Alec Thomas wrote:
On 3/27/07, Aaron Richton <richton@nbcs.rutgers.edu> wrote:
You can "push" from syncrepl today. See the list archives and, I believe,
the tests configs.

As I understand it, and other threads confirm, even though syncrepl logically supports a "push" based mechanism, from a network perspective it's a connection from the replica to the master which is not ideal from a DMZ.

That's syncrepl by itself, yes. Using syncrepl in conjunction with back-ldap provides a pure push based mechanism though.

From a previous thread [1], it sounds like 2.4 will support this model
using a hidden proxy database. For 2.3 it sounds like it may be
possible by using the attr keyword to the replica statement. I'll play
with this tomorrow.

[1] http://www.openldap.org/lists/openldap-software/200609/msg00071.html

