[Fedora-directory-users] mailAlternateAddress

2006-04-28 Thread Craig White
I wanted to import the 'misc' schema from openldap so I could use mailLocalAddress and fedora-ds didn't like that since there was a collision at "2.16.840.1.113730.3.1.13" - where: # grep "2.16.840.1.113730.3.1.13" /opt/fedora-ds/slapd-srv1/config/schema/* /opt/fedora-ds/slapd-srv1/config/schema/5

Re: [Fedora-directory-users] Re: Need help syncing between Active, Directory and FDS

2006-04-28 Thread Espen A. Stefansen
On Thu, 2006-04-27 at 10:47 -0400, Daniel Shackelford wrote: > > Message: 8 > > Date: Thu, 27 Apr 2006 13:36:56 +0200 > > From: "Espen A. Stefansen" <[EMAIL PROTECTED]> > > Subject: [Fedora-directory-users] Need help syncing between Active > > Directory and FDS > > To: fedora-directory-us

Re: [Fedora-directory-users] mailAlternateAddress

2006-04-28 Thread Richard Megginson
Craig White wrote: I wanted to import the 'misc' schema from openldap so I could use mailLocalAddress and fedora-ds didn't like that since there was a collision at "2.16.840.1.113730.3.1.13" - where: # grep "2.16.840.1.113730.3.1.13" /opt/fedora-ds/slapd-srv1/config/schema/* /opt/fedora-ds/slapd

Re: [Fedora-directory-users] replicating configuration directotry (NetscapeRoot)

2006-04-28 Thread Richard Megginson
Linux Admin wrote: Folks, Is it possible to set up multi-master replication of NetscapeRoot configuration directory. I have tried and I can successfully initialize subscribers from the current configuration directory server. However initialization of replication in opposite direction fails. S

Re: [Fedora-directory-users] replicating configuration directotry (NetscapeRoot)

2006-04-28 Thread Linux Admin
Richard,Thanks, this is very good.I do not want to really disable it right now, I just want to have 2 way replication between Server 1 and Server 2, and used authenticate against server1. I would then setup in pluging authentication against both 1 and 2. Is this right way? Thank your very much for

[Fedora-directory-users] FDS to AD sync weirdness ... CN changes, unique constraints.

2006-04-28 Thread Elías Halldór Ágústsson
We are experimenting with Fedora Directory Server and trying to sync it to AD. Setting up SSL for both and initiating sync was successful. However, it seems that DN in AD is constructed from the CN, which is the full name. However, that's neigh impossible, since DN has a unique constraint, bu

Re: [Fedora-directory-users] FDS to AD sync weirdness ... CN changes, unique constraints.

2006-04-28 Thread David Boreham
I regard AD as broken by design in this regard. My question is, can this be fixed? What would be the right way to approach this problem? Yes it's broken by design. As far as I know the way to work around it is to assign unique CN's (e.g. include middle initials, something like that). -- Fedo

Re: [Fedora-directory-users] replicating configuration directotry (NetscapeRoot)

2006-04-28 Thread Richard Megginson
Linux Admin wrote: Richard, Thanks, this is very good. I do not want to really disable it right now, I think you may need to disable it on the replica in order to make replication work. I just want to have 2 way replication between Server 1 and Server 2, and used authenticate against server1. I

Re: [Fedora-directory-users] replicating configuration directotry (NetscapeRoot)

2006-04-28 Thread Linux Admin
Richard,Thanks, let me try. I am surprised there is no documentation at all on NetScape root replication.You help is very much appricatedOn 4/28/06, Richard Megginson <[EMAIL PROTECTED]> wrote: Linux Admin wrote:> Richard,> Thanks, this is very good.> I do not want to really disable it right now,I

Re: [Fedora-directory-users] FDS to AD sync weirdness ... CN changes, unique constraints.

2006-04-28 Thread George Holbert
Elias, I agree with you that AD is wrong on this. I believe that CN is a multivalued attribute (at least in FDS). So, if it's any help, you could have unique CNs that are used in the entries' DNs, and optionally have additional CNs that may not be unique. e.g., dn: cn=Kristín Jónsdóttir_00,o

[Fedora-directory-users] [OT] A call for input from directory server experts ...

2006-04-28 Thread Bryan J. Smith
I'm helping head up development of a broad set real-world objectives that covers Linux-based directory services. To this date, the early focus had only looked at OpenLDAP, prior to the FDS project's existence. Being a longer-term Netscape Directory Server administrator myself (and thank God that