Re: daemon: bind(6) failed errno=98 (Address,already in use)

2012-02-22 Thread stefano
thanks, i successfully changed the psw with slappasswd but the problem is still. the difficult isn't the password. this is the sequence: - succesfully started the first time slapd server - one time started, the reboot fails - error in syslog is daemon: bind(8) failed errno=98 (Address already i

Re: LDAP guide, manuals

2012-02-22 Thread Pieter Baele
On Wed, Feb 22, 2012 at 16:30, NetNinja <2bitni...@gmail.com> wrote: > Good question by the way. > I think that if your installing on Linux I would look at the distros > documention. For example Red Hat & CentOS have step by step setup > guides. > For RHEL6 and derivatives I would recommend this o

Re:daemon: bind(6) failed errno=98 (Address,already in use)

2012-02-22 Thread huwenfeng_maillist
Hi stefona: i think you should enter the passwd you setup in slapd.conf and if you want to change your Admin passwd, you should use the command `slappasswd` instead of `ldappasswd`. read `man` for details. At 2012-02-22 17:00:10,stefano wrote: Hi folks, i don't understand a

Re: Controlling access based on group membership

2012-02-22 Thread Nick Milas
On 21/2/2012 3:18 μμ, Nick Milas wrote: What you want to do may be achieveable with sets (http://www.openldap.org/faq/data/cache/1133.html). I'll read about sets, thanks. As I see in the documentation, what we want to accomplish could be done using sets as follows: access to by

2.4.29 memberof: entry_encode: Assertion `i == a->a_numvals' failed.

2012-02-22 Thread Colin Hudler
Greetings, Haven't used OpenLDAP since 2.1; I see it has come a long way. I have a few hundred static groups and am using the memberOf overlay. There's a hundred thousand or so people entries and thousands of memberships. The overlay is configured thusly: # {0}memberof, {1}bdb, config dn: ol

Re: LDAP guide, manuals

2012-02-22 Thread NetNinja
Good question by the way. I think that if your installing on Linux I would look at the distros documention. For example Red Hat & CentOS have step by step setup guides. On Tue, Feb 21, 2012 at 8:24 AM, Liam Gretton wrote: > On 20/02/2012 11:52, Emmanuel Lécharny wrote: > >> Mastering OpenLDAP. Re

Re: DEL don't get synced

2012-02-22 Thread Marco Pizzoli
Hi On Wed, Feb 22, 2012 at 3:43 PM, Francis Swasey wrote: > > > On 2/22/12 5:15 AM, Howard Chu wrote: > > Eh. I would look at the RE24 CHANGES file and see if any of it is likely > to affect you. If > > so, then feel free to try it. If not, then no rush. I'm still chasing > down ITS#7170 in the >

Re: DEL don't get synced

2012-02-22 Thread Francis Swasey
On 2/22/12 5:15 AM, Howard Chu wrote: > Eh. I would look at the RE24 CHANGES file and see if any of it is likely to > affect you. If > so, then feel free to try it. If not, then no rush. I'm still chasing down > ITS#7170 in the > meantime; expect 2.4.30 to go when 7170 is resolved. As a non-d

Re: request for brief documentation

2012-02-22 Thread NetNinja
Hello, I know I'm a little late but I just did the same thisng and I used this guide. http://www.ibm.com/developerworks/linux/library/l-openldap/ There are also some you-tub videos that install and configure openldap on CentOS. If you use both of these, you should have not issues. If you still have

TIME_WAIT

2012-02-22 Thread arun.sasi1
Hello Team, I have a problem with my LDAP server. There are many TIME_WAIT connections (more than 5000). MinimumConnectionsInPool=1 MaximumConnectionsInpool=20 Thanks & Regards, Arun Sasi V -

Re: daemon: bind(6) failed errno=98 (Address,already in use)

2012-02-22 Thread stefano
any idea? On 02/22/2012 11:16 AM, stefano wrote: thank you! there was a process: openldap 1797 0.0 0.3 23752 4004 ?Ssl 11:48 0:00 /usr/sbin/slapd -h ldap:/// ldapi:/// -g openldap -u openldap -f /etc/ldap/slapd.conf after kill it i restarted without problems. i increased th

Re: Howto implement RBAC with OU's and posixGroups

2012-02-22 Thread Fred van Zwieten
*Hi Milan, I know RedHat's IPA server can do this, but that based on 389 Directory Server. Also, have a look here: http://www.mail-archive.com/sssd-devel@lists.fedorahosted.org/msg06902.html This guy succeeded, but with a combi of posixGroup and groupOfMembers. I'll try to see if I get you sugges

