Full_Name: Quanah Gibson-Mount
Version: 2.4.16
OS: Linux 2.6
URL: ftp://ftp.openldap.org/incoming/
Submission from: (NULL) (209.131.62.113)
Oracle has kindly provided Howard and I access to the early BDB 4.8 code.
Filing this ITS so that we can track modifications to support new features in
BDB 4.8, such as the bulk add/delete capabilities.
--On May 13, 2009 9:41:04 AM +0000 vinodkharatmol(a)gmail.com wrote:
> Full_Name: Vinod Kharatmol
> Version: 2.3.27-5
> OS: Linux RHEL 4 Update 2
> URL: ftp://ftp.openldap.org/incoming/
> Submission from: (NULL) (203.199.133.19)
>
>
> Hello,
>
> I have Installed RHEL 5 on VMware separately as Server and Client.
> The LDAP Sever and Client Successfully configured.
> I am able to start LDAP Server successfully using command: # service ldap
> start.
> I have created a ldapuser on Server.
> But when I am trying to login as a ldapuser on client using # su ldapuser
> then we are facing error as, su:ldapuser does not exist.
>
> I am totally stuck here.
Nothing in this report shows any bug in the OpenLDAP software. If you are
having problems with the ldap package provided by RHEL, I suggest you
contact RedHat support. If you have general usage questions about
OpenLDAP, you should address those to the appropriate list (most likely
openldap-software(a)openldap.org). This ITS will be closed.
--Quanah
--
Quanah Gibson-Mount
Principal Software Engineer
Zimbra, Inc
--------------------
Zimbra :: the leader in open source messaging and collaboration
Full_Name: Christoph Hannebauer
Version: 2.4.16
OS: Windows/cygwin
URL: http://www.hannebauer.name/openldap-openssl/configure.in.patch
Submission from: (NULL) (139.18.40.169)
I tried to use OpenSSL 0.9.8k for TLS in my cygwin (target MinGW) OpenLDAP
build. The configure script does not detect OpenSSL (however, it doesn't break,
instead it finishes without TLS support), because the static library cannot be
linked. The config.log file contains error messages like
/usr/local/mingw/lib/libcrypto.a(rand_win.o):rand_win.c:(.text+0xa0c): undefined
reference to `_CreateDCA@16'
The missing functions are part of the library gdi32.lib. The OpenSSL readme file
INSTALL.W32 says, that Windows program using OpenSSL should link gdi32.lib (and
user32.lib, ..., but on my machine, gdi32.lib seems to be sufficient). Therefore
I have created the attached patch file to configure.in (1.697), which adds
gdi32.lib to LIBS, if it is required for OpenSSL. I have tested the patched
configure file on my machine, the build works without problems.
Glück & Kanja Consulting AG (www.glueckkanja.com) hereby places the following
modifications to OpenLDAP Software (and only these modifications) into the
public domain. Hence, these modifications may be freely used and/or
redistributed for any purpose with or without attribution and/or other notice.
Luca Scamoni ha scritto:
> I have two more cores at the same point.
> Different entries but same assert hit
> info available from these cores also
>
And just around the time it died logs are full of:
May 12 15:40:01 quercia01 slapd[10124]: cmp -1, too old
May 12 15:40:01 quercia01 slapd[10124]: log csn
20090512050127.389811Z#000000#000#000000
May 12 15:40:01 quercia01 slapd[10124]: cmp -1, too old
May 12 15:40:01 quercia01 slapd[10124]: log csn
20090512050127.613282Z#000000#000#000000
May 12 15:40:01 quercia01 slapd[10124]: cmp -1, too old
May 12 15:40:01 quercia01 slapd[10124]: log csn
20090512050130.927811Z#000000#000#000000
May 12 15:40:01 quercia01 slapd[10124]: cmp -1, too old
May 12 15:40:01 quercia01 slapd[10124]: log csn
20090512050131.178084Z#000000#000#000000
May 12 15:40:01 quercia01 slapd[10124]: cmp -1, too old
May 12 15:40:01 quercia01 slapd[10124]: log csn
20090512053954.526945Z#000000#000#000000
May 12 15:40:01 quercia01 slapd[10124]: cmp -1, too old
May 12 15:40:01 quercia01 slapd[10124]: log csn
20090512060051.745213Z#000000#000#000000
May 12 15:40:01 quercia01 slapd[10124]: cmp -1, too old
May 12 15:40:01 quercia01 slapd[10124]: log csn
20090512060104.372615Z#000000#000#000000
May 12 15:40:01 quercia01 slapd[10124]: cmp -1, too old
May 12 15:40:01 quercia01 slapd[10124]: log csn
20090512060123.047312Z#000000#000#000000
and
May 12 20:15:37 quercia01 slapd[10355]: srs csn
20090512130647.129160Z#000000#000#000000
May 12 20:15:37 quercia01 slapd[10355]: log csn
20090512134228.001585Z#000000#000#000000
May 12 20:15:37 quercia01 slapd[10355]: log csn
20090512134918.492711Z#000000#000#000000
May 12 20:15:37 quercia01 slapd[10355]: log csn
20090512135120.067222Z#000000#000#000000
May 12 20:15:37 quercia01 slapd[10355]: log csn
20090512135443.385871Z#000000#000#000000
May 12 20:15:37 quercia01 slapd[10355]: log csn
20090512140043.322924Z#000000#000#000000
May 12 20:15:37 quercia01 slapd[10355]: log csn
20090512140055.931196Z#000000#000#000000
May 12 20:15:37 quercia01 slapd[10355]: log csn
20090512140111.553421Z#000000#000#000000
May 12 20:15:37 quercia01 slapd[10355]: log csn
20090512140139.198221Z#000000#000#000000
May 12 20:15:37 quercia01 slapd[10355]: log csn
20090512140151.790035Z#000000#000#000000
May 12 20:15:37 quercia01 slapd[10355]: log csn
20090512140225.400627Z#000000#000#000000
May 12 20:15:37 quercia01 slapd[10355]: log csn
20090512140240.985607Z#000000#000#000000
May 12 20:15:37 quercia01 slapd[10355]: log csn
20090512140314.649432Z#000000#000#000000
May 12 20:15:37 quercia01 slapd[10355]: log csn
20090512140327.203755Z#000000#000#000000
May 12 20:15:37 quercia01 slapd[10355]: log csn
20090512140345.926040Z#000000#000#000000
May 12 20:15:37 quercia01 slapd[10355]: log csn
20090512140410.553120Z#000000#000#000000
May 12 20:15:37 quercia01 slapd[10355]: log csn
20090512140423.120156Z#000000#000#000000
May 12 20:15:37 quercia01 slapd[10355]: log csn
20090512140502.743306Z#000000#000#000000
May 12 20:15:37 quercia01 slapd[10355]: log csn
20090512140533.526334Z#000000#000#000000
Don't know if they're normal or not
Ing. Luca Scamoni
Responsabile Ricerca e Sviluppo
SysNet s.r.l.
