Bug 2170494
| Summary: | Obsolete nsslapd-ldapimaprootdn attribute | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 9 | Reporter: | Viktor Ashirov <vashirov> |
| Component: | 389-ds-base | Assignee: | Simon Pichugin <spichugi> |
| Status: | VERIFIED --- | QA Contact: | LDAP QA Team <idm-ds-qe-bugs> |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | 9.2 | CC: | bsmejkal, idm-ds-dev-bugs, mreynolds, spichugi |
| Target Milestone: | rc | Keywords: | Triaged |
| Target Release: | 9.3 | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | sync-to-jira | ||
| Fixed In Version: | 389-ds-base-2.3.4-1.el9 | Doc Type: | If docs needed, set a value |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | Bug | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Viktor Ashirov
2023-02-16 14:22:14 UTC
Build tested: 389-ds-base-2.3.4-2.el9.x86_64 [1] dsconf changes only nsslapd-rootdn when RootDN is updated (previously both nsslapd-rootdn and nsslapd-ldapimaprootdn were changed): # dsconf -D cn=Directory\ Manager ldap://localhost config replace nsslapd-rootdn="cn=admin" Enter password for cn=Directory Manager on ldap://localhost: Successfully replaced "nsslapd-rootdn" [2] When nsslapd-ldapimaprootdn is updated, dsconf logs a message: # dsconf -D cn=Directory\ Manager ldap://localhost config replace nsslapd-ldapimaprootdn="cn=admin" Enter password for cn=Directory Manager on ldap://localhost: Successfully replaced "nsslapd-ldapimaprootdn" The "nsslapd-ldapimaprootdn" setting is obsolete and kept for compatibility reasons. For LDAPI configuration, "nsslapd-rootdn" is used instead And in the errors log: [28/Jul/2023:03:54:30.718130078 -0400] - WARN - config_set_ldapi_root_dn - The "nsslapd-ldapimaprootdn" setting is obsolete and kept for compatibility reasons. For LDAPI configuration, "nsslapd-rootdn" is used instead. In cn=config new value is also present: # ldapsearch -LLL -D cn=Directory\ Manager -w password -H ldap://localhost -s base -b cn=config nsslapd-rootdn nsslapd-ldapimaprootdn dn: cn=config nsslapd-rootdn: cn=Directory Manager nsslapd-ldapimaprootdn: cn=admin And autobind continues to work, since nsslapd-rootdn is now used, instead of nsslapd-ldapimaprootdn # dsconf localhost backend suffix list dc=example,dc=com (userroot) # echo $? 0 [28/Jul/2023:04:08:03.981381558 -0400] conn=14 fd=64 slot=64 connection from local to /run/slapd-localhost.socket [28/Jul/2023:04:08:03.985945222 -0400] conn=14 AUTOBIND dn="cn=Directory Manager" [28/Jul/2023:04:08:03.987695893 -0400] conn=14 op=0 BIND dn="cn=Directory Manager" method=sasl version=3 mech=EXTERNAL Marking as Verified:Tested |