<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
  <meta content="text/html; charset=ISO-8859-1"
 http-equiv="Content-Type">
</head>
<body bgcolor="#ffffff" text="#000000">
On 09/08/2009 09:14 AM, Doug Tucker wrote:
<blockquote cite="mid:1252426475.16260.12.camel@thor.seas.smu.edu"
 type="cite">
  <pre wrap="">
  </pre>
  <blockquote type="cite">
    <pre wrap="">
-----Original Message-----
From: <a class="moz-txt-link-abbreviated" href="mailto:fedora-directory-users-bounces@redhat.com">fedora-directory-users-bounces@redhat.com</a> [<a class="moz-txt-link-freetext" href="mailto:fedora-directory-users-bounces@redhat.com">mailto:fedora-directory-users-bounces@redhat.com</a>] On Behalf Of Doug Tucker
Sent: Tuesday, September 08, 2009 9:05 AM
To: General discussion list for the 389 Directory server project.
Subject: Re: [389-users] Pass Sync Doesn't Work


    </pre>
    <blockquote type="cite">
      <blockquote type="cite">
        <blockquote type="cite">
          <pre wrap="">would be greatly appreciated.
          </pre>
        </blockquote>
        <pre wrap="">
1 - In windows registry-HKLM-Software-PasswordSync,
change the "log level" setting from "0" to "1"

2 - Restart the passsync service

3 - look for passsync.log under C:\Program Files\*Password 
Synchronization\


--Chandra

        </pre>
      </blockquote>
    </blockquote>
    <pre wrap="">Thanks, I'll ask the windows guy to set this.  I haven't seen anything
about this, but merely thinking.  If the passync service is installed on
the PDC host, if a windows user changes their password, but are
connected to the BDC when they do so, will passync still catch the
change?
    </pre>
  </blockquote>
  <pre wrap="">
OK!  The logging was a tremendous help to at least seeing where the
failure is.  When the password change is made on the PDC, passync DOES
catch it and replicate to 389.  However, if the password change occurs
on the BDC, even though we see the change replicated to the PDC, passync
is NOT catching it and replicating to 389.  Does anyone have any ideas?
  </pre>
</blockquote>
<br>
<a id="d0e34827" class="indexterm">I believe The Password Sync Service
must be installed on every Active Directory domain controller. </a><br>
<br>
<blockquote cite="mid:1252426475.16260.12.camel@thor.seas.smu.edu"
 type="cite">
  <pre wrap="">
--
389 users mailing list
<a class="moz-txt-link-abbreviated" href="mailto:389-users@redhat.com">389-users@redhat.com</a>
<a class="moz-txt-link-freetext" href="https://www.redhat.com/mailman/listinfo/fedora-directory-users">https://www.redhat.com/mailman/listinfo/fedora-directory-users</a>
  </pre>
</blockquote>
<br>
</body>
</html>