Re: MDB Status

2012-10-01 Thread Jonathan Clarke
On 28/09/12 02:38, Howard Chu wrote: For those who haven't been following along, support for OpenLDAP's MDB (memory-mapped database) library is also available for several other open source projects, including Cyrus SASL (sasldb mech), Heimdal Kerberos (hdb module), SQLite3, OpenDKIM, and

Re: cannot populate with smbldap-populate

2012-04-29 Thread Jonathan Clarke
On 29 avr. 2012, at 10:27, stefano malini lozing...@gmail.com wrote: I used slapindex also, the output is: stefano@amahoro:~$ /usr/sbin/slapindex /etc/ldap/slapd.conf: line 20: invalid path: Permission denied slapindex: bad configuration file! Try running slapindex as the user openldap.

Re: Convert *.schema to *.ldif

2012-04-04 Thread Jonathan Clarke
Le 03/04/12 20:39, Francis Swasey a écrit : On 4/3/12 11:50 AM, Howard Chu wrote: I don't see any description in the admin guide about how to convert a *.schema file into a *.ldif file. Google tells me that most people are using slaptest with the -F and -f parameters with a specially

Re: Ubuntu can't connect to SambaPDC

2012-04-03 Thread Jonathan Clarke
Hi, On 02/04/12 14:52, Imre Bertalan wrote: Hi guys. This is not really an OpenLDAP question, but it seems we have some fine qualified users here, so I'll ask this question here. :) I have a nice working Zentyal 2.2 server with DNS and SambaPDC. Windows client's can join the domain with

Re: openldap proxy to AD

2012-04-03 Thread Jonathan Clarke
credentials=secret mode=none Will cause all connections to the proxied LDAP server to use those credentials. Is this what you're trying to achieve? Jonathan -- -- Jonathan Clarke - jonat...@phillipoux.net

Re: Password expiration

2012-04-03 Thread Jonathan Clarke
-- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization Connector (LSC) - http://lsc-project.org --

Re: REL_ENG versions produce different libraries?

2012-04-02 Thread Jonathan Clarke
On 30/03/2012 15:27, Howard Chu wrote: Nick Milas wrote: On 30/3/2012 3:04 μμ, Nick Milas wrote: I would expect some test parameter in build/version.var, but I didn't see any. Hmm, I guess I could simply change (in build/version.var): ol_patch=X from X to e.g. 29a or to 29.1 ? Would

Re: Schema definitions: from Sun DS to OpenLDAP

2011-06-07 Thread Jonathan Clarke
On 07/06/11 08:06, Silvio Verrecchia wrote: Hello gurus, I'm migrating a Sun DS to Openldap and I've an highly personalized 99user.ldif file with user defined objectclass and attributes (hundreds... :( :( ) Regarding personalized schema definitions, is there a way (script/batch/etc) to

Re: question about cn=config replication and security.

2011-02-12 Thread Jonathan Clarke
to change the configs ? Hi, I'm not entirely sure I've understood your question, but you can write ACLs to allow any user (using any DN, thus including a DN from a BDB database) access to the cn=config subtree. Jonathan -- -- Jonathan

Re: Slapd Security based on port

2011-02-12 Thread Jonathan Clarke
-- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization Connector (LSC) - http://lsc-project.org --

Re: slapo-lastbind

2011-02-07 Thread Jonathan CLARKE
failed password attempts or other operational attributes (actually, using the chain overlay it is possible to forward these updates for ppolicy but not currently with the lastbind overlay ). Jonathan -- == Jonathan CLARKE

Re: slapo-lastbind

2011-02-07 Thread Jonathan CLARKE
-- == Jonathan CLARKE -- Normation 44 rue Cauchy, 94110 Arcueil, France -- Telephone: +33 (0)1 83 62 41 24 -- Web:http://www.normation.com/ ==

Re: OpenLDAP server as a proxy to AD and local auth db

2011-01-25 Thread Jonathan Clarke
installation. Hope this helps, Jonathan -- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization Connector (LSC) - http://lsc-project.org --

Re: CLI remotes write, php remotes can't

2011-01-22 Thread Jonathan Clarke
On 23 janv. 2011, at 00:30, m...@grounded.net m...@grounded.net wrote: I'm trying to find leads on what else to look for with this problem. Locally, I can create users, etc. From remote centos servers, I can create and read account info from command line. However, from remotes using

Re: Pass-Through authentication

2010-11-15 Thread Jonathan Clarke
On 14/11/10 18:29, Paulo Jorge N. Correia (paucorre) wrote: Hi all, I’m just starting with openLDAP and saslauth, and I’m trying to replicate what I can achieve with ADAM/AD LDS in Windows platform. I’m trying to use openldap to aggregate user information from several AD servers

