--On Wednesday, September 17, 2003 5:04 PM +1000 Luke Howard <lukeh@PADL.COM> wrote:

You don't need to do this -- the consumer will suck the database from the
provider when it starts up.

I'm not entirely clear from the admin guide if this is true or not. According to the guide, the binddn entry must be present in the replica's DB -- So how can it suck the DB from the provider if it doesn't already have a DB?

"It will bind as "cn=syncuser,dc=example,dc=com" using simple authentication with password "secret". Note that the DN specified by the binddn= directive must be existent in the slave slapd's database or be the rootdn."

Since I'm using GSSAPI here, it isn't going to be the rootdn.

Note that instances of syncConsumerSubentry are named cn=syncreplID rather cn=ldapsync.

Okay, I'll fix that as well.


Should this be GSSAPI? Not sure if it icase-sensitive.

gssapi has worked fine for me so far. ;)


