Quanah Gibson-Mount wrote:
--On Saturday, April 21, 2007 11:08 PM +0300 Kari Mattsson
> I have this situation at hand, and would like to solve it proper way.
> It appears finding this kind of information on OpenLDAP is hard to come
> Host1 holds master OpenLDAP DIT.
> Host2 holds full syncrepl replicated read-only copy of the same DIT.
> Replication latency should be minimised. 30 seconds is ok, tough.
> Host1's slapd.conf contains lines like:
> overlay syncprov
> syncprov-checkpoint 1 1
> syncprov-sessionlog 100
> Host2's slapd.conf contains line:
> syncrepl rid=10
> type refreshAndPersist
> It seems to work ok, but I don't like the idea of having plain text
> password on the Host2's slapd.conf.
> Any comments on the Host1's values would be valuable.
> Same goes for Host2's values.
> Is SASL the only sensible way to go here, security-wise?
You could use SASL/EXTERNAL (cert auth) certainly... I'll note that
"interval" is not a valid parameter for "refreshAndPersist", I
looking at the "retry" parameter and going back over the documentation.
Yes, thanks. So it seems. I went to the manual page. I wuld like to
note, that there is an somewhat misleading error on page
in the example. On
the explanation below, the text is correct.
On the subject matter, I'll go for SASL. Thanks!