Re: dynamic groups seach for memberUID openldap 2.6

2022-01-03 Thread Quanah Gibson-Mount
ts,dc=example,dc=com uid: joe Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: symas openldap-packages and kerberos

2022-01-03 Thread Quanah Gibson-Mount
/opt/symas/lib/sasl2 (for Symas OpenLDAP builds). Similar idea for OS builds, etc, just with their paths instead. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Guide to setup syncrepl with proxy-based push config

2022-01-03 Thread Quanah Gibson-Mount
ided by Symas for Ubuntu. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: remove overlay from cn=config 2.6

2022-01-03 Thread Quanah Gibson-Mount
attrs and delete the ppolicy overlay, your resulting DB will be in a bad state (I.e., it's on you to clean up your database first). --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Interpreting username@domainname

2022-01-03 Thread Quanah Gibson-Mount
DNs for simple binds. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: [EXT] Re: openldap ppolicy pwdAccountLockedTime

2022-01-03 Thread Quanah Gibson-Mount
hat you want to ensure you're running 2.5.8 or later (See ITS#9671). --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: right order mmr-main-DB combined with mmr cn=config

2021-12-15 Thread Quanah Gibson-Mount
--On Wednesday, December 15, 2021 8:23 PM +0100 Stefan Kania wrote: Am 15.12.21 um 19:44 schrieb Quanah Gibson-Mount: Please file a bug. How can I? Is there someting like bugzilla I know from the Samba project. Step 1: Browse to https://www.openldap.org Step 2: Click on the "

Re: right order mmr-main-DB combined with mmr cn=config

2021-12-15 Thread Quanah Gibson-Mount
. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: ldap_search_ext_s fails with "Operations error" when using root as base dn

2021-12-15 Thread Quanah Gibson-Mount
ple,DC=com). If I use a more specific base, such as CN=Computers,DC=example,DC=com the operation succeeds. Is there a limitation to the search function? This sounds like a question for Microsoft and what limitations it imposes. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas C

Re: Ldap sync has broken from time to time

2021-12-15 Thread Quanah Gibson-Mount
have also been significant changes made to how sync replication works in the 2.5 release that could not be done in the 2.4 series that make standard syncrepl viable. Finally, I would note that there is nothing that prevents one from compiling OpenLDAP 2.5 (or later) on Solaris. Regards, Quan

Symas OpenLDAP 2.6.0-5 released

2021-12-14 Thread Quanah Gibson-Mount
: slapo-allowed is now available. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Symas OpenLDAP 2.5.9-5 released

2021-12-14 Thread Quanah Gibson-Mount
-mdb to update indices correctly on replace ops (ITS#9753) Fixed slapo-syncprov to generate a more accurate accesslog query (ITS#9756) Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <h

Re: OpenLDAP 2.6.0 testing call #3

2021-12-13 Thread Quanah Gibson-Mount
no such object, doesn't really tell me much. OTOH, memberof is deprecated now, so not sure how much I care. ;) --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Antw: [EXT] OpenLDAP Upgrade

2021-12-13 Thread Quanah Gibson-Mount
--On Monday, December 13, 2021 10:25 AM +0100 Ulrich Windl wrote: Quanah Gibson-Mount schrieb am 10.12.2021 um 18:00 in Nachricht <2A5F43DA950658AE64FEE654@[192.168.1.3]>: You are right insofar as Redhat and SUSE both moved from openLDAP to 389ds in their current releases, but

Re: Antw: [EXT] OpenLDAP Upgrade

2021-12-13 Thread Quanah Gibson-Mount
roject (<https://www.openldap.org/project/>). I'm telling you two things: a) 2.4 is historic and no longer supported. b) 2.5 is the current stable release. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions

Re: Antw: [EXT] OpenLDAP Upgrade

2021-12-10 Thread Quanah Gibson-Mount
kages used in production by our paying support customers, and critical issues found therein are promptly fixed. So *free* users get actual support and benefit from using our packages that are not obtainable via distribution provided packages. Regards, Quanah -- Quanah Gibson-Mount Prod

Re: deltasync replication with 2.6 not working

2021-12-09 Thread Quanah Gibson-Mount
test suite and has no issue. We also have customers running with delta-sync and no issue. As an aside, I would note that "olcmirrormode" was renamed to "olcmultiprovider" in 2.5+ --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified

Re: mmr of cn=config with OpenLDAP 2.6

2021-12-09 Thread Quanah Gibson-Mount
symas packages do not include the test suite. However, cn=config replication is tested in the test suite, both with syncrepl and delta-syncrepl, and passes. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by

