[389-users] Re: How to disable attribute encryption

2020-08-18 Thread William Brown
> > > These entries are generated at server startup (there is no way to prevent > that). So stop the server and edit the dse.ldif and remove these entries, > then start the server up and those errors will go away - well until you renew > the server cert again :-) It's worth pointing out that

[389-users] Re: How to disable attribute encryption

2020-08-18 Thread Mark Reynolds
On 8/18/20 9:24 AM, Jan Tomasek wrote: On 8/18/20 3:21 PM, Mark Reynolds wrote: Looks like you are all good then... Yes, but... is it possible to prevent creating "encrypted attribute keys" and seeing in logs message:  ERR - attrcrypt_cipher_init - Symmetric key failed to unwrap with the

[389-users] Re: How to disable attribute encryption

2020-08-18 Thread Jan Tomasek
On 8/18/20 3:21 PM, Mark Reynolds wrote: Looks like you are all good then... Yes, but... is it possible to prevent creating "encrypted attribute keys" and seeing in logs message: ERR - attrcrypt_cipher_init - Symmetric key failed to unwrap with the private key; Cert might have been renewed

[389-users] Re: How to disable attribute encryption

2020-08-18 Thread Mark Reynolds
On 8/18/20 9:13 AM, Jan Tomasek wrote: Hi Mark, On 8/18/20 2:56 PM, Mark Reynolds wrote: The best option would be config option to disable attribute encryption for all databases but I failed to find if it is possible. You have to delete each attribute that was configured for attribute encry

[389-users] Re: How to disable attribute encryption

2020-08-18 Thread Jan Tomasek
Hi Mark, On 8/18/20 2:56 PM, Mark Reynolds wrote: The best option would be config option to disable attribute encryption for all databases but I failed to find if it is possible. You have to delete each attribute that was configured for attribute encryption (like what you did above, but you c

[389-users] Re: How to disable attribute encryption

2020-08-18 Thread Mark Reynolds
On 8/18/20 8:47 AM, Jan Tomasek wrote: Hello, is it possible to disable attribute encryption in 389 DS? I'm running 1.4.0.21 @ Debian Buster. After replacing TLS certificate I'm receiving errors: [18/Aug/2020:10:25:16.099482453 +0200] - ERR - attrcrypt_unwrap_key - Failed to unwrap key for