Re: [Fedora-directory-users] posixgroup name lookups

2008-11-19 Thread George Holbert
John A. Sullivan III wrote: On Wed, 2008-11-19 at 12:21 -0800, George Holbert wrote: John A. Sullivan III wrote: John A. Sullivan III wrote: Hello, all. We're trying to move all our user access control to DS including file system rights management and thus group manageme

Re: [Fedora-directory-users] posixgroup name lookups

2008-11-19 Thread John A. Sullivan III
On Wed, 2008-11-19 at 12:21 -0800, George Holbert wrote: > John A. Sullivan III wrote: > >> John A. Sullivan III wrote: > >> > >>> Hello, all. We're trying to move all our user access control to DS > >>> including file system rights management and thus group management. > >>> We've hit a few

Re: [Fedora-directory-users] posixgroup name lookups

2008-11-19 Thread George Holbert
John A. Sullivan III wrote: John A. Sullivan III wrote: Hello, all. We're trying to move all our user access control to DS including file system rights management and thus group management. We've hit a few problems and would like to share how we've gotten around them both for documentation

Re: [Fedora-directory-users] posixgroup name lookups

2008-11-19 Thread John A. Sullivan III
> John A. Sullivan III wrote: > > Hello, all. We're trying to move all our user access control to DS > > including file system rights management and thus group management. > > We've hit a few problems and would like to share how we've gotten around > > them both for documentation and so someone wi

Re: [Fedora-directory-users] posixgroup name lookups

2008-11-19 Thread George Holbert
-sh-3.2$ id -gn id: cannot find name for group ID 2000 2000 ... Instead, we added posixgroup as an objectclass to the users. Is this a reasonable way to go about this? Not really... id is asking your name service "what is the group name for gid 2000". You have no groups defined in your name

[Fedora-directory-users] posixgroup name lookups

2008-11-19 Thread John A. Sullivan III
Hello, all. We're trying to move all our user access control to DS including file system rights management and thus group management. We've hit a few problems and would like to share how we've gotten around them both for documentation and so someone with more experience can tell us if we are going

Re: [Fedora-directory-users] Replicate o=NetscapeRoot database

2008-11-19 Thread Hugo Etievant
John Dickinson a écrit : On 19 Nov 2008, at 15:14, Hugo Etievant wrote: hello, I have put together some notes here: http://jadickinson.co.uk/test/howto/replicating-netscaperoot-on-fedora-ds/ they could do with testing - please let me know if you find any problems. With your procedu

Re: [Fedora-directory-users] Replicate o=NetscapeRoot database

2008-11-19 Thread John Dickinson
On 19 Nov 2008, at 15:14, Hugo Etievant wrote: hello, I have put together some notes here: http://jadickinson.co.uk/test/howto/replicating-netscaperoot-on-fedora-ds/ they could do with testing - please let me know if you find any problems. With your procedure, initialization of consum

Re: [Fedora-directory-users] Replicate o=NetscapeRoot database

2008-11-19 Thread Rich Megginson
Hugo Etievant wrote: hello, I have put together some notes here: http://jadickinson.co.uk/test/howto/replicating-netscaperoot-on-fedora-ds/ they could do with testing - please let me know if you find any problems. With your procedure, initialization of consumer fails. I apply your LD

Re: [Fedora-directory-users] Replicate o=NetscapeRoot database

2008-11-19 Thread Hugo Etievant
hello, I have put together some notes here: http://jadickinson.co.uk/test/howto/replicating-netscaperoot-on-fedora-ds/ they could do with testing - please let me know if you find any problems. With your procedure, initialization of consumer fails. I apply your LDAP script but on server1

Re: [Fedora-directory-users] Re: Windows sync: how do you populate the posixUser attributes?

2008-11-19 Thread Rich Megginson
Kenneth Holter wrote: Has anyone on the list set up such as scheme for adding posix attributes to users synced from AD, and would like to comment on this approach? I'm thinking that maybe running a cron job (for example a couple of times an hour) that searches for newly added users, then us

Re: [Fedora-directory-users] Replicate o=NetscapeRoot database

2008-11-19 Thread Hugo Etievant
John Dickinson a écrit : I have put together some notes here: http://jadickinson.co.uk/test/howto/replicating-netscaperoot-on-fedora-ds/ they could do with testing - please let me know if you find any problems. thanks, but that does not work too the script /usr/sbin/register-ds-admin.pl

Re: [Fedora-directory-users] Replicate o=NetscapeRoot database

2008-11-19 Thread John Dickinson
On 19 Nov 2008, at 09:09, Hugo Etievant wrote: hello, - I have installed 2 Directory servers, the second (DS2) is registered on the first (DS1). - I have installed multi master replication between the both (DS1 and DS2) for user data on userRoot database. Here, that is working. - Finally

Re: [Fedora-directory-users] Re: Windows sync: how do you populate the posixUser attributes?

2008-11-19 Thread Kenneth Holter
Has anyone on the list set up such as scheme for adding posix attributes to users synced from AD, and would like to comment on this approach? I'm thinking that maybe running a cron job (for example a couple of times an hour) that searches for newly added users, then using "ldapmodify" to add the r

[Fedora-directory-users] Replicate o=NetscapeRoot database

2008-11-19 Thread Hugo Etievant
hello, - I have installed 2 Directory servers, the second (DS2) is registered on the first (DS1). - I have installed multi master replication between the both (DS1 and DS2) for user data on userRoot database. Here, that is working. - Finally, I try to configure multi master replication for o