[Freeipa-users] Freeipa Active Directory Sync problems

2013-08-12 Thread luis lugo
Hi,
I have the following error when I try to sync Freeipa 3.2.2 with Active 
Directory.
 reports: Update failed! Status: [-1 Total update abortedLDAP error: Can't 
contact LDAP server]
Failed to start replication

All current users sync with freeipa, but new users cannot. I have differents OU 
and I need to sync all users in my active directories. I use the following 
ipa-replica-manage switches to created the sync.
ipa-replica-manage connect --winsync 
--binddn='cn=Administrator,cn=Users,dc=domain,dc=com' --bindpw='' 
--cacert=/root/ADCA.cer --passsync='' 
--win-subtree='OU=test,OU=users,DC=domain,DC=com' windows-server-hostname
In the dirsrv logs I have the following error.
[12/Aug/2013:10:45:18 -0400] NSMMReplicationPlugin - Replication agreement for 
agmt=cn=meTo (nigua:389) could not be updated. For replication to take place, 
please enable the suffix and restart the server[12/Aug/2013:10:45:18 -0400] 
NSMMReplicationPlugin - Replication agreement for agmt=cn=meTo (nigua:389) 
could not be updated. For replication to take place, please enable the suffix 
and restart the server[12/Aug/2013:10:45:18 -0400] NSMMReplicationPlugin - 
Replication agreement for agmt=cn=me (nigua:389) could not be updated. For 
replication to take place, please enable the suffix and restart the 
server[12/Aug/2013:10:45:18 -0400] NSMMReplicationPlugin - Replication 
agreement for agmt=cn=meTo (nigua:389) could not be updated. For replication 
to take place, please enable the suffix and restart the 
server[12/Aug/2013:10:45:18 -0400] NSMMReplicationPlugin - agmt=cn=meTo 
(nigua:389): Replica has no update vector. It has never been 
initialized.[12/Aug/2013:10:45:18 -0400] - Entry 


  ___
Freeipa-users mailing list
Freeipa-users@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] Freeipa Active Directory Sync problems

2013-08-12 Thread Rich Megginson

On 08/12/2013 11:37 AM, luis lugo wrote:

Hi,

I have the following error when I try to sync Freeipa 3.2.2 with 
Active Directory.


 reports: Update failed! Status: [-1 Total update abortedLDAP error: 
Can't contact LDAP server]


Failed to start replication


All current users sync with freeipa, but new users cannot. I have 
differents OU and I need to sync all users in my active directories. I 
use the following ipa-replica-manage switches to created the sync.


ipa-replica-manage connect --winsync 
--binddn='cn=Administrator,cn=Users,dc=domain,dc=com' --bindpw='' 
--cacert=/root/ADCA.cer --passsync='' 
--win-subtree='OU=test,OU=users,DC=domain,DC=com' windows-server-hostname


In the dirsrv logs I have the following error.

[12/Aug/2013:10:45:18 -0400] NSMMReplicationPlugin - Replication 
agreement for agmt=cn=meTo (nigua:389) could not be updated. For 
replication to take place, please enable the suffix and restart the server
[12/Aug/2013:10:45:18 -0400] NSMMReplicationPlugin - Replication 
agreement for agmt=cn=meTo (nigua:389) could not be updated. For 
replication to take place, please enable the suffix and restart the server
[12/Aug/2013:10:45:18 -0400] NSMMReplicationPlugin - Replication 
agreement for agmt=cn=me (nigua:389) could not be updated. For 
replication to take place, please enable the suffix and restart the server
[12/Aug/2013:10:45:18 -0400] NSMMReplicationPlugin - Replication 
agreement for agmt=cn=meTo (nigua:389) could not be updated. For 
replication to take place, please enable the suffix and restart the server
[12/Aug/2013:10:45:18 -0400] NSMMReplicationPlugin - agmt=cn=meTo 
(nigua:389): Replica has no update vector. It has never been initialized.

[12/Aug/2013:10:45:18 -0400] - Entry


This is truncated.  Please provide more.







___
Freeipa-users mailing list
Freeipa-users@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-users


___
Freeipa-users mailing list
Freeipa-users@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-users