<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<meta content="text/html; charset=ISO-8859-1"
http-equiv="Content-Type">
</head>
<body bgcolor="#ffffff" text="#000000">
On 01/05/2011 11:25 AM, <a class="moz-txt-link-abbreviated" href="mailto:harry.devine@faa.gov">harry.devine@faa.gov</a> wrote:
<blockquote
cite="mid:OF5FA0ADE4.A25379C0-ON8525780F.00644D60-8525780F.00652C2B@faa.gov"
type="cite">
<br>
<font face="sans-serif" size="2">I tried to upgrade, but yum tells
me
that there are no packages marked for update. I did see that I
had
the dirsrv.repo file renamed so it wouldn't be used, so I
renamed it back
and tried the "yum upgrade" again, and got the same thing. The
relevant contents of my dirsrv.repo file are:</font>
<br>
<br>
<font face="sans-serif" size="2">[dirsrv]</font>
<br>
<font face="sans-serif" size="2">name=389 Directory Server - 6 -
$basearch</font>
<br>
<font face="sans-serif" size="2">baseurl=<a class="moz-txt-link-freetext" href="http://port389.org/yum/dirsrv/fedora/6/$basearch/RPMS">http://port389.org/yum/dirsrv/fedora/6/$basearch/RPMS</a></font>
<br>
<br>
<font face="sans-serif" size="2">I assume this repo isn't correct?
I
think I downloaded it from that CentOS link I included in my
last email.</font>
<br>
</blockquote>
We've been using EPEL for a couple of years now - that repo is not
used any more.<br>
<a class="moz-txt-link-freetext" href="http://directory.fedoraproject.org/wiki/Download">http://directory.fedoraproject.org/wiki/Download</a><br>
<blockquote
cite="mid:OF5FA0ADE4.A25379C0-ON8525780F.00644D60-8525780F.00652C2B@faa.gov"
type="cite">
<br>
<font face="sans-serif" size="2">Thanks,</font>
<br>
<font face="sans-serif" size="2">Harry</font>
<br>
<br>
<font face="sans-serif" size="2">Harry Devine<br>
Common ARTS Software Development<br>
AJT-144<br>
(609)485-4218<br>
<a class="moz-txt-link-abbreviated" href="mailto:Harry.Devine@faa.gov">Harry.Devine@faa.gov</a></font>
<br>
<br>
<br>
<table width="100%">
<tbody>
<tr valign="top">
<td><font face="sans-serif" color="#5f5f5f" size="1">From:</font>
</td>
<td><font face="sans-serif" size="1">Rich Megginson
<a class="moz-txt-link-rfc2396E" href="mailto:rmeggins@redhat.com"><rmeggins@redhat.com></a></font>
<br>
</td>
</tr>
<tr valign="top">
<td><font face="sans-serif" color="#5f5f5f" size="1">To:</font>
</td>
<td><font face="sans-serif" size="1">Harry
Devine/ACT/FAA@FAA</font>
</td>
</tr>
<tr>
<td valign="top"><font face="sans-serif" color="#5f5f5f"
size="1">Cc:</font>
</td>
<td><font face="sans-serif" size="1"><a class="moz-txt-link-abbreviated" href="mailto:389-users@lists.fedoraproject.org">389-users@lists.fedoraproject.org</a></font>
</td>
</tr>
<tr valign="top">
<td><font face="sans-serif" color="#5f5f5f" size="1">Date:</font>
</td>
<td><font face="sans-serif" size="1">01/05/2011 11:57 AM</font>
</td>
</tr>
<tr valign="top">
<td><font face="sans-serif" color="#5f5f5f" size="1">Subject:</font>
</td>
<td><font face="sans-serif" size="1">Re: [389-users] Cannot
login as cn=Directory
Manager</font></td>
</tr>
</tbody>
</table>
<br>
<hr noshade="noshade">
<br>
<br>
<br>
<font size="3">On 01/05/2011 09:30 AM, </font><a
moz-do-not-send="true" href="mailto:harry.devine@faa.gov"><font