RE: [EXT]:Re: OpenLDAP SSLV3 disable

2021-12-09 Thread Quanah Gibson-Mount
k to OpenSSL already and skip building OpenLDAP yourself. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Antw: [EXT] OpenLDAP Upgrade

2021-12-09 Thread Quanah Gibson-Mount
--On Tuesday, December 7, 2021 8:39 AM -0800 Quanah Gibson-Mount wrote: --On Tuesday, December 7, 2021 9:57 AM + santoshk.se...@tcs.com wrote: Thanks Emmanuel, Is it a stable version we can reply upon? Because the request is for a production environment which are running critical

Re: mmr of cn=config with OpenLDAP 2.6

2021-12-07 Thread Quanah Gibson-Mount
.example.net olcServerID: 4 ldap://ldap04.example.net It's URI format or not? It is, but that's from a MOD. The configs don't start *out* that way. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by

Re: mmr of cn=config with OpenLDAP 2.6

2021-12-07 Thread Quanah Gibson-Mount
replication of cn=config on all servers? The documentation clearly states that for cn=config replication, the serverID must be in # URI format. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <h

Re: Antw: [EXT] OpenLDAP Upgrade

2021-12-07 Thread Quanah Gibson-Mount
binaries via a repository as described at <https://repo.symas.com/soldap/>. Paid support is optionally available as well. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: 2.6 slapadd bug? - SHA512 userPassword hash get 2 characters appended to the end at import

2021-12-06 Thread Quanah Gibson-Mount
multi-line attribute values and the leftover bits get tacked onto the previous attribute. One way around this is to turn off LDIF line wraps on export. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP:

Re: Antw: [EXT] OpenLDAP Upgrade

2021-12-06 Thread Quanah Gibson-Mount
ds, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Sv: Move from memberof to dynlist

2021-12-01 Thread Quanah Gibson-Mount
--On Wednesday, December 1, 2021 9:36 PM -0800 Quanah Gibson-Mount wrote: --On Wednesday, December 1, 2021 10:35 PM + Magnus Morén wrote: I have now tested dynlist and I have the memberOf working. Good. I did a "remove user" test... When I remove a user from th

Re: Sv: Move from memberof to dynlist

2021-12-01 Thread Quanah Gibson-Mount
This would imply that you left the "memberOf" attribute present on the raw entry. That would need to be manually removed. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: 2.6 rhel8 rpm pkg - lastbind module issue

2021-12-01 Thread Quanah Gibson-Mount
quot; and pwdLastSuccess is sufficient, you don't need the fix nor do you need to load the lastbind contrib module. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: 2.6 rhel8 rpm pkg - lastbind module issue

2021-12-01 Thread Quanah Gibson-Mount
est, Yeah, there's a number of issues currently being tracked down, I hope to have new packages or a new OpenLDAP release soon. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Move from memberof to dynlist

2021-12-01 Thread Quanah Gibson-Mount
e the functionality of the slapo-memberof(5) overlay. Your attribute is "uniqueMember" not member, and your group objectClass is "groupOfUniqueNames" not groupofNames. You need to adjust the dynlist-attrset accordingly. --Quanah -- Quanah Gibson-Mount Product Ar

Re: 2.6 rhel8 rpm pkg - lastbind module issue

2021-12-01 Thread Quanah Gibson-Mount
amp): attribute type undefined slapadd: could not parse entry (line=24) Closing DB... You need the fix for ITS#9725 to make use of authTimestamp. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: &l

Re: how to build dynacl now.c?

2021-11-29 Thread Quanah Gibson-Mount
--On Monday, November 29, 2021 12:24 PM -0800 Quanah Gibson-Mount wrote: --On Monday, November 29, 2021 7:18 PM +0100 Michael Ströder wrote: HI! Hmm, I cannot see what I'm doing wrong here. Compiling other contrib modules works just fine. $ make -B -C contrib/slapd-modules/ac

Re: how to build dynacl now.c?

