[389-users] Re: Samba & 389 Directory Server Integration

2019-02-25 Thread Janet H
Thanks Mark!

I appreciate the quick reply.   I'll try the -Z option and see how it goes. 

Cheers,
___
389-users mailing list -- 389-users@lists.fedoraproject.org
To unsubscribe send an email to 389-users-le...@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org


[389-users] Re: Samba & 389 Directory Server Integration

2019-02-22 Thread Mark Reynolds


On 2/22/19 12:42 PM, Janet Houser wrote:

Hi Folks,

I'm running DS-389 (version: 1.3.7.5 ; Build: 2018.178.1311) on a Cent 
OS 7 vs. 7.6.1810) system.  I've been working
through the Samba & 389 Directory Server Integration 
 
doc and I've hit a snag.   I've obtained my SID using the "net 
getlocalsid"

command, but when I create my .ldif file (see below):


[root]# cat sambaDomainName.ldif
dn: sambaDomainName=WORKGROUP,dc=test,dc=example,dc=com   (changed for 
security)

objectclass: sambaDomain
objectclass: sambaUnixIdPool
objectclass: top
sambaDomainName: WORKGROUP
sambaSID: S-1-5-21-x--xxx   (removed for security)
uidNumber: 550
gidNumber: 550


And attempt to import it into my DS server using:


/usr/lib64/dirsrv/slapd-/ldif2ldap  "cn=Directory manager" 
password ./sambaDomainName.ldif
/usr/lib64/dirsrv/slapd-/ldif2ldap  "cn=Directory 
manager,dc=test,dc=example,dc=com" password ./sambaDomainName.ldif


I get an error:

Options:
    -Z serverID  - Server instance identifier
    -D rootdn    - Directory Manager DN
    -w passwd    - Directory Manager password
    -f file  - File containing LDAP entries to add to the server
    -P protocol  - STARTTLS, LDAPS, LDAPI, LDAP
    -h   - Display usage


I tried modifying the command in various ways:

/usr/lib64/dirsrv/slapd-/ldif2ldap  -D "cn=Directory Manager" -w 
 -f /sambaDomainName.ldif


and I've even used the /usr/sbin/ldif2ldap executable and have only 
gotten errors about the usage.   From the messages it looks like I
don't need the -Z server ID in the command since I have only one 
instance running on the server.


I'm sure I'm missing the obvious but I was hoping an experienced eye 
might have an easier time finding it.
Perhaps try "-Z instance_name" anyway.  I just tried on 
389-ds-base-1.4.0 and it works for me, and I don't think we have changed 
it in a long time.


Any suggestions would be appreciated.

Thanks,

___
389-users mailing list -- 389-users@lists.fedoraproject.org
To unsubscribe send an email to 389-users-le...@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org
___
389-users mailing list -- 389-users@lists.fedoraproject.org
To unsubscribe send an email to 389-users-le...@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org