color="blue" size="3"><u>harry.devine@faa.gov</u></font></a><font
size="3">
wrote: </font>
<br>
<font face="sans-serif" size="2"><br>
Yep, it appears to just have stopped working. I know that I had
some
similar issues back in October when I first installed it, but I
turned
off the firewall on this PC and all was good. I verified that I
still
have the firewall off. I'm running this on an old laptop that
we
have here at work which is running CentOS 5.4, and isn't
connected to the
network at all. Just for evaluation and familiarization
purposes
at this point.</font><font size="3"> <br>
</font><font face="sans-serif" size="2"><br>
Here's the versions that I could get:</font><font size="3"> </font><font
face="sans-serif" size="2"><br>
389-console: 1.1.3</font><font size="3"> </font><font
face="sans-serif" size="2"><br>
389-ds-base: 1.2.2</font><font size="3"> </font><font
face="sans-serif" size="2"><br>
389-admin: 1.1.8</font><font size="3"> </font><font
face="sans-serif" size="2"><br>
idm-console-framework: 1.1.3</font><font size="3"> </font><font
face="sans-serif" size="2"><br>
389-adminutil: 1.1.8</font><font size="3"> <br>
</font><font face="sans-serif" size="2"><br>
Everything was (I assume) installed at once when I did the
initial installation
following the instructions I found at </font><a
moz-do-not-send="true"
href="http://www.linuxmail.info/389-directory-server-setup-howto-centos-5/"><font
face="sans-serif" color="blue" size="2"><u>http://www.linuxmail.info/389-directory-server-setup-howto-centos-5/</u></font></a><font
face="sans-serif" size="2">.</font><font size="3">
</font>
<br>
<font size="3">I suggest upgrading to the latest 1.2.7 if only to
make
it easier to support.</font>
<br>
<font face="sans-serif" size="2"><br>
Lastly, nothing is in the directory server access log around
10:41:25.
Just that one line that said "GET /admin-serv/authenticate
HTTP/1.0"
at 10:45:45.</font><font size="3"> </font>
<br>
<font size="3">That's the admin server log - the directory server
access
log is in /var/log/dirsrv/slapd-yourinstancename/access</font>
<br>
<font face="sans-serif" size="2"><br>
Thanks!</font><font size="3"> </font><font face="sans-serif"
size="2"><br>
Harry</font><font size="3"> <br>
</font><font face="sans-serif" size="2"><br>
Harry Devine<br>
Common ARTS Software Development<br>
AJT-144<br>
(609)485-4218</font><font face="sans-serif" color="blue"
size="2"><u><br>
</u></font><a moz-do-not-send="true"
href="mailto:Harry.Devine@faa.gov"><font face="sans-serif"
color="blue" size="2"><u>Harry.Devine@faa.gov</u></font></a><font
size="3">
<br>
<br>
</font>
<table width="100%">
<tbody>
<tr valign="top">
<td width="15%"><font face="sans-serif" color="#5f5f5f"
size="1">From:</font><font size="3">
</font>
</td>
<td width="84%"><font face="sans-serif" size="1">Rich
Megginson </font><a moz-do-not-send="true"
href="mailto:rmeggins@redhat.com"><font
face="sans-serif" color="blue" size="1"><u><rmeggins@redhat.com></u></font></a><font
size="3">
</font>
</td>
</tr>
<tr valign="top">
<td><font face="sans-serif" color="#5f5f5f" size="1">To:</font><font
size="3">
</font>
</td>
<td><font face="sans-serif" size="1">Harry
