Re: Chaining stops working after slapd restart

2013-04-29 Thread Ivan Nejgebauer
Quanah Gibson-Mount wrote: --On Monday, April 29, 2013 6:56 PM + jeevan kc wrote: No, I'm fully using cn=config on Openldap 2.4.30 . I'm working on the chain overlay for the past couple of weeks and when now I finally was able to get it working, I found I could modify the slaves until I re

Re: Modern Password Hashes in Openldap?

2013-04-29 Thread Michael Ströder
Quanah Gibson-Mount wrote: > --On Monday, April 29, 2013 3:28 PM -0700 Chris Hiestand > wrote: > >> Since SSHA-1 is weak these days I'd like to switch to PBKDF2, Bcrypt or >> the like with key stretching. Since Openldap does not support relatively >> strong hashes, do you guys use SASL to store s

Re: Modern Password Hashes in Openldap?

2013-04-29 Thread Quanah Gibson-Mount
--On Monday, April 29, 2013 3:28 PM -0700 Chris Hiestand wrote: Since SSHA-1 is weak these days I'd like to switch to PBKDF2, Bcrypt or the like with key stretching. Since Openldap does not support relatively strong hashes, do you guys use SASL to store stronger hashes? If so, what kind of bac

Modern Password Hashes in Openldap?

2013-04-29 Thread Chris Hiestand
Since SSHA-1 is weak these days I'd like to switch to PBKDF2, Bcrypt or the like with key stretching. Since Openldap does not support relatively strong hashes, do you guys use SASL to store stronger hashes? If so, what kind of backend are you using to store hashes? Background: OclHashcat can ge

RE: Chaining stops working after slapd restart

2013-04-29 Thread Quanah Gibson-Mount
--On Monday, April 29, 2013 6:56 PM + jeevan kc wrote: No, I'm fully using cn=config on Openldap 2.4.30 . I'm working on the chain overlay for the past couple of weeks and when now I finally was able to get it working, I found I could modify the slaves until I restart the server. After I

Re: Chaining stops working after slapd restart

2013-04-29 Thread Quanah Gibson-Mount
--On Monday, April 29, 2013 6:06 PM + jeevan kc wrote: Hi, I am trying to setup a chain overlay to allow writes to a read-only slave to be chained up to the master. dn: olcOverlay={0}chain,olcDatabase={-1}frontend,cn=config changetype: add objectClass: olcOverlayConfig objectClass: ol

Chaining stops working after slapd restart

2013-04-29 Thread jeevan kc
Hi, I am trying to setup a chain overlay to allow writes to a read-only slave to be chained up to the master. dn: olcOverlay={0}chain,olcDatabase={-1}frontend,cn=configchangetype: add objectClass: olcOverlayConfig objectClass: olcChainConfig olcOverlay: {0}chain dn: olcDatabase=ldap,olcOverlay=

Re: slow replication

2013-04-29 Thread Aaron Richton
On Fri, 26 Apr 2013, Meike Stone wrote: syncrepl really isn't intended for initial "full" loads, although it will work eventually (as you've seen). The preferred method for standing up an offline server is slapadd -q. syncrepl can then handle deltas since the LDIF was generated; this should com

translucent overlay and memberof overlay together?

2013-04-29 Thread Steve Eckmann
Are the translucent and memberof overlays supposed to work together? I have one mdb backend with "native" accounts, and another mdb backend for "remote" accounts using the translucent overlay to proxy a remote AD. I want to be able to add remote account entries to groups in the native branch and