Bug 889083 - For modifiersName/internalModifiersName feature, internalModifiersname is not working for DNA plugin
Summary: For modifiersName/internalModifiersName feature, internalModifiersname is not...
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: 389-ds-base
Version: 6.4
Hardware: All
OS: All
Target Milestone: rc
: 6.4
Assignee: Rich Megginson
QA Contact: Sankar Ramalingam
Depends On:
Blocks: 895654
TreeView+ depends on / blocked
Reported: 2012-12-20 07:46 UTC by Amita Sharma
Modified: 2020-09-13 20:19 UTC (History)
5 users (show)

Fixed In Version: 389-ds-base-
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2013-02-21 08:21:52 UTC
Target Upstream Version:

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Github 389ds 389-ds-base issues 495 0 None None None 2020-09-13 20:19:06 UTC
Red Hat Product Errata RHSA-2013:0503 0 normal SHIPPED_LIVE Moderate: 389-ds-base security, bug fix, and enhancement update 2013-02-21 08:18:44 UTC

Description Amita Sharma 2012-12-20 07:46:16 UTC
Description of problem:
For modifiersName/internalModifiersName feature, internalModifiersname is not 

The internalModifersname or internalCreatorsname is NOT supposed to be a 
bind DN, like "cn=directory manager", but either the DNA plugin or the 
the ldbm database plugin.

But we are seeing "cn=directory manager" for internalModifersname in DNA plugin.

/usr/lib64/mozldap/ldapsearch -1 -h dhcp201-134.englab.pnq.redhat.com -p 7512 -D "cn=directory manager" -w Secret123 -b uid=amsharma1,dc=example,dc=com objectClass=* internalModifiersname
dn: uid=amsharma1,dc=example,dc=com
internalModifiersname: cn=directory manager

So this is a bug.

Comment 1 RHEL Program Management 2012-12-24 06:47:09 UTC
This request was not resolved in time for the current release.
Red Hat invites you to ask your support representative to
propose this request, if still desired, for consideration in
the next release of Red Hat Enterprise Linux.

Comment 4 Nathan Kinder 2013-01-08 18:41:28 UTC
Upstream ticket:

Comment 6 Amita Sharma 2013-01-28 12:22:02 UTC
grep the internalModifiersname in the user entry
/usr/lib64/mozldap/ldapsearch -1 -T -h dell-pe2800-01.rhts.eng.bos.redhat.com -p 8086 -D cn=directory manager -w Secret123 -b cn=Posix User1,dc=example,dc=com objectClass=* internalModifiersname | grep -i cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config
internalModifiersname: cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config
internalModifiersname is plugin DN

cn=ldbm  database,cn=plugins,cn=config is the expected result when a plugin does  not interfere.  Since no plugins add entries, this is the value that  should always be expected for internalCreatorsname.
The internalModifersname and internalCreatorsname are always going to be plugin names.  They will never be bind DN's.

Comment 7 errata-xmlrpc 2013-02-21 08:21:52 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.