Gruppo Partners Associates
via Dossi, 8 - 27100 Pavia - ITALIA
http://www.sys-net.it
-----------------------------------
Office: +39 0382 573859 (137)
Fax: +39 0382 476497
Email: luca.scamoni(a)sys-net.it
-----------------------------------
Full_Name: Vinod Kharatmol
Version: 2.3.27-5
OS: Linux RHEL 4 Update 2
URL: ftp://ftp.openldap.org/incoming/
Submission from: (NULL) (203.199.133.19)
Hello,
I have Installed RHEL 5 on VMware separately as Server and Client.
The LDAP Sever and Client Successfully configured.
I am able to start LDAP Server successfully using command: # service ldap
start.
I have created a ldapuser on Server.
But when I am trying to login as a ldapuser on client using # su ldapuser
then we are facing error as, su:ldapuser does not exist.
I am totally stuck here.
Please help me out.
Thanks & Regards,
Vinod
Jemmy.Sentonius(a)infor.com wrote:
> Full_Name: Jemmy Sentonius
> Version: 2.2.29
> OS: Windows 2003 Server
> URL: ftp://ftp.openldap.org/incoming/
> Submission from: (NULL) (211.24.230.162)
>
>
>
> 1) Start the LDAP Service in Windows (logon as Domain Administrator)
> 2) System will prompt error:
> Windows could not start the InforSecurity LDAP on local computer. For more
> information, review the system event log. If this is non-Microsoft Service,
> contact the service vendor, and refer to service-specific error code 16.
>
> 3) Go to Windows Event Viewer, System Log
> Notice that there's an error log with description:
> The InforSecurity LDAP Service terminated with service-specific error 16
> (0x10)
The OpenLDAP Project dropped support for OpenLDAP 2.2 in 2005. This ITS will
be closed.
--
-- Howard Chu
CTO, Symas Corp. http://www.symas.com
Director, Highland Sun http://highlandsun.com/hyc/
Chief Architect, OpenLDAP http://www.openldap.org/project/
Full_Name: Mike Becher
Version: 2.4.16 or HEAD
OS: Linux
URL: ftp://ftp.openldap.org/incoming/mike-becher-090512.libraries-libldap.patch
Submission from: (NULL) (84.150.169.165)
patch file name: mike-becher-090512.libraries-libldap-gssapi.1.patch
patch subject: GSSAPI signing/encryption for unsuspectingly applications
ftp://ftp.openldap.org/incoming/mike-becher-090512.libraries-libldap.patch
This patch (see above) introduces a function hook and an additional ldap.conf
or ldaprc option GSSAPI_TRY_GSSAPI_BIND_S_IN_SASL_INTERACTIVE_BIND_S which
enables unsuspectingly applications to make use of GSSAPI based
authentification, signing, and/or encryption.
This is very useful if you are connected to MS Active Directory with
LDAP server signing is required (means is switched on) and your software
(like for example pam_ldap or nss_ldap) doesn't know about that requirement.
Additionally if a user does not want use this feature s/he can it switch off
on demand.
Excerpt from manual page enhancement:
On technical view this (hook and option) enables call of ldap_gssapi_bind_s()
at the beginning of ldap_sasl_interactive_bind_s(). If ldap_gssapi_bind_s()
returns with LDAP_SUCCESS the SASL code of ldap_sasl_interactive_bind_s()
will be skipped. In other case ldap_sasl_interactive_bind_s() will be
executed. If this option is switch on and an application makes use
of ldap_sasl_interactive_bind_s() but doesn't know anything about
ldap_gssapi_bind_s() it is able to use GSSAPI signing and encryption.
NOTE(s):
This patch makes patches of
* ITS#6091: missing implementation of "switch off" functionality of GSSAPI
OPTIONS
* ITS#6092: correct string problem in guess_service_principal()
* ITS#6093: correct hostname resolving problem in guess_service_principal()
obsolete.
Thanks to Hallvard B Furuseth for its comments to ITS#6092 which
results in a rewrite of that code snipset.