I am the only one who has access to these systems, so unless I did it in my sleep.. :-)

~J

On 12/19/14 12:14 AM, Ludwig Krispenz wrote:

On 12/18/2014 08:16 PM, Rich Megginson wrote:
On 12/18/2014 11:59 AM, Janelle wrote:
I am looking at the 2 entries in dse.ldif - and indeed they are different. If I replace the one in question with the one from the working system, it works again.

I'm assuming by "entry" you are referring to nsslapd-rootpw in cn=config.


I did find - replica was created on Dec 11 at noon -- and the dse.ldif file CHANGED a day later?!?

The dse.ldif file changes all the time - unique id generator state, csn generator state, replication state, etc. etc.

BUT - nsslapd-rootpw SHOULD NOT CHANGE
no, except someone follows the steps to change it.
Janelle, could it be that someone else was working on that server, not knowing the root pw and changing it in dse.ldif ?

--
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go To http://freeipa.org for more info on the project

Reply via email to