Password replication problems between a multi-master system and AD

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



I am using RHDS instead of FD, so if this issue has been addressed in FD please 
forgive me.

To exemplify the issues I'll use the model:
AD <-> RHDS1 <-> RHDS2.

Only one master is setup to sync to AD, which is the standard setup.  Since 
password sync uses clear text to replicate to AD, password changes  on RHDS2 
will not propagate correctly to AD.  RHDS2 sends the hash to RHDS1 which in turn 
sends it to AD.  AD assumes the hash to be the actual clear text pw and attempts 
to use it to login to RHDS1.  This creates a loop where one server keeps sending 
what it believes to be the new password to the other.
I _think_ that if I add a replication agreement between RHDS2 and AD it will not 
fix my problem as even if RHDS2 sends the password ok to AD, RHDS1 will still 
try to send the update it received from RHDS2.  Is this assumption correct?
What is the best course of action?  How can I tell if a password update is done 
on the server or pushed thru replication?
-------------- next part --------------
An embedded message was scrubbed...
From: Alexandre Augusto da Rocha <augusto.rocha at augustschell.com>
Subject: Password replication problems between a multi-master system and AD
Date: Mon, 19 Mar 2007 19:23:17 -0500
Size: 8047
Url: http://lists.fedoraproject.org/pipermail/389-users/attachments/20070319/2e9f89f4/attachment.mht 


[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux