Hello,
I'm working on the same project as Meheni.
Thanks for your answer, we'll try version 2.6 OpenLDAP using the
lastbind-precision.
However we have several questions for the current version we're using.
Is this a known problem and referenced somewhere? (we haven't found it)
Is it normal to find no replication error logs even in stats + sync mode?
We ran some tests in sequential mode (300,000 accounts one after the other)
and managed to reproduce the problem.
-Denis
Le mer. 11 …
[View More]oct. 2023 à 14:11, Quanah Gibson-Mount <quanah(a)fast-mail.org> a
écrit :
>
>
> --On Tuesday, October 10, 2023 9:30 PM +0200 Ziani Meheni
> <mehani06(a)gmail.com> wrote:
>
> >
> >
> > Hello, we are working on a project and we've come across a problem with
> > the replication after performance testing :
>
> You need to use OpenLDAP 2.6 and then set the:
>
> lastbind-precision
>
> value. I use 5 minutes.
>
> --Quanah
>
[View Less]
Hi there,
Two years ago I sent an announcement mentioning that the OpenLDAP 2.5.x
series was accepted for a Micro Release Exception in Ubuntu Jammy
(20.04). This meant that I'd be able to release any updates to the
2.5.x series on Jammy, which I have been doing since then.
We are now getting ready to work on the next Ubuntu LTS release, which
will come out next April. I seem to remember upstream discussions
mentioning that the next OpenLDAP LTS release would likely be the 2.7.x
series, but …
[View More]I don't remember seeing anything else about it. Are there
any plans to start working on the OpenLDAP LTS major series?
Thanks a lot,
--
Sergio
GPG key ID: E92F D0B3 6B14 F1F4 D8E0 EB2F 106D A1C8 C3CB BF14
[View Less]
Hi there!
We are working on a new installation and decided to try something new..
In the past I would have gone with multi-master with ldap balancer but
after reading and researching more and more on MDB, we decided to try to
integrate OpenLDAP into our current CI/CD pipelines using K8s.
What we tried so far and it seems to work is initialize a common
persistence storage and then an auto scaling group that shares that common
drive. Ech pod has as many threads as virtual CPU it may have, and …
[View More]none of
the pods can write, except a dedicated write pod (single instance) with
multiple threads for writing.
Is there anything else we are missing here? Any experience scaling OpenLDAP
with Kubernetes or other container technology.
Thank you in advance for any comments, pointers or recommendations!
--
Alex
[View Less]
Airbus Amber
Dear all,
basically I trying to establish a syncrepl/refreshAndpersist Setup between:
OpenLDAP: 2.4.57.0.1 @ Solaris < - > OpenLDAP: 2.6.2-3 @ Rhel 9.latest
(don`t ask)
An intial syncrepl activation does works properly (replication of ou`s content in both directions), but when I afterwards restart one of the replication Partners, the
sync failes and in consequence on one of replication Partner the ou`s are deleted.
From logging point of view there are somekind of issues to …
[View More]identify the remote object via the UUID which leads then to the deletion:
##schnipp
6538d3db.38892890 0x7f9fe65fe640 nonpresent_callback: rid=044 nonpresent UUID 25a0c72c-0364-103e-83af-fb52f2a7ef64, dn ou=permissions,dc=xxx,dc=xxxx,dc=xxxxxx
6538d3db.388983a6 0x7f9fe65fe640 nonpresent_callback: rid=044 adding entry ou=permissions,dc=xxxx,dc=xxxxx,dc=xxxx to non-present list
###schnapp
Unfortunately I cannot find any Information which says something useful about the basic backward compatibility of the synrepl/refreshAndPersist implementation from 2.6 to 2.4.
Can someone state why this mission is hopeless in detail or should the setup work basically ?
(I know the best practice : everywhere same versions...)
Best regards and thanks in advance,
michael
This Item has been reviewed and was determined as not listed under German regulation, nor EU export controls, nor U.S. export controls. However, in the case of the item has to be resold, transferred, or otherwise disposed of to an embargoed country, to an end user of concern or in support of a prohibited end use, you may be required to obtain an export license.
The information in this e-mail is confidential. The contents may not be disclosed or used by anyone other than the addressee. Access to this e-mail by anyone else is unauthorised.
If you are not the intended recipient, please notify Airbus immediately and delete this e-mail.
Airbus cannot accept any responsibility for the accuracy or completeness of this e-mail as it has been sent over public networks. If you have any concerns over the content of this message or its Accuracy or Integrity, please contact Airbus immediately.
All outgoing e-mails from Airbus are checked using regularly updated virus scanning software but you should take whatever measures you deem to be appropriate to ensure that this message and any attachments are virus free.
[View Less]
Hello,
We have a strange situation with refint and rwm overlays on ldap replica.
