Strange behaviour - SAMBA is writing on a Dedicated Consumer Server

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Diretorio Livre wrote:
> Hello,
> We are using FDS 1.2.0 and we are making samba integration with LDAP. 
> There are two FDS servers, one (serverA) is configured as single 
> master and the other (serverB) as a dedicated consumer. We're using 
> the option "ldap passwd sync=yes" and pointing the ldapsam to serverB. 
> When we changed the password of a user (in a Windows machine), his 
> "userpassword" ldap attribute has changed in serverB(the dedicated 
> consumer) instead of return referral to serverA (the master). The most 
> strange is that the access log doesn't show nothing, even the correct 
> error code 10 (referral). We've checked the suffix configuration in 
> the serverB and the "update on referral" was selected. It seems to us 
> that SAMBA found a way to ignore the "update on referral" and made the 
> modifications on the consumer. //Anybody has experiencied such behaviour?
Note that the access log is buffered, so operations may take a while 
before they are flushed to disk.  You can change this behavior by 
setting nsslapd-accesslog-logbuffering: off in cn=config (but note that 
this may impact performance in production environments).

Can you post relevant excerpts from the access log of the dedicated 
consumer showing the sequence of operations for the password change?  
Have you checked the access log of the master?
>
> Steps to reproduce the behaviour
> - Configure two LDAP servers (one as single master and the other as 
> dedicated consumer).
> - Configure replication between the two servers above.
> - Install SAMBA (we are using version 3.3.2 or 3.4.7).
> - Configure smb.conf with the following parameters:
>    -- the ldapbackend pointing to the dedicated consumer server.
>    -- ldap passwd sync=Only.
>    -- ldap ssl = start tls (it's necessary).
>  
>
> Thanks in advance,
> -- 
> SIEDN - Diretorio Livre
> "Esta mensagem do SERVI?O FEDERAL DE PROCESSAMENTO DE DADOS (SERPRO), empresa p?blica federal regida pelo disposto na Lei Federal n? 5.615, ? enviada exclusivamente a seu destinat?rio e pode conter informa??es confidenciais, protegidas por sigilo profissional. Sua utiliza??o desautorizada ? ilegal e sujeita o infrator ?s penas da lei. Se voc? a recebeu indevidamente, queira, por gentileza, reenvi?-la ao emitente, esclarecendo o equ?voco."
>
> "This message from SERVI?O FEDERAL DE PROCESSAMENTO DE DADOS (SERPRO) -- a government company established under Brazilian law (5.615/70) -- is directed exclusively to its addressee and may contain confidential data, protected under professional secrecy rules. Its unauthorized use is illegal and may subject the transgressor to the law's penalties. If you're not the addressee, please send it back, elucidating the failure."
>
> ------------------------------------------------------------------------
>
> --
> 389 users mailing list
> 389-users at lists.fedoraproject.org
> https://admin.fedoraproject.org/mailman/listinfo/389-users



[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux