Hi all,
There is an
issue when I try to communicate between 389ds and windows AD.
CentOS 7.4 (389ds
server)
389-ds-base-1.3.6.1-16.el7.x86_64
Windows 2008R2 (AD
DC)
389-PassSync-1.1.7-x86_64
06/01/18 08:54:21:
PassSync service initialized
06/01/18 08:54:21:
PassSync service running
06/01/18 08:54:21:
dataFilename is C:\Windows\System32\passhook.dat
06/01/18 08:54:21: No
entries yet
06/01/18 08:54:21:
Ldap bind error in Connect
34: Invalid DN syntax
06/01/18 08:54:21:
Password list is empty. Waiting for passhook event
06/01/18 10:01:57:
Received passhook event. Attempting sync
06/01/18 10:01:57: 1
new entries loaded from data file
06/01/18 10:01:57:
Cleared contents of data file
06/01/18 10:01:57:
Password list has 1 entries
06/01/18 10:01:57:
Ldap bind error in Connect
34: Invalid DN syntax
06/01/18 10:01:57:
Attempting to sync password for ad_bind
06/01/18 10:01:57:
Searching for (ntuserdomainid=ad_bind)
06/01/18 10:01:57:
There are no entries that match: ad_bind
06/01/18 10:01:57:
Deferring password change for ad_bind
06/01/18 10:01:57:
Backing off for 2000ms
06/01/18 10:01:59:
Backoff time expired. Attempting sync
06/01/18 10:01:59:
Password list has 1 entries
06/01/18 10:01:59:
Ldap bind error in Connect
34: Invalid DN syntax
06/01/18 10:01:59:
Attempting to sync password for ad_bind
06/01/18 10:01:59:
Searching for (ntuserdomainid=ad_bind)
06/01/18 10:01:59:
There are no entries that match: ad_bind
06/01/18 10:01:59:
Deferring password change for ad_bind
06/01/18 10:01:59:
Backing off for 4000ms
What I want is that
sync password from windows AD to 389ds(one way), no any other
data.
Could you please
provide some advice?
I think this can only happen after a user changes their password on
AD -> then its syncs to DS. There is no way to extract passwords
from AD.