Re: Multiple certificates in slapd

2015-11-23 Thread Jarbas Peixoto Júnior
> > I know that I could set-up a slave server, but that would be not as > transparent s0 I'd prefer my idea of havingslapd -h > ldaps://192.168.10.1:636/ ldaps:/192.168.10.1:637/ each using a > different certificate. > I did so: I put two ldap slave servers (server-server-new and server-old). On t

Re: Trying to set up multimaster syncrepl, error attribute 'olcTLSCertificateFile' not allowed , why?

2015-11-23 Thread Quanah Gibson-Mount
--On Monday, November 23, 2015 7:12 PM -0500 Betsy Schwartz wrote: On Sat, Nov 21, 2015 at 2:00 PM, Quanah Gibson-Mount wrote: I would suggest using slapcat to export the config database and clean up the invalid attribute values that were incorrectly added to the bdb database. Thank

Re: Human-friendly olcAccess management

2015-11-23 Thread Harry Jede
Bogdan Rudas wrote: > Hello all, > > I would like to start use of olcAccess rules, are there > human-friendly editor for that ACLs? Use any editor you wish. It is just text! > I can't even use line breaks in ldif file to make my restrictions a > bit more readable! One can use line breaks, no prob

Multiple certificates in slapd

2015-11-23 Thread Olivier Nicole
Hi, I am planing a transition of the certificate I use in OpenLDAP for LDAP over SSL (port 636). My selft signed certificate is quite old and has become obsolete/not recognized on some systems (for example Mac OS 10.11) so it is time to update. But I have many systems that use LDAP and updating

Re: questions about memberof-refint option

2015-11-23 Thread k c
Le Sat, 21 Nov 2015 20:51:30 -0800, Quanah Gibson-Mount a écrit : > --On Sunday, November 22, 2015 12:20 AM +0100 "M. P." > wrote: > > > Le 2015-11-21 19:59, Quanah Gibson-Mount a écrit : > >> --On Friday, November 20, 2015 2:59 PM +0100 "M. P." > >> wrote: > >> > >>> I want to permit a "two

Re: questions about memberof-refint option

2015-11-23 Thread k c
Le Sun, 22 Nov 2015 14:29:00 +0100, Michael Ströder a écrit : > Quanah Gibson-Mount wrote: > > You can even use the memberOf attribute for creating the dynamic groups. > > Because 'memberOf' has "USAGE dSAOperation" you would have to switch of > slapo-memberof and re-declare the attribute type d

RE: Getting around the single-threaded syncrepl model?

2015-11-23 Thread Quanah Gibson-Mount
--On Monday, November 23, 2015 11:38 AM + "Bannister, Mark" wrote: > --On Friday, November 20, 2015 6:31 PM + Albert Braden > wrote: > Hi Quanah, > > Are you sure your issues with syncrepl aren't specific to Zimbra? When > I ran the Zimbra at Homestead/Intuit we saw syncrepl issues,

Re: Getting around the single-threaded syncrepl model?

2015-11-23 Thread Jerry
On Mon, 23 Nov 2015 12:25:36 + Howard Chu wrote: > Bannister, Mark wrote: > >>> --On Friday, November 20, 2015 6:31 PM + Albert Braden > >>> wrote: > >> > >>> Hi Quanah, > >>> > >>> Are you sure your issues with syncrepl aren't specific to Zimbra? When > >>> I ran the Zimbra at Homest

Re: Getting around the single-threaded syncrepl model?

2015-11-23 Thread Howard Chu
Bannister, Mark wrote: --On Friday, November 20, 2015 6:31 PM + Albert Braden wrote: Hi Quanah, Are you sure your issues with syncrepl aren't specific to Zimbra? When I ran the Zimbra at Homestead/Intuit we saw syncrepl issues, but I have not seen those issues in non-Zimbra LDAP cluster

RE: Getting around the single-threaded syncrepl model?

2015-11-23 Thread Bannister, Mark
> > --On Friday, November 20, 2015 6:31 PM + Albert Braden > > wrote: > > > Hi Quanah, > > > > Are you sure your issues with syncrepl aren't specific to Zimbra? When > > I ran the Zimbra at Homestead/Intuit we saw syncrepl issues, but I > > have not seen those issues in non-Zimbra LDAP clu