2021-11-29 Thread Quanah Gibson-Mount
ap/contrib/slapd-modules/acl' gcc now.c -o now now.c:28:10: fatal error: portable.h: No such file or directory 28 | #include I would suggest fixing your CFLAGS? Other contrib modules have no issue finding the header file. --Quanah -- Quanah Gibson-Mount Product Architect Sy

Re: contextCSN value

2021-11-16 Thread Quanah Gibson-Mount
, except "provider" not "replica". --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: global vs. frontend config in slapd.conf

2021-11-16 Thread Quanah Gibson-Mount
something like database frontend ... to fix it, but it doesn't appear to. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

RE: [EXT]:Re: OpenLDAP SSLV3 disable

2021-11-14 Thread Quanah Gibson-Mount
d.conf(5) man page section on TLSCipherSuite for the GnuTLS command line to print out relevant information. This ticket may also be helpful: <https://mod.gnutls.org/ticket/29> --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LD

Re: OpenLDAP client build/compilation steps on Windows platform

2021-11-11 Thread Quanah Gibson-Mount
me. There is no support for using the MS visual studio C compiler to build openldap. I was talking about using gcc etc inside of MSYS2 to do the build. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP

Re: compare operation behaves differently under 2.5

2021-11-10 Thread Quanah Gibson-Mount
> On Nov 10, 2021, at 7:07 PM, Paul B. Henson wrote: > > On Wed, Nov 10, 2021 at 04:36:00PM -0800, Quanah Gibson-Mount wrote: > >> If you disable the dynlist overlay, do you get the same behavior? > > Nope; if I remove the line > >dynlist-attrset groupOf

Re: compare operation behaves differently under 2.5

2021-11-10 Thread Quanah Gibson-Mount
uire ldap-group uid=unxadmin,ou=group,dc=cpp,dc=edu This stopped working when accessing a server updated to 2.5. On the 2.4 server, the Apache logs look like: If you disable the dynlist overlay, do you get the same behavior? --Quanah -- Quanah Gibson-Mount Product Architect Symas Corpo

Re: DirSync support in OpenLDAP

2021-11-10 Thread Quanah Gibson-Mount
--On Wednesday, November 10, 2021 8:41 AM -0800 Christopher Paul wrote: On 11/10/21 7:49 AM, Quanah Gibson-Mount wrote: See <https://lists.openldap.org/hyperkitty/list/openldap-announce@openldap.o rg/thread/BH3VDPG6IYYF5L5U6LZGHHKMJY5HFA3L/> , specifically the section entite

Re: DirSync support in OpenLDAP

2021-11-10 Thread Quanah Gibson-Mount
be done on the OpenLDAP proxy. Thanks you for your help ! See <https://lists.openldap.org/hyperkitty/list/openldap-annou...@openldap.org/thread/BH3VDPG6IYYF5L5U6LZGHHKMJY5HFA3L/> , specifically the section entited "New replication protocols". --Quanah -- Quanah Gibs

RE: [EXT]:Re: OpenLDAP SSLV3 disable

2021-11-09 Thread Quanah Gibson-Mount
/local/var/openldap-data index objectClass eq database monitor If you are still unable to set the minimum protocol, I would advise confirming what TLS library your slapd build is linked to. For example, the TLSProtocolMin parameter has no effect when slapd is linked to GnuTLS. Regards, Quanah -

Re: OpenLDAP 2.6 Build Failure - undefined reference

2021-11-03 Thread Quanah Gibson-Mount
fully. If 'ber_sockbuf_io_udp' absence is intentional, should I somehow account for it during './configure'? That symbol only exists if OpenLDAP is built with LDAP_CONNECTIONLESS defined, which is not a supported feature. Feel free to file a bug report at https://bug

RE: [EXT]:Re: OpenLDAP SSLV3 disable

2021-11-03 Thread Quanah Gibson-Mount
SSL or TLS. I would note that your TLS configuration directives are inside the database backend definition which is invalid. They are global options and should appear before any database configuration section. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged,

RE: [EXT]:Re: OpenLDAP SSLV3 disable

2021-11-03 Thread Quanah Gibson-Mount
ion for the 2.6 version? I can look to upgrade it. The OpenLDAP website has a tarball of the source available for download. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: OpenLDAP SSLV3 disable

2021-11-03 Thread Quanah Gibson-Mount
e also have free replacement packages providing OpenLDAP 2.4.59 on RHEL7 at <https://repo.symas.com/sofl/rhel7/>. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: OpenLDAP client build/compilation steps on Windows platform

2021-11-02 Thread Quanah Gibson-Mount
changes required in OpenLDAP source code to compile successfully on Windows with MSVC compiler if any? I've generally used MSYS2 to compile OpenLDAP on Windows. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by Ope

Re: memberof vs groupMembership

2021-11-01 Thread Quanah Gibson-Mount
mberOf. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Antw: [EXT] Symas openldap 2.5 RPMs / openssl cert trust

