Bug 2053204

Summary: Referral mode not working
Product: Red Hat Enterprise Linux 9 Reporter: Akshay Adhikari <aadhikar>
Component: 389-ds-baseAssignee: Simon Pichugin <spichugi>
Status: CLOSED ERRATA QA Contact: LDAP QA Team <idm-ds-qe-bugs>
Severity: high Docs Contact: Evgenia Martynyuk <emartyny>
Priority: high    
Version: 9.0CC: bsmejkal, idm-ds-dev-bugs, mreynolds, pasik, radrao, sgouvern, spichugi, tbordaz, vashirov
Target Milestone: rcKeywords: Triaged
Target Release: 9.3   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: sync-to-jira
Fixed In Version: 389-ds-base-2.3.4-1.el9 Doc Type: Bug Fix
Doc Text:
.Referral mode is now working correctly in Directory Server Previously, CLI set `nsslapd-referral` configuration attribute to the backend and not to the mapping tree. As a result, referral mode did not work. With this update, the `nsslapd-referral` attribute is set correctly and the referral mode works as expected.
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-11-07 08:25:17 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Akshay Adhikari 2022-02-10 16:49:07 UTC
Description of problem:

Referral mode not working and failing with error: ERROR: Error: 103 - 10 - 53 - Server is unwilling to perform - [] -
need to set nsslapd-referral

Version-Release number of selected component (if applicable):


How reproducible:

Every time

Steps to Reproduce:
1. Create two instances

2. Stop the instance on the host you want to redirect:

# systemctl stop dirsrv@instance_name

3. Run ns-slapd in referral mode:

# ns-slapd refer -D /etc/dirsrv/slapd-instance_name [-p port] -r referral_url

4.Even though nsslapd-referral is set:
cn=data_on_1,cn=ldbm database,cn=plugins,cn=config
...
nsslapd-referral: ldap://localhost:38902/ou=people,dc=example,dc=com

Updating the state doesn't work:
# dsconf -v instance1 backend suffix set --state referral
ou=data_on_instance1,dc=example,dc=com
...
ldap.UNWILLING_TO_PERFORM: {'msgtype': 103, 'msgid': 10, 'result': 53,
'desc': 'Server is unwilling to perform', 'ctrls': [], 'info': 'need
to set
 nsslapd-referral before moving to referral state\n'}


Actual results:


Expected results:


Additional info:

https://access.redhat.com/documentation/en-us/red_hat_directory_server/11/html-single/administration_guide/index#Configuring_Directory_Databases-Using_Referrals

Comment 15 Viktor Ashirov 2023-08-04 07:46:10 UTC
Moving to VERIFIED according to comment #11

Comment 19 errata-xmlrpc 2023-11-07 08:25:17 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (389-ds-base bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2023:6350