Re: [Fedora-directory-users] Re: Error viewing Encryption settings tab

2007-04-10 Thread Rich Megginson
Philip Kime wrote: Hmm - I restarted the Admin server and this error went away. Now there is no problem with that tab. I do nightly restarts of slapd (to guard against memory leaks, even though the NSS leak was fixed some time ago) but I've never restarted the admin server. Perhaps I should resta

Re: [Fedora-directory-users] Non-indexed searches on objectclass?

2007-04-10 Thread Pete Rowley
Philip Kime wrote: When I look at the logconv output for some of my FDS servers, I see that the common factor on all listed unindexed searches is using the "objectclass" attribute. Is it worth indexing this? It is already indexed for equality. The fact that an attribute is indexed does not me

Re: [Fedora-directory-users] Non-indexed searches on objectclass?

2007-04-10 Thread George Holbert
objectclass is indexed by default, so you shouldn't have to add it. Maybe your searches are exceeding the All IDs threshold. Take a look at: http://www.redhat.com/docs/manuals/dir-server/ag/7.1/index1.html#1110655 Philip Kime wrote: When I look at the logconv output for some of my FDS servers, I

[Fedora-directory-users] Non-indexed searches on objectclass?

2007-04-10 Thread Philip Kime
When I look at the logconv output for some of my FDS servers, I see that the common factor on all listed unindexed searches is using the "objectclass" attribute. Is it worth indexing this? PK -- Philip Kime NOPS Systems Architect 310 401 0407 -- Fedora-directory-users mailing list Fedora-dire

Re: [Fedora-directory-users] ldap super users

2007-04-10 Thread Pete Rowley
Rick Mattier wrote: Hi In my setup, I currently have three branches ou=Engineering,dc=mydomain,dc=com, ou=Sales,dc=mydomain,dc=com, ou=People,dc=mydomain,dc=com. I would like to know if there is a primary group that I can create that houses administrators that can access all off these ou’s

[Fedora-directory-users] ldap super users

2007-04-10 Thread Rick Mattier
Hi In my setup, I currently have three branches ou=Engineering,dc=mydomain,dc=com, ou=Sales,dc=mydomain,dc=com, ou=People,dc=mydomain,dc=com. I would like to know if there is a primary group that I can create that houses administrators that can access all off these ou's without being added to

[Fedora-directory-users] Re: Error viewing Encryption settings tab

2007-04-10 Thread Philip Kime
Hmm - I restarted the Admin server and this error went away. Now there is no problem with that tab. I do nightly restarts of slapd (to guard against memory leaks, even though the NSS leak was fixed some time ago) but I've never restarted the admin server. Perhaps I should restart both ... PK -- F

RE: [Fedora-directory-users] TLS issues during screen lock

2007-04-10 Thread Brian Zuromski
Rich, No, I'm not using client based auth with this setup. I am sharing out the server certificate to the network client. Date: Tue, 10 Apr 2007 08:35:00 -0700 From: Rich Megginson <[EMAIL PROTECTED]> Subject: Re: [Fedora-directory-users] TLS issues during screen lock To: "General discus

Re: [Fedora-directory-users] Problem running console on Windows

2007-04-10 Thread Glenn
Yes. In this case, it seems Windows doesn't use symbolic links the way Linux does. I fixed it by replacing all linked files with copies of the files they were linked to. Thanks for your reply. -G. -- Original Message --- From: Patrick Morris <[EMAIL PROTECTED]> To: "General

Re: [Fedora-directory-users] Replica has no update vector . . . .

2007-04-10 Thread Glenn
This problem is due to the formatting of data in the Fedora Directory that does not meet the requirements for Active Directory. The last time I set up Windows Sync, I avoided this by importing the data directly into AD from an ldif file. Then I populated the Fedora Directory by initiating a fu

Re: [Fedora-directory-users] TLS issues during screen lock

2007-04-10 Thread Rich Megginson
Brian Zuromski wrote: Hello, I'm having an issue with TLS certificates. On the client side, it seems that when I have TLS enabled it works fine. When I screen lock the computer, I have to disable TLS to get back in. Has anyone else experienced this before? Are you using client cer

Re: [Fedora-directory-users] ssl certificate problem

2007-04-10 Thread Rich Megginson
Paolo Ercolani wrote: Hi. I'm new to this list and it's a week i'm really fighting with directory server. I followed some howtos, i downloaded a lot of documents but i can't get out of trouble. I need to make login from my linux boxes on ldap directory server. If i try to use my test user in cl

[Fedora-directory-users] TLS issues during screen lock

2007-04-10 Thread Brian Zuromski
Hello, I'm having an issue with TLS certificates. On the client side, it seems that when I have TLS enabled it works fine. When I screen lock the computer, I have to disable TLS to get back in. Has anyone else experienced this before? Thanks, -- -- Brian Z. -- Fedora-directory-u

Re: [Fedora-directory-users] Errors in error log on startup

2007-04-10 Thread Rich Megginson
Philip Kime wrote: Starts up ok (although last week, twice it says it started but the server wasn't talking LDAP at all and the load-balancer ignored it for a day) ... are these anything to worry about? Could it be that this server was configured for SSL, then SSL was turned off. [09/Apr/2007

Re: [Fedora-directory-users] Error viewing Encryption settings tab

2007-04-10 Thread Rich Megginson
Philip Kime wrote: When I click the Encryption tab in the Configuration page for one of our FDS 1.0.2 servers, I get this popup error: org.mozilla.jss.ssl.SSLSocketException: Unable to connect (-5981) Connection refused by peer And the cipher/cert section is missing on the page after I click

Re: [Fedora-directory-users] db_verify

2007-04-10 Thread Ville Silventoinen
Hi Noriko, sorry it took so long to reply, I've been busy with other work. On Fri, 30 Mar 2007, Noriko Hosoi wrote: Ville Silventoinen wrote: I asked my manager but he doesn't think it's a good idea for security reasons. The problem is that the data is our NIS mail.aliases and passwd, and we

[Fedora-directory-users] ssl certificate problem

2007-04-10 Thread Paolo Ercolani
Hi. I'm new to this list and it's a week i'm really fighting with directory server. I followed some howtos, i downloaded a lot of documents but i can't get out of trouble. I need to make login from my linux boxes on ldap directory server. If i try to use my test user in clear mode i can do that.