|
|
#1 |
|
OD network users cannot authenticate
I recently had a lot of errors on two ML servers acting as OD Master/Replica, so decided to reinstall from scratch. One is running OS X 10.8.2, the other 10.8. Both are vanilla installs (going so far as to recreate the RAID), and both have the latest version of server.app installed.
Network users cannot authenticate. Running slapconfig -ver gives the following errors on both machines: Code:
bubbles:~ administrator$ sudo slapconfig -ver
2012-11-27 20:17:31 +0000 command: /usr/libexec/slapd -T cat -c -f /etc/openldap/slapd.conf -s ou=macosxodconfig,cn=config,dc=test249,dc=home
2012-11-27 20:17:31 +0000 Error execing slapcat: 50b51fdb /etc/openldap/slapd_macosxserver.conf: line 303: unknown directive <TLSCertificatePassphrase> inside backend database definition.
slapcat: bad configuration file!
LDAP Setup Tool (slapconfig), Apple, Inc., Version 1.2
Opening slapd_macosxserver.conf shows the last four lines to be: Code:
TLSCertificateFile /etc/certificates/server.mydomain.LONGHASH.cert.pem TLSCACertificateFile /etc/certificates/server.mydomain.LONGHASH.chain.pem TLSCertificateKeyFile /etc/certificates/server.mydomain.LONGHASH.key.pem TLSCertificatePassphrase "Mac OS X Server certificate management.LONGHASH" Code:
bubbles:~ administrator$ sudo slapconfig -ver 2012-11-27 20:43:00 +0000 command: /usr/libexec/slapd -T cat -c -f /etc/openldap/slapd.conf -s ou=macosxodconfig,cn=config,dc=test249,dc=home 2012-11-27 20:43:00 +0000 Error execing slapcat: slapcat: slap_init no backend for "ou=macosxodconfig,cn=config,dc=test249,dc=home" LDAP Setup Tool (slapconfig), Apple, Inc., Version 1.2
__________________
Too much stuff Not enough stuff |
|
|
|
0
|
|
|
#2 |
|
Before you go anywhere, is your DNS configured correctly on both boxes?
Code:
sudo changeip -checkhostname However, you're showing errors in the LDAP configuration. If you absolutely want to change that yourself, at the command line, you're going to need to delve in to LDAP admin. You should hopefully also be able to change it in Server Admin, but you absolutely have to have DNS functioning fully before LDAP or it's just not gonna play ball. |
|
|
|
0
|
|
|
#3 | ||
|
Quote:
Quote:
Which leaves me with the command line. Where should I start looking (I've already tried /etc/openldap/slapd.conf and /etc/openldap/slapd_macosxserver.conf)?
__________________
Too much stuff Not enough stuff |
|||
|
|
0
|
|
|
#4 | ||
|
Quote:
Quote:
|
|||
|
|
0
|
|
|
#5 |
|
Thanks. Is there a primer on this, or a guide to the CLI tools that I should use (slapconfig?)?
__________________
Too much stuff Not enough stuff |
|
|
|
0
|
|
|
#6 | |
|
Quote:
|
||
|
|
0
|
![]() |
|
«
Previous Thread
|
Next Thread
»
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
All times are GMT -5. The time now is 02:32 AM.







Linear Mode
