<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Active Directory and 389 Directory Server Sync Howto</title>
	<atom:link href="http://www.linuxmail.info/ad-fds-sync-howto/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.linuxmail.info/ad-fds-sync-howto/</link>
	<description>Rapidly deploy Linux based mail solutions today</description>
	<lastBuildDate>Sat, 12 Sep 2009 22:40:43 -0400</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Prashanth</title>
		<link>http://www.linuxmail.info/ad-fds-sync-howto/#comment-3761</link>
		<dc:creator>Prashanth</dc:creator>
		<pubDate>Tue, 14 Jul 2009 18:25:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.linuxmail.info/?p=173#comment-3761</guid>
		<description>I would like to build a system where the FDS authentication is delegated to Active Directory. I do not want the password to be stored in FDS or Synced using PassSync.msi.

I am asking the community if anyone has come this way? I am trying to put together the pieces of this puzzle with PAM, Pass-through Authentication, Winbind, Windows ADAM and ADFS, Samba etc.</description>
		<content:encoded><![CDATA[<p>I would like to build a system where the FDS authentication is delegated to Active Directory. I do not want the password to be stored in FDS or Synced using PassSync.msi.</p>
<p>I am asking the community if anyone has come this way? I am trying to put together the pieces of this puzzle with PAM, Pass-through Authentication, Winbind, Windows ADAM and ADFS, Samba etc.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: zette</title>
		<link>http://www.linuxmail.info/ad-fds-sync-howto/#comment-3758</link>
		<dc:creator>zette</dc:creator>
		<pubDate>Mon, 13 Jul 2009 09:22:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.linuxmail.info/?p=173#comment-3758</guid>
		<description>Hi

I&#039;ve got same error as Patric and arne: “LDAP error: invalid credentials. Error Code: 49?.

Did You find any solution to this? I&#039;ve tripple rechecked all accounts credentials, and those are fine.</description>
		<content:encoded><![CDATA[<p>Hi</p>
<p>I&#8217;ve got same error as Patric and arne: “LDAP error: invalid credentials. Error Code: 49?.</p>
<p>Did You find any solution to this? I&#8217;ve tripple rechecked all accounts credentials, and those are fine.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: consultant</title>
		<link>http://www.linuxmail.info/ad-fds-sync-howto/#comment-3713</link>
		<dc:creator>consultant</dc:creator>
		<pubDate>Wed, 10 Jun 2009 17:14:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.linuxmail.info/?p=173#comment-3713</guid>
		<description>Hi mintra,

What error message are you getting and where are you getting it?</description>
		<content:encoded><![CDATA[<p>Hi mintra,</p>
<p>What error message are you getting and where are you getting it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mintra</title>
		<link>http://www.linuxmail.info/ad-fds-sync-howto/#comment-3712</link>
		<dc:creator>mintra</dc:creator>
		<pubDate>Wed, 10 Jun 2009 15:57:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.linuxmail.info/?p=173#comment-3712</guid>
		<description>I get this message and i take on board that it means what it says. Also I am clear that the their are two systems requiring credentials. Which one is the error refering to Active directory or FDS?</description>
		<content:encoded><![CDATA[<p>I get this message and i take on board that it means what it says. Also I am clear that the their are two systems requiring credentials. Which one is the error refering to Active directory or FDS?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: arne</title>
		<link>http://www.linuxmail.info/ad-fds-sync-howto/#comment-3612</link>
		<dc:creator>arne</dc:creator>
		<pubDate>Mon, 20 Apr 2009 14:18:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.linuxmail.info/?p=173#comment-3612</guid>
		<description>Hi consultant,

syncadm does not have a blank password. I have given a password to him at creation time. Moreover I have checked this particular password when I logged in with this credentials to the Windows desktop.