Devine/ACT/FAA@FAA</font><font size="3">
</font>
</td>
</tr>
<tr>
<td valign="top"><font face="sans-serif" color="#5f5f5f"
size="1">Cc:</font><font size="3">
</font>
</td>
<td><a moz-do-not-send="true"
href="mailto:389-users@lists.fedoraproject.org"><font
face="sans-serif" color="blue" size="1"><u>389-users@lists.fedoraproject.org</u></font></a><font
size="3">
</font>
</td>
</tr>
<tr valign="top">
<td><font face="sans-serif" color="#5f5f5f" size="1">Date:</font><font
size="3">
</font>
</td>
<td><font face="sans-serif" size="1">01/05/2011 11:18 AM</font><font
size="3">
</font>
</td>
</tr>
<tr valign="top">
<td><font face="sans-serif" color="#5f5f5f" size="1">Subject:</font><font
size="3">
</font>
</td>
<td><font face="sans-serif" size="1">Re: [389-users] Cannot
login as cn=Directory
Manager</font></td>
</tr>
</tbody>
</table>
<br>
<font size="3"><br>
</font>
<hr noshade="noshade"><font size="3"><br>
<br>
<br>
On 01/05/2011 08:40 AM, </font><a moz-do-not-send="true"
href="mailto:harry.devine@faa.gov"><font color="blue" size="3"><u>harry.devine@faa.gov</u></font></a><font
size="3">
wrote: </font><font face="sans-serif" size="2"><br>
<br>
How do I tell what the other versions are?</font><font size="3">
<br>
rpm -qi 389-console 389-ds-base 389-admin idm-console-framework
389-adminutil
</font><font face="sans-serif" size="2"><br>
I haven't upgraded or anything, so its the same
version/installation that
I initially did a few months ago.</font><font size="3"> <br>
So it just stopped working, with no explanation, and nothing has
changed?
</font><font face="sans-serif" size="2"><br>
Should I upgrade? Is there a bug that's fixed in a newer
version
that could be causing what I'm seeing?</font><font size="3"> </font><font
face="sans-serif" size="2"><br>
<br>
The /var/log/dirsrv/admin-serv/error log shows:</font><font
size="3"> </font><font face="Courier New" size="2"><br>
[Wed Jan 05 10:40:45 2011] [notice] [client 127.0.0.1]
admserv_host_ip_check:
ap_get_remote_host could not resolve 127.0.0.1</font><font
size="3"> </font><font face="Courier New" size="2"><br>
[Wed Jan 05 10:40:45 2011] [notice] [client 127.0.0.1]
admserv_host_ip_check:
host [localhost.localdomain] did not match pattern [*.test.com]
-will scan
aliases</font><font size="3"> </font><font face="Courier New"
size="2"><br>
[Wed Jan 05 10:40:45 2011] [notice] [client 127.0.0.1]
admserv_host_ip_check:
host alias [localhost] did not match pattern [*.test.com]</font><font
size="3">
</font><font face="Courier New" size="2"><br>
[Wed Jan 05 10:41:25 2011] [crit] buildUGInfo(): unable to
initialize TLS
connection to LDAP host localhost.test.com port 389: 4</font><font
size="3">
<br>
<br>
This error message is somewhat misleading - it is not actually
attempting
a TLS connection unless you have configured it to use TLS.<br>
<br>
What's in the directory server access log on or around [Wed Jan
05 10:41:25
2011] ? </font><font face="Courier New" size="2"><br>
[Wed Jan 05 10:41:25 2011] [error] [client 127.0.0.1] user
cn=Directory
Manager not found: /admin-serv/authenticate</font><font size="3">
<br>
If the directory server connection fails, it will fail to
lookup/bind too.