Re: DEL don't get synced

2012-02-22 Thread Michael Ströder
Howard Chu wrote: Michael Ströder wrote: Howard Chu wrote: Marc Patermann wrote: There are reverted commits in git (ITS#7162). Should a build again with current git status? Yes, build with current git. Should we take this as a call to have a test round? Eh. I would look at the RE24 CHANG

Re: Howto implement RBAC with OU's and posixGroups

2012-02-22 Thread Clément OUDOT
Le 22 février 2012 12:00, Fred van Zwieten a écrit : > Howard, > > So, what is the right way? Could you give me an example how to set this up > or give me a reference to a good source on this? Here is an example on how create an RBAC model in OpenLDAP, to be used by a SSO software: http://lemonl

OpenLDAP training Europe

2012-02-22 Thread Pieter Baele
Any recommendations for OpenLDAP traing going further then the basics? location: Belgium, France, Germany or UK Sincerely, PieterB

Re: Howto implement RBAC with OU's and posixGroups

2012-02-22 Thread Fred van Zwieten
Howard, So, what is the right way? Could you give me an example how to set this up or give me a reference to a good source on this? Thank you! Greetz, Fred 2012/2/22 Howard Chu > Fred van Zwieten wrote: > >> Hi llg, >> >> I fail to see how this solves my RBAC ne

Re: Howto implement RBAC with OU's and posixGroups

2012-02-22 Thread Howard Chu
Fred van Zwieten wrote: Hi llg, I fail to see how this solves my RBAC need. Let me give an example: Say, personA is in ou DeptA. Then, ideally personA would based on being in this ou, become member of group webserver No, when I move personA to ou DeptB, this would mean that, on the next login

Re: daemon: bind(6) failed errno=98 (Address,already in use)

2012-02-22 Thread stefano
thank you! there was a process: openldap 1797 0.0 0.3 23752 4004 ?Ssl 11:48 0:00 /usr/sbin/slapd -h ldap:/// ldapi:/// -g openldap -u openldap -f /etc/ldap/slapd.conf after kill it i restarted without problems. i increased the loglevel to "4" and tried another time to test th

Re: DEL don't get synced

2012-02-22 Thread Howard Chu
Michael Ströder wrote: Howard Chu wrote: Marc Patermann wrote: There are reverted commits in git (ITS#7162). Should a build again with current git status? Yes, build with current git. Should we take this as a call to have a test round? Eh. I would look at the RE24 CHANGES file and see if

Re: Howto implement RBAC with OU's and posixGroups

2012-02-22 Thread Fred van Zwieten
Hi llg, I fail to see how this solves my RBAC need. Let me give an example: Say, personA is in ou DeptA. Then, ideally personA would based on being in this ou, become member of group webserver No, when I move personA to ou DeptB, this would mean that, on the next login, it looses it's membershi

Re: DEL don't get synced

2012-02-22 Thread Michael Ströder
Howard Chu wrote: Marc Patermann wrote: There are reverted commits in git (ITS#7162). Should a build again with current git status? Yes, build with current git. Should we take this as a call to have a test round? Ciao, Michael.

Re: Howto implement RBAC with OU's and posixGroups

2012-02-22 Thread llg
Hi, persons should use inetOrgPerson and PosixAccount schemas : gidNumber gives primary group. Then define specific branch ou=posix based on PosixGroup schema and add the uid of the person in memberUid multiple values attribute to specify secondary gid. Regards Llg Le 22/02/2012 10:22,

Re: daemon: bind(6) failed errno=98 (Address,already in use)

2012-02-22 Thread Marc Patermann
stefano, stefano schrieb (22.02.2012 10:00 Uhr): i tryied to comment everything in ldap.conf and restart the ldap server but is failed. You can forget about all the ldap.conf things before you did not solved this: checking in syslog the error is daemon: bind(6) failed errno=98 (Address,alr

Howto implement RBAC with OU's and posixGroups

2012-02-22 Thread Fred van Zwieten
Hi all, warning: openldap newbie.. is it possible to have a person put into an OU and, because of this, will become member of some group in such a way that this group shows up in linux using "id". This to implement some form of RBAC. I found GroupofMembers, but that has nothing to do with OU's. A

daemon: bind(6) failed errno=98 (Address,already in use)

2012-02-22 Thread stefano
Hi folks, i don't understand a little problem with mi ldap server I installed and configuring my ldap server. after configuring slapd.conf, restarting the server was ok. then i prepared the client with ldap.conf # # LDAP Defaults # # See ldap.conf(5) for details # This file should be world r