Re: Sometimes getent missing users

2010-10-19 Thread Jonathan CLARKE
be faulty, either on the clients or the server? What results do you get when running a similar search manually from the clients, via ldapsearch? Any error or warning messages in the slapd logs? Jonathan -- == Jonathan CLARKE

Re: questions about openldap replication

2010-10-07 Thread Jonathan Clarke
based relation. Hope this clears some things up! Jonathan -- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization Connector (LSC) - http://lsc-project.org --

Re: syncrepl only working in one direction

2010-09-24 Thread Jonathan CLARKE
Hi, Le 24/09/2010 07:31, Alister Forbes a écrit : Hi Jonathon, On 23 Sep 2010, at 15:24, Jonathan CLARKE wrote: Hello Alister, Le 23/09/2010 12:04, Alister Forbes a écrit : All, I have two identical servers (RHEL based VMs, server1 and server3) running 2.4.23 openldap. built

Re: syncrepl only working in one direction

2010-09-23 Thread Jonathan CLARKE
with -c rid=001 -c rid=003, to reset the replication status, and take it from there. Hope this helps, Jonathan -- == Jonathan CLARKE -- Normation 44 rue Cauchy, 94110 Arcueil, France

Re: Replicating from a mirrormode pair to a read-only server

2010-09-22 Thread Jonathan CLARKE
Hi Andrew, On 10/09/2010 18:42, Andrew Findlay wrote: On Fri, Sep 03, 2010 at 08:06:31PM +0200, Jonathan CLARKE wrote: I don't have any problems using the 2 syncrepl statements side-by-side on the slave. When one master goes offline, replication continues from the other, etc. I have done

Re: Searched Attr=1.1

2010-09-22 Thread Jonathan CLARKE
in the same order on all servers. I see no changes between 2.4.22 and 2.4.23 that could lead to this specific error occuring, but of course it may be more complicated than it looks. Jonathan -- == Jonathan CLARKE

Re: Configuring AD using OpenLDAP

2010-09-20 Thread Jonathan CLARKE
: This list is intended for discussion of technical issues related to the use of OpenLDAP Software. OpenLDAP software includes slapd, the libraries, utilities, tools and sample clients (from http://www.openldap.org). Jonathan -- == Jonathan CLARKE

Re: Configuring AD using OpenLDAP

2010-09-20 Thread Jonathan CLARKE
-- == Jonathan CLARKE -- Normation 44 rue Cauchy, 94110 Arcueil, France -- Telephone: +33 (0)1 83 62 26 96 -- Web:http://www.normation.com/ ==

Re: syncrepl: contextCSN less than entryCSN

2010-09-14 Thread Jonathan Clarke
... -- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization Connector (LSC) - http://lsc-project.org --

Re: Can't get TLS working.

2010-09-14 Thread Jonathan CLARKE
://www.openldap.org/lists/mm/listinfo/openldap-software The official announcement was sent out to all subscribers, see: http://www.openldap.org/lists/openldap-software/201005/msg00095.html So I'm here. This is the right place to be :) Jonathan -- == Jonathan

Re: I can't login in my system using OpenLDAP

2010-09-09 Thread Jonathan CLARKE
server). Being able to log in to a system using accounts from LDAP is another. To acheive this, I suggest you google one of many tutorials on PAM NSS LDAP. Hope this helps, Jonathan -- == Jonathan CLARKE -- Normation

Re: Defining a password attributetype

2010-09-03 Thread Jonathan CLARKE
, though, if that's what you want. Jonathan -- == Jonathan CLARKE -- Normation 44 rue Cauchy, 94110 Arcueil, France -- Telephone: +33 (0)1 83 62 26 96

Re: Can't start replication

2010-09-03 Thread Jonathan CLARKE
/philosophy/no-word-attachments.html -- == Jonathan CLARKE -- Normation 44 rue Cauchy, 94110 Arcueil, France -- Telephone: +33 (0)1 83 62 26 96

Re: Replicating from a mirrormode pair to a read-only server

2010-09-03 Thread Jonathan CLARKE
Le 03/09/2010 17:18, Andrew Findlay a écrit : On Fri, Sep 03, 2010 at 04:35:24PM +0200, Jonathan CLARKE wrote: DB_LOCK_DEADLOCK errors are only a warning: retries should occur until the operation completes. Of course, if they can be avoided, best avoid! Question: is this topology sensible

