[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: Replication suddenly broken





--On Thursday, January 16, 2020 9:03 PM +0000 Prentice Bisbal <pbisbal@princeton.edu> wrote:

One of my coworkers just noticed that replication is broken between our
primary and secondary LDAP servers. It appears to have been broken for
about 1 week now. Nothing has changed relative to the LDAP configuration
on either of our servers, so this is an odd thing to suddenly happen.
When I look at the consumer with some debugging on, I see these messages
(/usr/sbin/slapd -d 1638 was used to get these messages):

It looks like the consumer
host/voltron-b.pppl.gov,cn=pppl.gov,cn=gssapi,cn=auth,is being rejected
as not being authorized, but this has been working for years w/o issue.
Any idea what has changed and how I may fix it?


Well, the error came from cyrus-sasl rather than OpenLDAP. This would indicate to me that the not authorized came from the KDC. Have you checked to ensure the keys in the keytab file haven't expired inside the KDC?

Regards,
Quanah


--

Quanah Gibson-Mount
Product Architect
Symas Corporation
Packaged, certified, and supported LDAP solutions powered by OpenLDAP:
<http://www.symas.com>