2021-10-25 Thread Quanah Gibson-Mount
e it to use the system CAs as well as your own local certificate authority if desired. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: contextCSN not updated

2021-10-25 Thread Quanah Gibson-Mount
you're running in an MMR environment? Alternatively, if there is some need that mandates consumers, there are examples in the test suite on how to set things up so that a group of consumers share a replicated database (See test059 or test086). Regards, Quanah -- Quanah Gibson

Re: Problem with SSL/TLS on CentOS 7 after upgrading to 2.4.59

2021-10-21 Thread Quanah Gibson-Mount
.noa.gr, issuer: /C=NL/O=GEANT Vereniging/CN=GEANT OV RSA CA 4 TLS certificate verification: Error, unable to get local issuer certificate --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Symas OpenLDAP 2.5 RPMs run slapd as root?

2021-10-20 Thread Quanah Gibson-Mount
--On Tuesday, October 19, 2021 9:55 PM -0700 "Paul B. Henson" wrote: On 10/19/2021 8:10 AM, Quanah Gibson-Mount wrote: If you want it to run as a non-root user, it's on you to configure it as such, including said user.  The majority of Symas customers run as root.

Re: Symas OpenLDAP 2.5 RPMs run slapd as root?

2021-10-19 Thread Quanah Gibson-Mount
r. The majority of Symas customers run as root. So yes, this is intentional and due to the fact that it's not attempting to be the replacement of the system bundled OpenLDAP. You're free to run things as best fits your environment. --Quanah -- Quanah Gibson-Mount Product Archite

OpenLDAP 2.6.0 testing call #3

2021-10-18 Thread Quanah Gibson-Mount
ends have been removed: back-ndb back-shell Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: accesslog moving from 2.4. to 2.5 SIGSEGV on startup

2021-10-14 Thread Quanah Gibson-Mount
0> Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: delta-sync out of sync..

2021-10-14 Thread Quanah Gibson-Mount
contextCSN of both server are exactly the same (both context csn), but the entry has not been created on the second server. Do a modify of some sort on that entry on the server where it exists, that should force it to re-sync. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation

Symas OpenLDAP 2.5.8 now available

2021-10-12 Thread Quanah Gibson-Mount
Symas OpenLDAP 2.5.8 is now available. Installation instructions available at <https://repo.symas.com/soldap/>. Builds are provided for free of use with no support. Optional paid support is available, further details at <https://www.symas.com/> Regards, Quanah -- Quanah

Re: OpenLDAP 2.6.0 testing call #2

2021-10-08 Thread Quanah Gibson-Mount
--On Monday, October 4, 2021 10:44 AM +0200 Bastian Tweddell wrote: On 30Sep21 08:39-0700, Quanah Gibson-Mount wrote: > The setup we use is quite simple, so a number of tests are skipped. > Would you recommend, or like to see certain configurations to be > tested? Mainly the ne

Re: [LMDB] Performance on AWS/Windows

2021-10-07 Thread Quanah Gibson-Mount
er causing all sorts of problems unless you start shelling out some cash to get decent perf. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: OpenLDAP 2.6.0 testing call #2

2021-09-30 Thread Quanah Gibson-Mount
--On Thursday, September 30, 2021 4:15 PM +0200 Bastian Tweddell wrote: On 28Sep21 12:12-0700, Quanah Gibson-Mount wrote: Generally, get the code for RE26: <https://git.openldap.org/openldap/openldap/-/archive/OPENLDAP_REL_ENG_2 _6/openldap-OPENLDAP_REL_ENG_2_6.tar.gz> E

Re: OpenLDAP 2.6.0 testing call

2021-09-30 Thread Quanah Gibson-Mount
ACL" then the ACL data starts getting added to the log.  No restart required. If I change it back to "stats" I keep getting ACL data until the directory is restarted. This should now be fixed. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, cert

Re: OpenLDAP 2.6.0 testing call

2021-09-29 Thread Quanah Gibson-Mount
> On Sep 29, 2021, at 8:09 PM, Howard Chu wrote: > > Quanah Gibson-Mount wrote: >> >> >> --On Thursday, September 30, 2021 12:53 AM +0100 Howard Chu >> wrote: >> >>> Nick Folino wrote: >>>> Yes. Logging now continues to work a