Re: syncrepl help

2010-08-26 Thread Jonathan Clarke
comment comes to mind: your setting of attrs=* in the syncrepl statements is going to prevent operational attributes not to be replicated. This is most likely not what you want. Jonathan -- -- Jonathan Clarke - jonat...@phillipoux.net

Re: I can't see my /etc/ldap/slapd.conf file after reinstall

2010-08-26 Thread Jonathan Clarke
/etc/ldap/slapd.conf? but the server is running. I believe that Debian testing has switched to the cn=config based configuration now, and you should find it stored in /etc/ldap/slapd.d/. -- -- Jonathan Clarke - jonat...@phillipoux.net

Re: OpenLDAP as a proxy for Active Directory (missing attributes)

2010-08-20 Thread Jonathan Clarke
database. This seems unnecessary, an may well cause problems. I suggest you remove it. Hope this helps, Jonathan -- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap

Re: pass-through authentication

2010-08-20 Thread Jonathan Clarke
/slapd.conf, but some distributions may use other paths (Debian uses /etc/ldap/sasl/slapd.conf). This file should contain at least pwcheck_method: saslauthd, and be readable by slapd. Hope this helps, Jonathan -- -- Jonathan Clarke - jonat

Re: Syncrepl: Reliable method to ask a server for its own URL

2010-08-20 Thread Jonathan Clarke
the CSN, and thus the serverID of the server you performed the operation on, eg: entryCSN: 20100816090343.822782Z#00#001#00 Here the serverID is 001. Jonathan -- -- Jonathan Clarke - jonat...@phillipoux.net

Re: How to check LDAP replication status?

2010-08-20 Thread Jonathan Clarke
-- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization Connector (LSC) - http://lsc-project.org --

Re: Notification of userPassword change in OpenLDAP?

2010-08-19 Thread Jonathan Clarke
://blog.normation.com/2010/07/18/java-ldap-sdk-for-syncrepl-replication-showcase/ Hope this helps, Jonathan -- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization

Re: multi / standby master: incomplete replication after downtime (?)

2010-08-18 Thread Jonathan CLARKE
re-sync of your backup instance. This should help! Jonathan -- == Jonathan CLARKE -- Normation 44 rue Cauchy, 94110 Arcueil, France -- Telephone: +33 (0)1 83 62 26 96

Re: Finiky old OpenLDAP Server: To be or not to be...

2010-07-28 Thread Jonathan Clarke
this helps, Jonathan -- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization Connector (LSC) - http://lsc-project.org --

Re: how to add a new database with slapd.d?

2010-07-27 Thread Jonathan Clarke
Le 27/07/2010 02:51, Zhang Weiwu a écrit : On 2010年07月26日 22:13, Jonathan Clarke wrote: Actually if you re-read that (means the document), you'll see that it says to use the 'olcBdbConfig' objectClass *in addition* to the olcDatabaseConfig objectClass. If you re-read my original post, you

Re: acls help

2010-07-22 Thread Jonathan Clarke
Le 21/07/2010 14:29, Juliano Rodrigues a écrit : On 21/07/10 05:33, Jonathan Clarke wrote: On 21/07/2010 02:28, Juliano Rodrigues wrote: Hello, Im using Phamm, its an php-web front-end to manage ldap postfix virtual hosting mail env. at my Fedora 11 box (openldap 2.4.15-7). Its designed

Re: acls help

2010-07-21 Thread Jonathan Clarke
=tld$ by dn=cn=admin,dc=example,dc=tld write by self read --- end --- -- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization Connector (LSC) - http://lsc

Re: OpenLDAP authenticate the username/password with MS-AD?

2010-07-19 Thread Jonathan Clarke
-- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization Connector (LSC) - http://lsc-project.org --

Re: OpenLDAP authenticate the username/password with MS-AD?

2010-07-19 Thread Jonathan Clarke
-- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization Connector (LSC) - http://lsc-project.org --

Proxy cache overlay: effect of pcachePersist parameter?

2010-07-16 Thread Jonathan Clarke
Hi, I've set up an ldap backend, with a pcache overlay to cache binds for PAM. The config is below, for info. My question concerns the pcachePersist parameter. From the man page: pcachePersist { TRUE | FALSE } Specify whether the cached queries should be saved across restarts of the caching

Re: Syncrepl - frontend database cannot be shadow

2010-07-15 Thread Jonathan Clarke
, Jonathan -- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization Connector (LSC) - http://lsc-project.org --

Re: Problem with ADS authentication - any alternatives?

