--On Wednesday, August 30, 2017 9:21 AM -0700 Quanah Gibson-Mount quanah@symas.com wrote:
--On Wednesday, August 30, 2017 2:49 PM +0800 Chris Leung chris@q-station.net wrote:
Sometime, the user password is replicated without problem after switched to REFRESH, however, sometime password can't be sync.
Error 16 means "no such attribute exists". My guess would be you have ACLs that block your replica from replicating userPassword. I'd also guess that you originally loaded the replica via a slapcat of the other master, so some accounts have passwords, and others don't. This is all guesswork of course, but it would match the behavior you're seeing.
Also, I would confirm that you have identical overlay configurations between the two masters. It sounds like on has ppolicy and perhaps the other one doesn't? Also be sure and read the ppolicy manpage closely on replication behavior.
--Quanah
--
Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: http://www.symas.com