Re: OpenLDAP 2.6.0 testing call

2021-09-29 Thread Quanah Gibson-Mount
18 slapd[5980]: conn=1004 op=1 SEARCH RESULT tag=101 err=0 qtime=0.000176 etime=0.000428 nentries=1 text= Sep 30 01:31:52 ub18 slapd[5980]: conn=1004 op=2 UNBIND Sep 30 01:31:52 ub18 slapd[5980]: conn=1004 fd=13 closed Zero need to restart slapd or use a replace op to reset the logging. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: OpenLDAP 2.6.0 testing call

2021-09-29 Thread Quanah Gibson-Mount
fixed. :) --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

OpenLDAP 2.6.0 testing call #2

2021-09-28 Thread Quanah Gibson-Mount
l honor debug level settings passed via the -d option. *) The standalone form of lloadd can deadlock if the monitor backend is enabled. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: OpenLDAP 2.6.0 testing call

2021-09-28 Thread Quanah Gibson-Mount
--On Friday, September 17, 2021 10:13 AM -0700 Quanah Gibson-Mount wrote: --On Tuesday, September 7, 2021 7:07 PM -0400 Nick Folino wrote: Thanks Quanah.  olcLogFile and olcLogFileOnly seem to have no effect. Using them I still get logs only to the journal on Fedora 34. Hi Nick

Re: delta-sync replication setup

2021-09-27 Thread Quanah Gibson-Mount
lt;https://mishikal.wordpress.com/2019/04/23/configuring-mmr-using-delta-syncrepl-in-openldap-updating-an-existing-standalone-configuration/> that should be possible to pull from. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions

Re: Replication N-way

2021-09-23 Thread Quanah Gibson-Mount
tput of slapcat -n 0 -l /tmp/config.ldif) with any passwords redacted. What you provided clearly fell fall short of that and is all I have to go off of. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by

Re: Replication N-way

2021-09-23 Thread Quanah Gibson-Mount
replication to function. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: 2.5.7 - help understanding syslog local4

2021-09-23 Thread Quanah Gibson-Mount
an be bypassed entirely and a purely local log file can be used, resulting in a significant performance increase. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: 2.5.7 - help understanding syslog local4

2021-09-23 Thread Quanah Gibson-Mount
configured correctly. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Uplift from 2.3.20 to 2.4.50

2021-09-23 Thread Quanah Gibson-Mount
customizations to OpenLDAP 2.3 they likely do not remotely apply any longer (I.e., the bdb/hdb backends found in 2.3 no longer exist in 2.5). Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <h

Re: configure: error: Could not locate Cyrus SASL

2021-09-23 Thread Quanah Gibson-Mount
need to install the development package for cyrus-sasl on your platform so that OpenLDAP can link against it. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: ./Configure failed on openldap

2021-09-22 Thread Quanah Gibson-Mount
le-modules --enable-rlookups --enable-backends=mod --disable-ndb --disable-sql --disable-wt --enable-overlays=mod Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Some problems while compiling + using openldap 2.5.7 ubuntu 20.04

2021-09-22 Thread Quanah Gibson-Mount
was just not run after the library was installed. Or just correctly set the compile time build flags so that the library runpath is correctly built into the binaries. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered

Re: Replication N-way

2021-09-21 Thread Quanah Gibson-Mount
with that information. Thanks, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Replication N-way

2021-09-21 Thread Quanah Gibson-Mount
However, I'd strongly advise looking at migrating to 2.5. Symas provides free 2.5 packages as well (<https://repo.symas.com/soldap/>). Additionally, optional paid support is available for either. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Package

Re: Is there significance in overlay order in replicated environment

2021-09-20 Thread Quanah Gibson-Mount
Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Syncrepl failing after a while

2021-09-20 Thread Quanah Gibson-Mount
mas.com/soldap/rhel7/>). I'd also note that your syncrepl stanza is missing the "keepalive" option, which is usually essential when dealing with traffic through load balancers. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and

Re: Is there significance in overlay order in replicated environment

2021-09-20 Thread Quanah Gibson-Mount
log. After that order should be immaterial. I would note that in OpenLDAP 2.5, a bit of the lastbind functionality has been integrated into slapd so you may not need to deploy it separately. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported L

Re: OpenLDAP 2.6.0 testing call

2021-09-17 Thread Quanah Gibson-Mount
-- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: OpenLDAP 2.6.0 testing call

2021-09-16 Thread Quanah Gibson-Mount
--On Tuesday, September 14, 2021 10:37 AM -0700 Quanah Gibson-Mount wrote: All tests completed without error. I then ran the regressions tests and got this error: Thanks Scott, I'm able to reproduce and investigating. This should now be fixed. --Quanah -- Quanah Gibson-