2010-07-15 Thread Jonathan Clarke
a SASL bind. AD does in fact accept plain LDAP binds with a username in place of a DN. Or at least usern...@domain.tld. It's one of those weird things... -- -- Jonathan Clarke - jonat...@phillipoux.net

Re: Adding rfc schema clashes

2010-07-13 Thread Jonathan Clarke
On Tue, 13 Jul 2010 07:32:53 +, Stuart Cherrington stuart_cherring...@hotmail.co.uk wrote: Hi, Running OpenLDAP 2.4 on RHEL 5. In order for my SOlaris 10 clients to start using the OpenLDAP service I need the objectclass 'nisDomainObject' to be declared. I found this objecttype in the

Re: bdb/hdb cachesize calculation

2010-07-13 Thread Jonathan Clarke
On Tue, 13 Jul 2010 11:19:06 +0200, openldap...@stresst.net wrote: On 07/12/2010 07:40 PM, Quanah Gibson-Mount wrote: --On Monday, July 12, 2010 5:01 PM +0200 openldap...@stresst.net wrote: Attached to this message you'll find a quick and dirty bash script that should determine the cachesize

Re: Attribute type is operational

2010-07-12 Thread Jonathan Clarke
On Mon, 12 Jul 2010 08:10:56 +, Stuart Cherrington stuart_cherring...@hotmail.co.uk wrote: Hi, I'm running Openldap 2.4 on Rhel5. I've got the basics working, user accounts etc, but have tried adding some new schemas which I'm getting problems with. I followed a VERY helpful Blog at

Re: Cannot authenticate with user/password

2010-07-12 Thread Jonathan Clarke
On Mon, 12 Jul 2010 14:13:27 +0100, Nicholas Syrotiuk syrot...@manchester.ac.uk wrote: Dear OpenLDAP users, We have downloaded OpenLDAP 2.4.22 from Sunfreeware.com and installed it. We have successfully imported the LDAP data from another server. We are using the *simple* authentication

Re: Access control for multiple admins

2010-07-10 Thread Jonathan Clarke
: http://www.openldap.org/faq/data/cache/1140.html Jonathan -- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization Connector (LSC) - http://lsc-project.org --

Re: ACL to allow an attribute to be cleared, but not changed to something else?

2010-07-01 Thread Jonathan Clarke
-- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization Connector (LSC) - http://lsc-project.org --

Re: LDAP proxy with local database

2010-06-30 Thread Jonathan Clarke
-- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization Connector (LSC) - http://lsc-project.org --

Re: Adding Schema

2010-06-29 Thread Jonathan Clarke
posting an excerpt of the LDIF that fails, and your config. Jonathan -- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization Connector (LSC) - http://lsc-project.org --

Re: Interdomain authentication

2010-06-22 Thread Jonathan Clarke
://www.openldap.org/lists/openldap-technical/201006/msg00225.html Jonathan -- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization Connector (LSC) - http://lsc

Re: Simple question about LDAP and web authentication.

2010-06-22 Thread Jonathan Clarke
have the right idea? Apache does all this for you. See: http://httpd.apache.org/docs/2.1/mod/mod_authnz_ldap.html Jonathan -- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap

Re: Copying trees from one consumer to another

2010-06-22 Thread Jonathan Clarke
. That would probably work, yes. I would instead recommend doing a slapcat on one consumer, copying over the file to second consumer, slapadd, then starting that consumer. Jonathan -- -- Jonathan Clarke - jonat...@phillipoux.net

Re: Distributed directories using meta backend

2010-06-21 Thread Jonathan Clarke
. Luizmarceloo! -- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization Connector (LSC) - http://lsc-project.org --

Re: Syncrepl problems

2010-06-21 Thread Jonathan Clarke
database definition. Looks like your mailer has provided the solution: it seems there's some funny (probably invisible) character after syncrepl. Delete the line and rewrite it... Jonathan -- -- Jonathan Clarke - jonat

Re: Can't start ldap or can't create ldap database.

2010-06-21 Thread Jonathan Clarke
can now be (advantageously) set up from slapd.conf or slapd-config via the dbconfig parameter. Jonathan -- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization

Re: Bidirectional sync using openldap and active directory

2010-06-04 Thread Jonathan Clarke
, such as Ldap Synchronization Connector (LSC), which is designed for exactly this purpose - see http://lsc-project.org. Hope this helps, Jonathan -- -- Jonathan Clarke - jonat...@phillipoux.net

Re: Write through an LDAP Proxy?

