I think about to adopt that and abandon -u/-g > LimitNOFILE=96 this could be too low, depending on use case. it limits nr of incoming connections. > RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX > # various hardening options from ansi

Re: OpenLDAP 2.6.0 testing call #2

2021-10-11 Thread Bastian Tweddell
Which is good, but the failed > > slaptest does not print the reason for the failure. > > Thanks, filed as ITS#9713. This should be fixed now in head and RE26, if > you would like to confirm. I updated this issue with a comment. Cheers, -- Bastian Twed

Re: OpenLDAP 2.6.0 testing call #2

2021-10-04 Thread Bastian Tweddell
On 30Sep21 08:39-0700, Quanah Gibson-Mount wrote: > > The setup we use is quite simple, so a number of tests are skipped. > > Would you recommend, or like to see certain configurations to be tested? > > Mainly the new logging bits. A minor thing: I think I discovered a change in slaptest in rc

Re: OpenLDAP 2.6.0 testing call #2

2021-09-30 Thread Bastian Tweddell
est skipped' make_test.out|wc -l 40 % grep 'Test .* disabled' make_test.out|wc -l 1 --- eop The numbers match. Looks good! The setup we use is quite simple, so a number of tests are skipped. Would you recommend, or like to see certain configurations to be tested? Cheers, -- Bastian Tweddell

Re: RESULT etime vs. qtime

2021-09-28 Thread Bastian Tweddell
eries data in Prometheus. > > > > So I wonder what's the difference? Is it worth to always look at both? We are using prometheus, too. Would you be so kind to share some information about mtail? Cheers, -- Bastian TweddellJuelich Supercomputing Centre phone: +49 (2461

Re: @Quanah About your blog

2020-09-15 Thread Bastian Tweddell
ast mail threads. Many thanks, -- Bastian TweddellJuelich Supercomputing Centre phone: +49 (2461) 61-6586 HPC in Neuroscience, HPS smime.p7s Description: S/MIME cryptographic signature

Re: slapd not running, not producing useful messages

2020-05-06 Thread Bastian Tweddell
In case slapd did not start up, I always succeeded to find the issue with: slapd ${YADAYADA} -d -1 `-d -1` enables all log levels, it's highly verbose. Cheers, -- Bastian TweddellJuelich Supercomputing Centre phone: +49 (2461) 61-6586 HPC in Neuroscience, HPS

Re: use proprietary password hash in "userpassword"

2017-01-19 Thread Bastian Tweddell
could solve your problem. 1: http://www.openldap.org/doc/admin24/security.html Cheers, -- Bastian Tweddell Juelich Supercomputing Centre phone: +49 (2461)

Re: MDB data replication issues

2016-07-01 Thread Bastian Tweddell
On 29Jun16 10:04-0700, Quanah Gibson-Mount wrote: > --On Wednesday, June 29, 2016 4:21 PM +0200 Bastian Tweddell > <b.twedd...@fz-juelich.de> wrote: > > > On 27Jun16 09:16-0700, Quanah Gibson-Mount wrote: > > > --On Monday, June 27, 2016 2:00 PM + Gurjot Kaur

Re: MDB data replication issues

2016-06-29 Thread Bastian Tweddell
d correctly, that I should prefer the use of ldapadd? Does ldapadd also support operational and user attributes? Many thanks, -- Bastian Tweddell Juelich Supercomputing Centre phone: +49 (2461) 61-6586 HPC in Neuroscience smime.p7s Description: S/MIME cryptographic signature

Re: MDB data replication issues

2016-06-27 Thread Bastian Tweddell
might be of interest to you. - After slapadd, run both servers with -d -1 and read the excessive debug information. These always helped me a lot. Cheers, -- Bastian Tweddell Juelich Supercomputing Centre phone: +49 (2461) 61-6586 HPC in Neuroscience smime.p7s Description: S/MIME cryptographic signature

Need help in design for users with multiple posixAccounts

2016-06-27 Thread Bastian Tweddell
the existing attribute? Do you think, keeping multiple entries for an user is too much overhead compared to use only one entry with multiple objectClasses? Many thanks, -- Bastian Tweddell Juelich Supercomputing Centre phone: +49 (2461) 61-6586 HPC in Neuroscience

Re: MDB data replication issues

2016-06-27 Thread Bastian Tweddell
For daily-business modifications to the LDAP DB I always use ldap* commands. Cheers, -- Bastian Tweddell Juelich Supercomputing Centre phone: +49 (2461) 61-6586 HPC in Neuroscience smime.p7s Description: S/MIME cryptographic signature

Re: mdb backup via slapcat

2016-06-27 Thread Bastian Tweddell
On 24Jun16 07:19-0700, Quanah Gibson-Mount wrote: > --On Friday, June 24, 2016 1:29 PM +0200 Bastian Tweddell > > I am used to run slapcat to create backups of the backend database > > _while_ slapd is running. Recently I migrated from bdb to mdb. Now I > > read that using

mdb backup via slapcat

2016-06-24 Thread Bastian Tweddell
: - Is that still true? - In which situation could data corruption occur? - Is that supposed to change in the future? Many thanks, -- Bastian Tweddell Juelich Supercomputing Centre phone: +49 (2461) 61-6586 HPCNS, HPS