2.4.18 refint getting "no such attribute" in bdb_modify_internal with removal; works with rename

2009-10-08 Thread Andreas Hasenack
[apologies if you get this twice: I originally sent this from the wrong non-subscribed address] Hi, I'm using the refint overlay with a few attributes, but I can't get it to work with krbPwdPolicyReference from MIT kerberos 1.7. I get the error from the subject when deleting the entry this attrib

Re: Fast massive ldif load

2009-10-08 Thread Emmanuel Lécharny
Quanah Gibson-Mount wrote: --On October 7, 2009 11:09:18 PM +0200 Emmanuel Lecharny wrote: Quanah Gibson-Mount wrote: --On October 7, 2009 3:32:51 PM -0400 Aaron Richton wrote: On Wed, 7 Oct 2009, iz1ksw iz1ksw wrote: What is the fastest way (in terms of openldap settings) to perfo

Re: OpenLdap performance and Berkeley DB version

2009-10-08 Thread Quanah Gibson-Mount
--On October 8, 2009 8:20:39 PM +0400 Evgeniy wrote: Hello. What has better performance , when using with OpenLdap 2.4.19 - Berkeley DB 4.5.20 or 4.7.25 ? Small DB (5-20 Mb), but many parallel read/write requests to it. Probably BDB 4.8. --Quanah -- Quanah Gibson-Mount P

Re: Fast massive ldif load

2009-10-08 Thread Quanah Gibson-Mount
--On October 7, 2009 11:09:18 PM +0200 Emmanuel Lecharny wrote: Quanah Gibson-Mount wrote: --On October 7, 2009 3:32:51 PM -0400 Aaron Richton wrote: On Wed, 7 Oct 2009, iz1ksw iz1ksw wrote: What is the fastest way (in terms of openldap settings) to perform a massive load (~200MB ld

RE: openldap service stop cause database corruption

2009-10-08 Thread Antonini Gabriele
> I don't know about CentOS, but if it's anything like Redhat, the > system provided init scripts are very hostile to processes that don't > shut down fast enough. > > The killproc() function will send a TERM, wait 100k microseconds, then > send a KILL. > > You're running a large process on a low

Re: syncrepl and the memberof overlay

2009-10-08 Thread Michael Smith
On Wed, 7 Oct 2009, Dieter Kluenter wrote: > Michael Smith writes: > > > Has anyone tried using the memberof overlay with syncrepl? > There have been made many fixes since 2.4.12, in particular to > syncrepl. I would suggest to update to the last available version > (which is as of today 2.4.18

OpenLdap performance and Berkeley DB version

2009-10-08 Thread Evgeniy
Hello. What has better performance , when using with OpenLdap 2.4.19 - Berkeley DB 4.5.20 or 4.7.25 ? Small DB (5-20 Mb), but many parallel read/write requests to it. -- ---__--- Evgeniy

ch_malloc of 0 bytes failed

2009-10-08 Thread Edgar Fuß
This afternoon, one of our slapds died with "ch_malloc of 0 bytes failed". Is there any known issue with 2.4.15 that can lead to this behaviour? In case it matters, the server in question operates as a syncrepl consumer with updateref and the chain overlay. The last messages (all within the same s

RE: openldap service stop cause database corruption

2009-10-08 Thread Brandon Hume
On Thu, 2009-10-08 at 15:07 +0200, Antonini Gabriele wrote: > I tried modifying stop script adding 30 seconds sleep after killproc but the > problem remains. Here is the stop script: That wouldn't accomplish anything... the damage occurs INSIDE killproc. Did you time how long it takes your slapd

Re: problem with security ppolicy

2009-10-08 Thread Evgeniy
Its solving problem with security policy. Thank you. Please, update documentation for security policy in OpenLdap. Now: "This attribute controls the action taken when an account has had more consecutive failed bind attempts with invalid passwords than is defined by pwdMaxFailur

Re: problem with security ppolicy

2009-10-08 Thread Clément OUDOT
Le 7 octobre 2009 19:51, Evgeniy a écrit : > > On releases up to 2.4.16  (2.3.x  too)  works  next config : > > overlay ppolicy > ppolicy_default "cn=CompanyAccountPolicy,ou=CompanyPolicies,dc=Company,dc=com" > ppolicy_hash_cleartext > ppolicy_use_lockout > >   On 2.4.18,  2.4.19  its don't  work.

Re: syncrepl loosing connection

2009-10-08 Thread Peter Mogensen
Quanah Gibson-Mount wrote: I can find a few mentions of this problem with older versions of slapd, but nothing saying that I shouldn't use idletimeout with syncrepl on 2.4.17. Have I missed something? From 2.4.18: Fixed slapd incorrectly applying writetimeout when not set (ITS#6220) mo

Re: Fast massive ldif load

2009-10-08 Thread Emmanuel Lecharny
Quanah Gibson-Mount wrote: --On October 7, 2009 3:32:51 PM -0400 Aaron Richton wrote: On Wed, 7 Oct 2009, iz1ksw iz1ksw wrote: What is the fastest way (in terms of openldap settings) to perform a massive load (~200MB ldif file) of data into openldap directory? Try "slapadd -q" (read sl