2010-06-04 Thread Jonathan Clarke
) to a distant LDAP server. If you just want an LDAP proxy with multiple backends, take a look at the meta and ldap backends: http://www.openldap.org/software/man.cgi?query=slapd-meta Hope this helps, Jonathan -- -- Jonathan Clarke

Re: User restriction

2010-06-04 Thread Jonathan Clarke
keyword in ldap.conf for OpenLDAP clients. If you're configuring this on a Linux server, I think you'll find the equivalent configuration in /etc/libnss_ldap.conf or similar. Hope this helps, Jonathan -- -- Jonathan Clarke - jonat

Re: Problem with syncrepl and deletion on openldap 2.4.21

2010-05-17 Thread Jonathan Clarke
. Many thanks, Mark. -- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization Connector (LSC) - http://lsc-project.org --

Re: forgotten rootdn psw

2010-04-06 Thread Jonathan Clarke
change the rootdn's password in the configuration file or configuration backend: http://www.openldap.org/doc/admin24/slapdconfig.html#rootpw%20%3Cpassword%3E Hope this helps Jonathan -- -- Jonathan Clarke - jonat...@phillipoux.net

Re: syncrepl not working for pwdFailureTime attribute

2010-03-02 Thread Jonathan Clarke
configured. This option was clearly designed for read-only slaves. I'm not sure what the behaviour would be in a multi-master setup. You could try this anyway. Any ideas from someone else? Regards, Jonathan -- -- Jonathan Clarke - jonat

Re: OpenLDAP client configuration with CentOS 5.3

2010-03-01 Thread Jonathan Clarke
Do you think, there are some steps or configurations I am missing. Yes. To login via LDAP on your Linux box you also need to configure PAM and NSS. Plenty of information on that by googling. Jonathan -- -- Jonathan Clarke - jonat

Re: posixGroup and groupofNames

2010-02-26 Thread Jonathan Clarke
groups: one listing members, and another one, dynamically filled from the contents of the first. Regards, Jonathan -- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap

Re: a newbie trying to get the basics of syncrepl going

2010-02-25 Thread Jonathan Clarke
, Jonathan -- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization Connector (LSC) - http://lsc-project.org --

Re: a newbie trying to get the basics of syncrepl going

2010-02-25 Thread Jonathan Clarke
On 25/02/2010 13:17, Seger, Mark wrote: -Original Message- From: Jonathan Clarke [mailto:jonat...@phillipoux.net] Sent: Thursday, February 25, 2010 6:00 AM To: Seger, Mark Cc: openldap-technical@openldap.org Subject: Re: a newbie trying to get the basics of syncrepl going On 23/02

Re: a newbie trying to get the basics of syncrepl going

2010-02-25 Thread Jonathan Clarke
, initial setup *does* require changing the configuration of the provider. Jonathan -- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization Connector (LSC) - http

Re: Syncrepl for AD replication

2010-02-22 Thread Jonathan Clarke
-- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization Connector (LSC) - http://lsc-project.org --

Re: Directory layout help

2010-01-09 Thread Jonathan Clarke
dynamic groups on the fly without restarting slapd? Yes. You may need to load the overlay as a module, if you don't have it compiled in statically, then add the overlay config object under your database. Regards, Jonathan -- -- Jonathan

Re: Encoded entries on LDIF file

2010-01-04 Thread Jonathan Clarke
On 01/04/2010 07:33 PM, Diego Lima wrote: Hello all, I'm trying to import an LDIF file where some users have values that appear to be encoded on the file. The values have two : (i.e. ::) and appear like this: # entry-id: 36545 dn: uid=someuser,ou=funcionarios,ou=pessoal,o=xxx,c=xxx l::

Re: syncrepl broke, connection loss

2009-12-10 Thread Jonathan Clarke
On Thu, 10 Dec 2009 15:35:26 +0100, Peter Mogensen a...@mutex.dk wrote: Jonathan Clarke wrote: Is it possible to temporarily turn of mirroring of cn=config, so I can raise loglevels on server2 without the change being replicated to server1 and thus hanging the whole system ? Of course

Re: gidNumber attribute inside group member

2009-12-04 Thread Jonathan Clarke
of other groups the user is a member of. So, yes, all members of a group with gid 4 have the permissions granted to that group. Each user also has the permissions of his main group. Hope this helps, Jonathan -- -- Jonathan Clarke - jonat

Re: UPN in BIND request

2009-11-24 Thread Jonathan Clarke
OpenLDAP schema, and created entries that use it, then it can't work. What are you trying to achieve? Does your OpenLDAP server contain the same accounts ad your Microsoft AD? Regards, Jonathan -- -- Jonathan Clarke - jonat

Re: Queries very very slow + strange problem with indexes

2009-11-20 Thread Jonathan Clarke
set_lk_max_objects 1500 set_lk_max_locks 1500 set_lk_max_lockers 1500 -- -- Jonathan Clarke - jonat...@phillipoux.net -- Ldap Synchronization Connector (LSC) - http://lsc