Looks like those overlays depend on each other and on position in the
slapd.conf file regarding database section. However refint overlay is
working in any position if rwm overlay is not specified. Here are the
examples with positions in the file:
Refint overlay work if:
1.
rwm overlay section
database section
refint overlay section
Refint overlay does not work if:
1.
database section
refint …
[View More]overlay section
rwm overlay section
2.
rwm overlay section
refint overlay section
database section
Could you please explain to us the root cause of that as I can't find any
explanation in the docs.
--------
Maksim Saroka
DevOps/System Administrator
Exadel.com <https://exadel.com/>
Follow Us on LinkedIn <https://www.linkedin.com/company/exadel/>
--
CONFIDENTIALITY
NOTICE: This email and files attached to it are
confidential. If you
are not the intended recipient you are hereby notified
that using,
copying, distributing or taking any action in reliance on the
contents of this information is strictly prohibited. If you have
received
this email in error please notify the sender and delete this
email.
[View Less]
Hi,
I am trying to force users to change their password at first login or
after
password reset by administrator.
Tried following:
1)Password policy 'pwdMustChange TRUE' doesn't seems to be working as non
of the
users get prompt to change their password at first login.
2) used the 'pwdReset TRUE' attribute in users attributes, and it won't
prompt
to change the password and didn't allow to login
i observe below messages in log
"slapd[12684]: connection restricted to password changing only
…
[View More]slapd[12684]: send_ldap_result: err=50 matched="" text="Operations are
restricted to bind/unbind/abandon/StartTLS/modify password"
slapd[12684]: conn=1053 op=1 SEARCH RESULT tag=101 err=50 nentries=0
text=Operations are restricted to bind/unbind/abandon/StartTLS/modify
password"
Please help me configure the option to force all users to change their
password
at first login or after pwd reset by administrator.
Thanks & Regards
Raj
Tata Consultancy Services
Mailto: rajagopal.rc(a)tcs.com
Website: http://www.tcs.com
____________________________________________
Experience certainty. IT Services
Business Solutions
Consulting
____________________________________________
=====-----=====-----=====
Notice: The information contained in this e-mail
message and/or attachments to it may contain
confidential or privileged information. If you are
not the intended recipient, any dissemination, use,
review, distribution, printing or copying of the
information contained in this e-mail message
and/or attachments to it are strictly prohibited. If
you have received this communication in error,
please notify us by reply e-mail or telephone and
immediately and permanently delete the message
and any attachments. Thank you
[View Less]
On Fri, Oct 27, 2023 at 5:58 PM Quanah Gibson-Mount <quanah(a)fast-mail.org>
wrote:
>
>
> --On Friday, October 27, 2023 10:51 AM +0200 Alejandro Imass
> <aimass(a)yabarana.com> wrote:
>
> > Again for future people reading this, if you encounter ACL issues and you
> > want to modify the LDIF database in /etc/openldap/slapd.d don't do it
> > manually.
>
> Your advice here is generally wrong.
>
>
You mean they SHOULD edit them manually ?
I'…
[View More]m actually suggesting to use slapadd and slapmodify directly on the
filesystem if everything else fails.
What's wrong with that suggestion?
>
[View Less]
On Thu, Oct 26, 2023 at 11:13 PM Quanah Gibson-Mount <quanah(a)fast-mail.org>
wrote:
>
>
> --On Thu> Try the following (and replace with the correct URL):
> >
> > $ ldifmodify -x -H ldap://localhost/ -D cn=config -W << EOF
> > > dn: olcDatabase={0}config,cn=config
> > > changetype: modify
> > > add: olcRootPW
> > > olcRootPW: {SSHA}cZbRoOhRew8MBiWGSEOiFX0XqbAQwXUr
> > > EOF
>
> There doesn't appear to …
[View More]be an old olcRootPW value either, so that wouldn't
> work.
>
>
Thanks for your response.
There actually is one in dn: olcDatabase={1}mdb,cn=config
Anyway I solved my issue and was able to modify the config DB using
slapadd and slapmodify directly on the filesystem as root and that is that.
Thanks again for your help!
--
Alex
[View Less]
--On Tuesday, October 24, 2023 10:01 AM +0200 Óscar Remírez de Ganuza
Satrústegui <oscarrdg(a)unav.edu> wrote:
> What architecture would you suggest for implementing lastbind?
> Is it better to use a Master-Slave with the chain overlay to send the
> lastbind writes from the slave to the master?
If you want the value to have general meaning for most deployments, yes.
Generally I'd go with Multi-provider replication in a active/passive
configuration, with some number of read …
[View More]only consumer nodes, where the read
only nodes forward their updates to the active provider.
--Quanah
[View Less]