It seems as if it is working with the certificate but not with the password. 
Another strange effect is: when I check the checkbox &quot;Check hostname against name in certificate for outbound connections&quot; the error changes into &quot;81 - LDAP error: Can&#039;t contact LDAP server&quot;. It is weired as they are in the same subnet and no firewall etc. is in between...</description>
		<content:encoded><![CDATA[<p>Hi consultant,</p>
<p>syncadm does not have a blank password. I have given a password to him at creation time. Moreover I have checked this particular password when I logged in with this credentials to the Windows desktop.</p>
<p>It seems as if it is working with the certificate but not with the password.<br />
Another strange effect is: when I check the checkbox &#8220;Check hostname against name in certificate for outbound connections&#8221; the error changes into &#8220;81 &#8211; LDAP error: Can&#8217;t contact LDAP server&#8221;. It is weired as they are in the same subnet and no firewall etc. is in between&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: consultant</title>
		<link>http://www.linuxmail.info/ad-fds-sync-howto/#comment-3608</link>
		<dc:creator>consultant</dc:creator>
		<pubDate>Fri, 17 Apr 2009 14:34:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.linuxmail.info/?p=173#comment-3608</guid>
		<description>Hi arne,

It means what it says, the credential is invalid. Not specifying a password to syncadm works because syncadm has a blank password.</description>
		<content:encoded><![CDATA[<p>Hi arne,</p>
<p>It means what it says, the credential is invalid. Not specifying a password to syncadm works because syncadm has a blank password.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrick</title>
		<link>http://www.linuxmail.info/ad-fds-sync-howto/#comment-3604</link>
		<dc:creator>Patrick</dc:creator>
		<pubDate>Thu, 16 Apr 2009 20:52:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.linuxmail.info/?p=173#comment-3604</guid>
		<description>I&#039;ve gotten it to work now but i really don&#039;t know what I did to fix it. At least its synced now! Anyways once again thank you! I&#039;ll report updates on this asap.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve gotten it to work now but i really don&#8217;t know what I did to fix it. At least its synced now! Anyways once again thank you! I&#8217;ll report updates on this asap.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: arne</title>
		<link>http://www.linuxmail.info/ad-fds-sync-howto/#comment-3603</link>
		<dc:creator>arne</dc:creator>
		<pubDate>Thu, 16 Apr 2009 17:23:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.linuxmail.info/?p=173#comment-3603</guid>
		<description>Hi consultant,

I have this two accounts. Both are working fine.
When I run directly from the FDS

[root@ldap1 slapd-ldap1]# ldapsearch -H ldaps://dc1.rack -x -D &quot;cn=syncadm&quot; -s base -b &quot;&quot; objectclass=* 

it gives back success:
...
# search result
search: 2
result: 0 Success

# numResponses: 2
# numEntries: 1
[root@ldap1 slapd-ldap1]# 

I even don&#039;t need to put in a password as I do have configured the .ldaprc file with the certificate:
[root@ldap1 slapd-ldap1]# cat ~/.ldaprc
# TLS_CACERT /root/CertificateAuthorityRACK-cacert.pem
TLS_REQCERT allow
[root@ldap1 slapd-ldap1]#


The error log file on the FDS gives me the same bloody message hundered times:

[16/Apr/2009:19:15:38 +0200] slapi_ldap_bind - Error: could not read bind results for id [cn=syncadm,dc=w2k3,dc=rack] mech [SIMPLE]: error 49 (Invalid credentials)


So coming back to the manual ldapsearch try it is not working when I run the same command but put in with -w password the password of the AD user:

[root@ldap1 slapd-ldap1]# ldapsearch -H ldaps://dc1.rack -x -D &quot;cn=syncadm&quot; -w password -s base -b &quot;&quot; objectclass=*
ldap_bind: Invalid credentials (49)
        additional info: 80090308: LdapErr: DSID-0C090334, comment: AcceptSecurityContext error, data 525, vece
[root@ldap1 slapd-ldap1]#

I guess we are on the last steps solving this if we can find an answer for the question: Why the login to the AD is possible only without giving the password, but the .pem file.

Furthermore I guess that a workaround would be to let the passowrd field empty while creating the Windows Sync Agreement. Unfortunately this isn&#039;t possible at all as the next button is disabled in that case.