</font><font face="Courier New" size="2"><br>
<br>
The /var/log/dirsrv/admin-serv/access log (which only got
written to AFTER
I closed 389-console) shows:</font><font size="3"> </font><font
face="Courier New" size="2"><br>
127.0.0.1 - cn=Directory Manager [05/Jan/2011:10:40:45 -0500]
"GET
/admin-serv/authenticate HTTP/1.0" 401 466</font><font size="3">
</font><font face="Courier New" size="2"><br>
<br>
Thanks!</font><font size="3"> </font><font face="Courier New"
size="2"><br>
Harry</font><font size="3"> </font><font face="sans-serif"
size="2"><br>
<br>
Harry Devine<br>
Common ARTS Software Development<br>
AJT-144<br>
(609)485-4218</font><font color="blue" size="3"><u><br>
</u></font><a moz-do-not-send="true"
href="mailto:Harry.Devine@faa.gov"><font face="sans-serif"
color="blue" size="2"><u>Harry.Devine@faa.gov</u></font></a><font
size="3">
<br>
</font>
<table width="100%">
<tbody>
<tr valign="top">
<td width="15%"><font face="sans-serif" color="#5f5f5f"
size="1">From:</font><font size="3">
</font>
</td>
<td width="84%"><font face="sans-serif" size="1">Rich
Megginson </font><a moz-do-not-send="true"
href="mailto:rmeggins@redhat.com"><font
face="sans-serif" color="blue" size="1"><u><rmeggins@redhat.com></u></font></a><font
size="3">
</font>
</td>
</tr>
<tr valign="top">
<td><font face="sans-serif" color="#5f5f5f" size="1">To:</font><font
size="3">
</font>
</td>
<td><font face="sans-serif" size="1">Harry
Devine/ACT/FAA@FAA</font><font size="3">
</font>
</td>
</tr>
<tr>
<td valign="top"><font face="sans-serif" color="#5f5f5f"
size="1">Cc:</font><font size="3">
</font>
</td>
<td><a moz-do-not-send="true"
href="mailto:389-users@lists.fedoraproject.org"><font
face="sans-serif" color="blue" size="1"><u>389-users@lists.fedoraproject.org</u></font></a><font
size="3">
</font>
</td>
</tr>
<tr valign="top">
<td><font face="sans-serif" color="#5f5f5f" size="1">Date:</font><font
size="3">
</font>
</td>
<td><font face="sans-serif" size="1">01/05/2011 10:23 AM</font><font
size="3">
</font>
</td>
</tr>
<tr valign="top">
<td><font face="sans-serif" color="#5f5f5f" size="1">Subject:</font><font
size="3">
</font>
</td>
<td><font face="sans-serif" size="1">Re: [389-users] Cannot
login as cn=Directory
Manager</font></td>
</tr>
</tbody>
</table>
<br>
<font size="3"><br>
<br>
</font>
<hr noshade="noshade"><font size="3"><br>
<br>
<br>
On 01/05/2011 05:59 AM, </font><a moz-do-not-send="true"
href="mailto:harry.devine@faa.gov"><font color="blue" size="3"><u>harry.devine@faa.gov</u></font></a><font
size="3">
wrote: </font><font face="sans-serif" size="2"><br>
<br>
I'm on CentOS 5.4 and my 389 version is 1.1.3 if I'm reading the
console
log properly. The console log that got generated when I ran
"389-console
-D 9 -f console.log" is attached.</font><font size="3"> <br>
What are the versions of the other components?<br>
389-ds-base, 389-admin, idm-console-framework<br>
<br>
What does it say in the admin server logs in
/var/log/dirsrv/admin-serv/error
and access?<br>
<br>
Have you upgraded recently? If so, did you run
setup-ds-admin.pl
-u after upgrading? </font><font face="sans-serif" size="2"><br>
<br>
Thanks for the help!</font><font size="3"> </font><font
face="sans-serif" size="2"><br>
Harry</font><font size="3"> <br>
</font><font face="sans-serif" size="2"><br>
<br>
<br>
Harry Devine<br>
Common ARTS Software Development<br>
AJT-144<br>
(609)485-4218</font><font color="blue" size="3"><u><br>
</u></font><a moz-do-not-send="true"
href="mailto:Harry.Devine@faa.gov"><font face="sans-serif"
