Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

DS 4.11 with Solaris Extension 4.1

1 view
Skip to first unread message

Luc Vigeant

unread,
Nov 13, 2000, 3:00:00 AM11/13/00
to
Product & Version: Directory 4.11

Hardware Platform & OS Version: Sun Solaris 2.6

Summary Description: modifies a user on the master it roll back to all
the default settings on slave

I modify a user entri on my Solaris NIS master, And on the Solaris Slave
run
with Iplanet Directory Server 4.11 and the Iplanet Solaris Extension
server 4.1
the user was recreate has a default user in the LDAP Database, so that
delete
all the others attributes for this user.

Do you know solution for this problem?


Olivier Hussenet

unread,
Nov 15, 2000, 3:00:00 AM11/15/00
to
When you use the solaris extensions to LDAP, you must define a (new) NIS
master that will itself be mastered by the Directory Server:
if your NIS is a slave, it will be updated by its NIS master, and the
LDAP/NIS synchronization will then update your directory with information
coming from that remote NIS master.
(see the NIS extensions docs at page 26).

Luc Vigeant a écrit :

hussenet.olivier.vcf

Luc Vigeant

unread,
Nov 15, 2000, 3:00:00 AM11/15/00
to
Yes i agree with this but
If you add a Description for the user ABC with the Netscape Directory
Server
and you change the password of the ABC user on unix at the command line.
The synchronization will over write the Description with a blank
Description for the
user ABC.

--
Luc Vigeant mailto:lvig...@research.cantel.rogers.com
Systems Analyst - OSS

Rogers AT&T tel.: (514) 345-6800 ext. 6131
2056 32nd avenue fax.: (514) 340-7470
Lachine (Quebec) cell.: (514) 983-0995
H8T 3H7

Luc Vigeant

unread,
Nov 15, 2000, 3:00:00 AM11/15/00
to

Jean Henchey

unread,
Nov 16, 2000, 3:00:00 AM11/16/00
to Luc Vigeant, Olivier Hussenet
I'm having a problem with this too. The iplanet documentation isn't
clear about where to make changes. Also, how changes are made becomes
important..for example, dsypsync won't rewrite the NIS source files (NIS
pdf, Chapter 1, page 23.). So, if I use a yppasswd, does it write
changes to the map file, directly, or does it write changes to the map
loaded into memory, or does yppasswd write changes to the directory?

The other problem is that once I make userpassword changes in the
directory, a ypcat reveals the (encoded/encrypted) password field. I
have a passwd.adjunct file that stopped NIS from printing the password
field...so....what's going on with the LDAPized NIS? Hmm..

And, after I make a userpassword change in the directory, I can't seem
to login (via NIS) with that new password.

Jean

jeannie.vcf

Luc Vigeant

unread,
Nov 20, 2000, 3:00:00 AM11/20/00
to Jean Henchey
If you use the yppasswd the NIS source file will be change and the
information
will be push to all the yp slave ( including the LDAP server if they are
acting has a slave server.)

Jean Henchey

unread,
Dec 1, 2000, 3:00:00 AM12/1/00
to Jean Henchey
I finally spoke with a manager at Iplanet a couple of days ago.
Here are some points of the converation you might find interesting.

- NIS Extensions were written by Sun but not in the States.
- Iplanet makes NIS Extensions available but nobody in tech support
understands NIS or NIS Extensions.
- There is no contract between Iplanet and Sun for NIS Extensions
support.

If you look closely at the Solaris 8 documentation at sun.com, although
Iplanet Directory and NIS Extensions are included with the OS, Sun
clearly
states they're not contractually obligated to support the Iplanet
software.

I finally gotten the truth from tech support, 5 weeks after opening the
work order, with Silver support. This greatly shakes my faith in
Iplanet
tech support and its products.

If anyone else has had a more positive experience, I'd be interested to
see it.

Jean

jeannie.vcf

Evan Montgomery-Recht

unread,
Dec 4, 2000, 3:00:00 AM12/4/00
to
Have you checked out any of the stuff from www.padl.com, appearently some of there
stuff conforms more closely to RFC 2307.

evan

Jean Henchey

unread,
Dec 5, 2000, 3:00:00 AM12/5/00
to
Yes, but I was looking for more integration than what padl offered.

The more important question from my point of view is about Sun's
direction with directory services integration.

jeannie.vcf

Luc Vigeant

unread,
Dec 7, 2000, 3:00:00 AM12/7/00
to Jean Henchey
I still searching for product like Solaris Extension
but i did not found any thing.

But with the Meta-Directory of CriticalPath ( www.cp.net ) call InJoin
according to the documentation we are able to manager all the users
NIS,NIS+,NT,DB users and other mail server in one LDAP server.

The InJoin is available now only on NT, but we are able to query on
Solaris. The Version on solaris is on is way ...

For Sun direction in Solaris 8 we have the possibility to add a new
services call LDAP how are connecting the information on LDAP.
You can have more detail in the book coming soon call "Solaris and LDAP
Naming Services: ISBN:0-13-030678-9"
But is it working with NIS,NIS+? I do not know.

John Kevin O'Shaughnessy

unread,
Dec 7, 2000, 3:00:00 AM12/7/00
to
I'll look into this as well. Hopefully one of us can resolve the problem with this
plugin, though. It seems like such a simple problem to fix. If there's not a simple
value-change somewhere, I will consider it a serious bug in the software. Thanks for the
update.

</k>

0 new messages