[389-users] MMR Dead-Lock

2015-08-06 Thread Joel Levin
Hi List: We have a multi-master set-up: 1 Primary Master, 1 Cold Master, 3 Consumers. All usually humming well - however today, there were a number of deadlocks - like below - 2 of which brought the 1 Primary Master (example below from 'error' logs resulted in master going offline). Any ideas

Re: [389-users] MMR Dead-Lock

2015-08-06 Thread Joel Levin
The 389 plug-in was enabled yesterday - we think the deadlock it is similar to case below: http://comments.gmane.org/gmane.linux.redhat.fedora.directory.user/15775 DNA plug-in has now been disabled - we are monitoring and will update the list. On Thu, Aug 6, 2015 at 3:23 PM, Joel Levin

[389-users] File Permissions

2015-08-06 Thread Paul Whitney
I have a several openldap clients.  Certs are installed in /etc/openldap/cacerts.  I am using server certificates to to establish an SSL connection with the LDAP server.  Using PAM LDAP to authenticate users. I would like to test hardening these clients. 1.  What are the absolute minimum