Any Ideas?</description>
		<content:encoded><![CDATA[<p>Hi consultant,</p>
<p>I have this two accounts. Both are working fine.<br />
When I run directly from the FDS</p>
<p>[root@ldap1 slapd-ldap1]# ldapsearch -H ldaps://dc1.rack -x -D &#8220;cn=syncadm&#8221; -s base -b &#8220;&#8221; objectclass=* </p>
<p>it gives back success:<br />
&#8230;<br />
# search result<br />
search: 2<br />
result: 0 Success</p>
<p># numResponses: 2<br />
# numEntries: 1<br />
[root@ldap1 slapd-ldap1]# </p>
<p>I even don&#8217;t need to put in a password as I do have configured the .ldaprc file with the certificate:<br />
[root@ldap1 slapd-ldap1]# cat ~/.ldaprc<br />
# TLS_CACERT /root/CertificateAuthorityRACK-cacert.pem<br />
TLS_REQCERT allow<br />
[root@ldap1 slapd-ldap1]#</p>
<p>The error log file on the FDS gives me the same bloody message hundered times:</p>
<p>[16/Apr/2009:19:15:38 +0200] slapi_ldap_bind &#8211; Error: could not read bind results for id [cn=syncadm,dc=w2k3,dc=rack] mech [SIMPLE]: error 49 (Invalid credentials)</p>
<p>So coming back to the manual ldapsearch try it is not working when I run the same command but put in with -w password the password of the AD user:</p>
<p>[root@ldap1 slapd-ldap1]# ldapsearch -H ldaps://dc1.rack -x -D &#8220;cn=syncadm&#8221; -w password -s base -b &#8220;&#8221; objectclass=*<br />
ldap_bind: Invalid credentials (49)<br />
        additional info: 80090308: LdapErr: DSID-0C090334, comment: AcceptSecurityContext error, data 525, vece<br />
[root@ldap1 slapd-ldap1]#</p>
<p>I guess we are on the last steps solving this if we can find an answer for the question: Why the login to the AD is possible only without giving the password, but the .pem file.</p>
<p>Furthermore I guess that a workaround would be to let the passowrd field empty while creating the Windows Sync Agreement. Unfortunately this isn&#8217;t possible at all as the next button is disabled in that case.</p>
<p>Any Ideas?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: consultant</title>
		<link>http://www.linuxmail.info/ad-fds-sync-howto/#comment-3600</link>
		<dc:creator>consultant</dc:creator>
		<pubDate>Wed, 15 Apr 2009 22:52:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.linuxmail.info/?p=173#comment-3600</guid>
		<description>Hi Patrick and Arne,

The replication plugin connects to two servers, Fedora Directory Server and Active Directory Server, that&#039;s why it uses two accounts. Make sure both of them exists.

Replication Plugin to Fedora Directory Server
uid=SMaster,cn=config (exists in FDS)

Replication Plugin to Active Directory Server
cn=fds,dc=acme,dc=local (exists in ADS)
</description>
		<content:encoded><![CDATA[<p>Hi Patrick and Arne,</p>
<p>The replication plugin connects to two servers, Fedora Directory Server and Active Directory Server, that&#8217;s why it uses two accounts. Make sure both of them exists.</p>
<p>Replication Plugin to Fedora Directory Server<br />
uid=SMaster,cn=config (exists in FDS)</p>
<p>Replication Plugin to Active Directory Server<br />
cn=fds,dc=acme,dc=local (exists in ADS)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: arne</title>
		<link>http://www.linuxmail.info/ad-fds-sync-howto/#comment-3599</link>
		<dc:creator>arne</dc:creator>
		<pubDate>Wed, 15 Apr 2009 12:49:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.linuxmail.info/?p=173#comment-3599</guid>
		<description>I have the same problem as Patrick. &quot;LDAP error: invalid credentials. Error Code: 49&quot;. But I have checked everything 10 times and I have written every password in clear text and copy pasted it into the password field. Can you please give me some hints?</description>
		<content:encoded><![CDATA[<p>I have the same problem as Patrick. &#8220;LDAP error: invalid credentials. Error Code: 49&#8243;. But I have checked everything 10 times and I have written every password in clear text and copy pasted it into the password field. Can you please give me some hints?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic page generated in 0.390 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2010-03-12 02:29:29 -->
<!-- Compression = gzip -->