I know about the replication agreements, cn=replication manager, and all that, but...
In the process of moving my old instances to 2.5, I decided to use lib389 as much as possible to script my replicas, replication agreements, replication accounts, etc. lib389, as far as I can tell, only creates replication service accounts in ou=Services. As
such, I assumed that the old system, where everything was in cn=config, was no longer the recommendation. It seems to me that having the replication accounts in an OU makes them susceptible to password polices, which I do believe was causing the issues I was
seeing. If you're saying that having it all in cn=config is still fine, I will happily revert to that.
On subtree policies, if that's the expected behavior of dsconf, which I find rather unhelpful to be honest, then it's all good. It just feels like there out to be something in the system that you can point at any given ou and ask "what's the policy that's active
on this ou?"
Tim Darby
From: Mark Reynolds <mareynol@xxxxxxxxxx>
Sent: Monday, August 26, 2024 12:13 To: General discussion list for the 389 Directory server project. <389-users@xxxxxxxxxxxxxxxxxxxxxxx>; Darby, Tim - (tdarby) <tdarby@xxxxxxxxxxx> Subject: Re: [389-users] Re: [EXT] Re: Password policies and replication service accounts External Email
On 8/26/24 1:18 PM, Darby, Tim - (tdarby) wrote:
I was referring to the entry you use in the replication agreement (typically cn=replication manager, cn=config):
Supplier:
dn: cn=replication manager,cn=config dn: cn=darby,cn=replica,cn=dc\3Dexample\2Cdc\3Dcom,cn=mapping tree,cn=config
On the consumer side you must specify the bind that that can perform replication updates in the replica configuration entry:
dn: cn=replica,cn=dc\3Dexample\2Cdc\3Dcom,cn=mapping tree,cn=config ... ...
Right, so anything under "ou=accounts,ou=etc" should have that local policy applied to it. It will only be listed under the the original subtree. So this all looks correct. Please provide your password policy settings and describe how it's not working as you expect:
# dsconf slapd-INSTANCE localpwp get "ou=accounts,ou=etc"
Thanks,
-- Identity Management Development Team |
-- _______________________________________________ 389-users mailing list -- 389-users@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to 389-users-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/389-users@xxxxxxxxxxxxxxxxxxxxxxx Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue