Multimaster OpenLDAP - LDAP failed to start

2014-10-22 Thread Arantza Serrano
Hello, I've a multimaster openldap servers. One of them is not running and when I try to start I show this error: Starting ldap...Done. Failed. /opt/zimbra/bin/ldap: line 50: kill: (4375) - No such process /opt/zimbra/bin/ldap: line 50: kill: (6219) - No such process

Modifying schemas

2014-10-22 Thread Côme BERNIGAUD
Hello, If I do sudo ldapsearch -Y EXTERNAL -H ldapi:/// -b cn=schema,cn=config cn=* cn I can see in the resulsting list: # {18}applications-fd, schema, config dn: cn={18}applications-fd,cn=schema,cn=config cn: {18}applications-fd But if I use an ldif trying to modify this I

Re: Modifying schemas

2014-10-22 Thread Michael Ströder
Côme BERNIGAUD wrote: But if I use an ldif trying to modify this I get: modifying entry cn={18}applications-fd,cn=schema,cn=config ldap_modify: No such object (32) Which OpenLDAP version? Ciao, Michael. smime.p7s Description: S/MIME Cryptographic Signature

Re: Modifying schemas

2014-10-22 Thread Côme BERNIGAUD
On 2014-10-22 10:27, Michael Ströder wrote: Côme BERNIGAUD wrote: But if I use an ldif trying to modify this I get: modifying entry cn={18}applications-fd,cn=schema,cn=config ldap_modify: No such object (32) Which OpenLDAP version? Ciao, Michael. 2.4.31-1+nmu2

Re: LDAP searches hang after returning results...

2014-10-22 Thread Howard Chu
Jeff Lebo wrote: I was able to get 2.4.40 compiled and installed. Having the same issue.. here is the syslog output... you can see the timestamp difference between where the hang happens, and where slapd finally disconnects. Use slapd -d7, not syslog. The null search references look

journal of changes

2014-10-22 Thread Zeus Panchenko
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 hi, is there way to have something like, I'd call, journal of changes where it could be saved all changes (modifications and deletions in particular) for each object what I'm talking about is *whole* history of the actions the object has undergone

Re: journal of changes

2014-10-22 Thread Michael Ströder
Zeus Panchenko wrote: is there way to have something like, I'd call, journal of changes where it could be saved all changes (modifications and deletions in particular) for each object what I'm talking about is *whole* history of the actions the object has undergone after creation You're

Re: Modifying schemas

2014-10-22 Thread Michael Ströder
Côme BERNIGAUD wrote: On 2014-10-22 10:27, Michael Ströder wrote: Côme BERNIGAUD wrote: But if I use an ldif trying to modify this I get: modifying entry cn={18}applications-fd,cn=schema,cn=config ldap_modify: No such object (32) Which OpenLDAP version? 2.4.31-1+nmu2

RE: Synchronizing two mirror mode clusters

2014-10-22 Thread Meunier, Antonin
Hello, I currently have several problems with MMR with lots of modification of data made in the Ldap : - ITS 7830 (http://www.openldap.org/its/index.cgi/Incoming?id=7830;selectid=7830) -- MDB_MAP_FULL with lots of modifications and read access -

RE: LDAP searches hang after returning results...

2014-10-22 Thread Jeff Lebo
These OpenLDAP servers are in an Internet facing DMZ, so they are using external DNS servers. I pointed them to internal DNS servers and created firewall rules to allow this traffic, and they can now resolve the internal 'ForestDnsZones.domain.com', which is were it appears to have been

Re: Multimaster OpenLDAP - LDAP failed to start

2014-10-22 Thread Quanah Gibson-Mount
--On Wednesday, October 22, 2014 9:39 AM +0200 Arantza Serrano aserr...@gfi.es wrote: Hello, I've a multimaster openldap servers. One of them is not running and when I try to start I show this error: OpenLDAP version? --Quanah -- Quanah Gibson-Mount Server Architect Zimbra, Inc.

Re: translucent overlay add an attribute to all users in a OU and subtree

2014-10-22 Thread Nicolas RENAULT
Le 21/10/2014 17:42, Dieter Klünter a écrit : Am Tue, 21 Oct 2014 14:35:14 +0200 schrieb Nicolas RENAULT nicolas_rena...@yahoo.fr: Le 21/10/2014 09:23, Michael Ströder a écrit : Dieter Klünter wrote: collectiveAttrbibuteSubentry is declared in schema_prep.c. When I tested collective

Re: Redhat LDAP Client Issues when disabling SSLv3

2014-10-22 Thread Philip Guenther
On Wed, 22 Oct 2014, Peter Boguszewski wrote: I am running into issues on RHEL 6.x servers (mix of 6.5 and now 6.6) when attempting to disable SSLv3. I have compiled the servers with the --with-tls=openssl option and communication appears to be working well between servers to matter what I

Re: Redhat LDAP Client Issues when disabling SSLv3

2014-10-22 Thread Peter Boguszewski
Thanks for the quick response. I was also messing with the olcTLSProtocolMin settings and seeing similar issues (which are now verified by your answer). It appears as though RHEL 6.x does not support TLS1.1 nor TLS1.2 with the yum installed packages. Pete On 10/22/2014 4:29 PM, Philip

Re: Redhat LDAP Client Issues when disabling SSLv3

2014-10-22 Thread Quanah Gibson-Mount
--On Wednesday, October 22, 2014 5:54 PM -0500 Peter Boguszewski pboguszew...@library.wisc.edu wrote: Thanks for the quick response. I was also messing with the olcTLSProtocolMin settings and seeing similar issues (which are now verified by your answer). It appears as though RHEL 6.x does

Re[2]: Redhat LDAP Client Issues when disabling SSLv3

2014-10-22 Thread Peter Boguszewski
I opened a case with Red Hat support. I will see how far that goes. Will continue to compile from source on the server side. Thanks, Pete -- Peter Boguszewski Manger of Library Systems UW - Madison - Library Technology Group Wednesday, 22 October 2014, 05:08PM -05:00 from Quanah

Re: Redhat LDAP Client Issues when disabling SSLv3

2014-10-22 Thread SATOH Fumiyasu
At Wed, 22 Oct 2014 16:54:24 -0500, Peter Boguszewski wrote: Thanks for the quick response. I was also messing with the olcTLSProtocolMin settings and seeing similar issues (which are now verified by your answer). It appears as though RHEL 6.x does not support TLS1.1 nor TLS1.2 with the yum

Re: Seems that syncprov holds up LMDB's reclaiming while handle a syncrepl requests.

2014-10-22 Thread Леонид Юрьев
ITS#7904 http://www.openldap.org/its/index.cgi/Incoming?id=7974;selectid=7974 2014-10-21 9:15 GMT+04:00 Леонид Юрьев l...@yuriev.ru: I will submit the ITS with a patch. Now it is being tested. Leonid. 2014-10-20 21:30 GMT+04:00 Quanah Gibson-Mount qua...@zimbra.com: --On Wednesday,

Re: Synchronizing two mirror mode clusters

2014-10-22 Thread Леонид Юрьев
I assume that ITS7830 (MDB_MAP_FULL with lots of modifications and read access) is the same as ITS7904, and would be solved by a 'dreamcatcher' feature. 2014-10-22 16:26 GMT+04:00 Meunier, Antonin antonin.meun...@cgi.com: Hello, I currently have several problems with MMR with lots of