[389-users] Re: Compact problem solved with nsslapd-db-locks: 1500000, should i keep it?

2021-04-26 Thread murmansk
Thanks for your answer Mark!! We'll configure the same value on our second server. ___ 389-users mailing list -- 389-users@lists.fedoraproject.org To unsubscribe send an email to 389-users-le...@lists.fedoraproject.org Fedora Code of Conduct: https://do

[389-users] Compact problem solved with nsslapd-db-locks: 1500000, should i keep it?

2021-04-26 Thread murmansk
We had a problem today, one of our two 389 DS servers hanged showing the errors: ERR - libdb - BDB2055 Lock table is out of available lock entries ERR - NSMMReplicationPlugin - changelog program - _cl5CompactDBs - Failed to compact db5f7bb9-ab0611e6-9bc8987f-40ec05bf; db error - 12 Cannot allocat

[389-users] Max number of users in a group?

2020-10-22 Thread murmansk
We have a two machine 389DS multimaster cluster holding about 850.000 users. It's been working great for over three years now. But we are creating some big groups, that will have about 150.000 users in them. I've read in the list some posts about groups larger than that. But I would like to kno

[389-users] PBKDF2_SHA256 not available as Password Storage Scheme

2018-05-09 Thread murmansk
I'm trying to change our Password Storage Scheme to PBKDF2_SHA256 using the 389 Console, but the scheme is not present in the list. When using ldapsearch in "cn=Password Storage Schemes,cn=plugins,cn=config" this is the result: dn: cn=Password Storage Schemes,cn=plugins,cn=config dn: cn=AES,cn=P

[389-users] 389 DS with two certificates

2016-11-12 Thread murmansk
I want to use two servers with multi-master replication behind a common DNS name (let's call it ldap.foo.net) with two IPs, balancing with round-robin. I plan to use only LDAPS. I have one server installed, with a certificate issued to his own FQDN. I can use ldapsearch over TLS with the -ZZZ p