[389-users] subtree level password policy enabled with a few user level pwdPolicysubentry exceptions

2018-03-21 Thread albert . luo
Hi, Fine-grained subtree password policy enabled for ou=people,dc=example,dc=com. The same password policy is applied to all users under ou=people,dc=example,dc=com. I need to apply a different password policy to a few users, what is the best way to do it? The following is my failed attempts.

[389-users] Account lockout error code/message differences for correct and incorrect password

2017-07-28 Thread albert . luo
Hi, I am doing some experiements with account lockout password policy. The account is locked out after many wrong password tries. Then If bind with correct password, the result is # if bind with wrong password, the result is # So attacker can still continue to try/guess different passwords

[389-users] notes=A for filter with undefined attribute

2017-06-09 Thread albert . luo
Hi, Xerox printer's LDAP connectivity's default search filter is (|(uid=someone)(samaccountname=someone)). samaccountname is not a defined attribute. This search filter will result notes=A, causing performance issue. Is there a way to avoid searching samaccountname=someone, since

[389-users] v1.2 and v1.3 differences in return results for lookthroughlimit exceeding search

2017-06-09 Thread albert . luo
Hi, In the following example, consumer replica v1.3 return err=11 with no entries. v1.2 return err=4, with the first 20 entries which is the size limit. Is this difference a change in the implementation or a configuration difference I am missing? The look through limit is the default 5000.

[389-users] Re: problems after upgrading to 1.3.5.10 B2017.093.2133

2017-05-02 Thread albert . luo
Hi, Mark, I couldn't reproduce the problem. The other two servers upgraded didn't have this problem. There are two instance of slapd on this server. Only one instance have this problem. /etc/sysconfig/dirsrv-ldap12.0 diff /etc/sysconfig/dirsrv-ldap12.0 /etc/sysconfig/dirsrv-ldap12 15c15 <

[389-users] problems after upgrading to 1.3.5.10 B2017.093.2133

2017-05-02 Thread albert . luo
I have the following problems after upgrading from: 389-Directory/1.3.5.10 B2017.047.2239 to: 389-Directory/1.3.5.10 B2017.093.2133 slapd-ldap12 is one of the directory server instance. 1. a new directory slapd-ldap12.0 under /etc/dirsrv/ drwxrwx---. 4 dirsrv dirsrv 235 May 2 10:46