Re: openldap and oauth2

2021-09-14 Thread Quanah Gibson-Mount
-- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: How to create an entry, which is not returned on SEARCH

2021-09-14 Thread Quanah Gibson-Mount
--On Monday, September 13, 2021 2:33 PM +0300 Дилян Палаузов wrote: Hello, How can I create an entry (in terms of ldif/ldapadd/ldapmodify), which is not returned on searches (apart from tweaking the olcAccess rules? You need to tweak the olcAccess rules. --Quanah -- Quanah Gibson

Re: OpenLDAP 2.6.0 testing call

2021-09-14 Thread Quanah Gibson-Mount
ble-ppolicy --enable-memberof make depend make make test All tests completed without error. I then ran the regressions tests and got this error: Thanks Scott, I'm able to reproduce and investigating. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged,

Re: OpenLDAP 2.6.0 testing call

2021-09-08 Thread Quanah Gibson-Mount
appen for 2.6. File a bug on it though for the future. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: OpenLDAP 2.6.0 testing call

2021-09-07 Thread Quanah Gibson-Mount
ds, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: OpenLDAP 2.6.0 testing call

2021-09-07 Thread Quanah Gibson-Mount
--On Tuesday, September 7, 2021 8:57 PM +0200 Michael Ströder wrote: On 9/7/21 19:01, Quanah Gibson-Mount wrote: This is the first testing call for OpenLDAP 2.6.0 Release. FWIW: make test worked on openSUSE Tumbleweed x86_64. But what are the main differences compared to 2.5.7? I

OpenLDAP 2.6.0 testing call

2021-09-07 Thread Quanah Gibson-Mount
so supports this new feature, but it can be tested with slapd at this time. Additionally, the following deprecated backends have been removed: back-ndb back-shell Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: dynlist vs memberof performance issues

2021-09-01 Thread Quanah Gibson-Mount
resence%20indexing> If the group object is large you may be having slow searches due to indices being collapsed to a range. You would need to run the search with trace logging to determine if that's the case as was recently discussed on the list. Regards, Quanah -- Quanah Gibson-Mou

Re: 2.5.7 - adding memberof module Duplicate attributeType

2021-08-30 Thread Quanah Gibson-Mount
recommend either groupOfNames or groupOfMembers Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: 2.5.7 - adding memberof module Duplicate attributeType

2021-08-30 Thread Quanah Gibson-Mount
provide it for them. posixGroup is not a valid objectClass to use with providing memberOf information. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: OpenLDAP 2.5.7 dies

2021-08-30 Thread Quanah Gibson-Mount
at https://bugs.openldap.org with the reproduction steps. Thanks! Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: 2.5.7 - adding memberof module Duplicate attributeType

2021-08-30 Thread Quanah Gibson-Mount
external schema. The msuser.ldif is provided for those people who want to try the AD replication integration added in OpenLDAP 2.5. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: OpenLDAP 2.5.7 dies

2021-08-27 Thread Quanah Gibson-Mount
entry for whatever you have defined the default policy to be or whatever policy it is that applies to the entries you are modifying. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: 2.5.7 - adding memberof module Duplicate attributeType

2021-08-27 Thread Quanah Gibson-Mount
. Installations should use the dynlist overlay instead. Using this overlay in a replicated environment is especially discouraged. The point was you should be using dynlist rather than memberOf. Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged

Re: 2.5.7 - adding memberof module Duplicate attributeType

2021-08-27 Thread Quanah Gibson-Mount
--On Friday, August 27, 2021 6:09 PM -0400 Dave Macias wrote: Hello again... On a clean rocky linux install i cannot seem to be able to add the memberof.la module. Get below output: First question is, why are you installing memberOf module at all? :) --Quanah -- Quanah Gibson-Mount

Re: OpenLDAP 2.5.7 dies

2021-08-27 Thread Quanah Gibson-Mount
2.5 source tree, without any other modifications, you should have gotten a compile error. It didn't exist in the contrib directory in OpenLDAP 2.4, and he specifically noted he built it out of contrib with 2.5. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged,

Re: OpenLDAP 2.5.7 dies

2021-08-27 Thread Quanah Gibson-Mount
our build and the related debuginfo packages. <https://repo.symas.com/soldap/> Regards, Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

Re: Antw: [EXT] Re: openSUSE/SLE users, migrate to back-mdb now!

2021-08-27 Thread Quanah Gibson-Mount
issue however. --Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>

<    1   2   3   4   5   6   7   8   9   10   >