Replication credentials issue

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Kyle Tucker wrote:
>> I stopped the service, edited the password in clear in userPassword
>> field, reinput the password on the master and same errors. The error
>> from the initialize consumer action is:
>>     
>
> For grins, I stopped the master as well, edited its dse.ldif and
> changed it to clear (it was in DES method) and voila - it all took
> off and synched up. I checked my working test master and consumer
> and they were in DES and SSHA respectively, again always working
> from the onset. I'll leave it to the developers to take anything from
> this. Thanks for the pointer to dse.ldif.
>   
The consumer should have the cn=Repl Manager user with userPassword as 
an SSHA hash (or some other secure hash), not cleartext.  The supplier 
should store the repl manager credentials with the {DES} reversible 
password encryption type so that it can send the clear text password to 
the consumer in the BIND request (as is done in the normal LDAP simple 
BIND request).  You can always test this by using the ldapsearch command 
line tool to attempt to bind using -D "cn=replication manager,cn=config" 
and the password to the consumer to test the bind and credentials.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3178 bytes
Desc: S/MIME Cryptographic Signature
Url : http://lists.fedoraproject.org/pipermail/389-users/attachments/20061127/02131643/attachment.bin 


[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux