[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: deploying password policy module



Michael Ströder wrote:
> Paul B. Henson wrote:
>>> From: Michael Ströder
>>> Sent: Tuesday, April 29, 2014 12:50 PM
>>>
>>> AFAICS nothing prevents you from loading the schema first on all replicas.
>>> And after that load the overlay.
>>
>> The attribute in question is not defined in the external schema, in fact, it
>> is commented out:
> 
> Ah, sorry. Missed that.

Nope. I did not miss anything.
I tried to reproduce your problem in a simple MMR testbed.

If just add "moduleload ppolicy" to your slapd.conf (or similar action for
back-config) the subschema will contain attribute type description for
'pwdFailureTime' from slapo-accesslog. So you should do this first on all
replicas, one after the other, without adding "overlay ppolicy" to the
database section.

In a second step you have to add "overlay ppolicy" to the database section on
all replicas, also one after the other. The replication will catch up even
though some prior modifications might have failed in the past.

Ciao, Michael.


Attachment: smime.p7s
Description: S/MIME Cryptographic Signature