Nothing related to this except the search result errors.
I tinkered with the limits and got a search to give me returns. I made them massively large (100k). I’ll work on tuning it down, but that looks like it was it. Thanks for the help Rich! What I can’t reconcile is that we have the same limits on the master directories, but those don’t have issues. They must not be receiving anonymous searches on these DNs, or even non-anonymous SEARCHES on them
I guess. They get written to and replicate from them just fine though – I need to understand LDAP better
J.
Now just on to the replication conflict issue, but I do have a ticket with redhat open for that. From: 389-users-bounces@xxxxxxxxxxxxxxxxxxxxxxx [mailto:389-users-bounces@xxxxxxxxxxxxxxxxxxxxxxx]
On Behalf Of Rich Megginson On 01/21/2014 12:59 PM, Colin Tulloch wrote:
Replications were ongoing, but at that time I made no other config changes. From:
389-users-bounces@xxxxxxxxxxxxxxxxxxxxxxx [mailto:389-users-bounces@xxxxxxxxxxxxxxxxxxxxxxx]
On Behalf Of Rich Megginson If the answers given below are not satisfactory, please file tickets for all of these issues at
https://fedorahosted.org/389/newticket. Also, since you appear to be a Red Hat DS customer, please open cases with RH support.
We had some previously mentioned issues running out of file descriptors on our consumers.
After resolving those, we were getting err=11s on searches under that entry, returning nentries=699,700,701. 700 didn’t make sense, but I thought that the issue might be the search limit – these are anonymous,
so I tried the anonlimitsdn setting with a template, and set it higher than 700. That wasn’t it.
We then started getting err=53s searching that entry – we don’t even seem to get the err=11s anymore.
These searches ARE showing up un-indexed. We have indexes for the attributes though
– is it because of the ;binary versions?
Example; [21/Jan/2014:13:32:28 -0500] conn=37952 op=1 SRCH base="ou=Entrust Managed Services SSP CA,ou=Certification Authorities,o=Entrust,c=US" scope=2 filter="(&(|(objectClass=cRLDistributionPoint)(objectClass=pkiCA))(cn=CRL*8))"
attrs="authorityrevocationlist;binary authorityRevocationList certificaterevocationlist;binary certificateRevocationList" [21/Jan/2014:13:32:28 -0500] conn=37952 op=1 RESULT err=53 tag=101 nentries=0 etime=0 notes=U
-- 389 users mailing list 389-users@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/389-users
-- 389 users mailing list 389-users@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/389-users |
-- 389 users mailing list 389-users@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/389-users