color="blue" size="2"><u>Harry.Devine@faa.gov</u></font></a><font
size="3">
</font>
<table width="100%">
<tbody>
<tr valign="top">
<td width="8%"><font face="sans-serif" color="#5f5f5f"
size="1">From:</font><font size="3">
</font>
</td>
<td width="91%"><font face="sans-serif" size="1">Rich
Megginson </font><a moz-do-not-send="true"
href="mailto:rmeggins@redhat.com"><font
face="sans-serif" color="blue" size="1"><u><rmeggins@redhat.com></u></font></a><font
size="3">
</font>
</td>
</tr>
<tr valign="top">
<td><font face="sans-serif" color="#5f5f5f" size="1">To:</font><font
size="3">
</font>
</td>
<td><font face="sans-serif" size="1">"General discussion
list for the
389 Directory server project." </font><a
moz-do-not-send="true"
href="mailto:389-users@lists.fedoraproject.org"><font
face="sans-serif" color="blue" size="1"><u><389-users@lists.fedoraproject.org></u></font></a><font
size="3">
</font>
</td>
</tr>
<tr>
<td valign="top"><font face="sans-serif" color="#5f5f5f"
size="1">Cc:</font><font size="3">
</font>
</td>
<td><font face="sans-serif" size="1">Harry
Devine/ACT/FAA@FAA</font><font size="3">
</font>
</td>
</tr>
<tr valign="top">
<td><font face="sans-serif" color="#5f5f5f" size="1">Date:</font><font
size="3">
</font>
</td>
<td><font face="sans-serif" size="1">01/04/2011 04:40 PM</font><font
size="3">
</font>
</td>
</tr>
<tr valign="top">
<td><font face="sans-serif" color="#5f5f5f" size="1">Subject:</font><font
size="3">
</font>
</td>
<td><font face="sans-serif" size="1">Re: [389-users] Cannot
login as cn=Directory
Manager</font></td>
</tr>
</tbody>
</table>
<br>
<font size="3"><br>
<br>
<br>
</font>
<hr noshade="noshade"><font size="3"><br>
<br>
<br>
On 01/04/2011 12:55 PM, </font><a moz-do-not-send="true"
href="mailto:harry.devine@faa.gov"><font color="blue" size="3"><u>harry.devine@faa.gov</u></font></a><font
size="3">
wrote: </font><font face="sans-serif" size="2"><br>
<br>
I've been away from my 389-ds admin for a few months (I'm just
starting
to get familiar with it), and I can't login using the user ID
"cn=Directory
Manager". A few months ago I could using the GUI 389-console
application. But today I can't. It keeps saying:</font><font
size="3">
</font><font face="sans-serif" size="2"><br>
<br>
"Can't login because of an incorrect User ID, Incorrect
password,
or Directory problem."</font><font size="3"> </font><font
face="sans-serif" size="2"><br>
<br>
The error log shows: "[error] [client 127.0.0.1] user
cn=Directory
Manager not found: /admin-serv/authenticate"</font><font
size="3"> </font><font face="sans-serif" size="2"><br>
<br>
I am able to get data back when I enter: "</font><tt><font
size="1">ldapsearch
-x -b o=netscaperoot -D "cn=Directory Manager" -w
<password>
"objectclass=nsAdminConfig"</font></tt><font face="sans-serif"
size="2">"
from the command line, so I know that the password is correct.</font><font
size="3">
</font><font face="sans-serif" size="2"><br>
<br>
Any thoughts on what to do to fix this?</font><font size="3"> <br>
What platform? What versions of 389-ds-base, 389-admin,
idm-console-framework?<br>
run 389-console -D 9 -f console.log then send console.log (you
will first
want to obscure any sensitive information) </font><font
face="sans-serif" size="2"><br>
<br>
Thanks!</font><font size="3"> </font><font face="sans-serif"
size="2"><br>
Harry</font><font size="3"> </font><font face="sans-serif"
size="2"><br>
<br>
Harry Devine<br>
Common ARTS Software Development<br>
AJT-144<br>
(609)485-4218</font><font color="blue" size="3"><u><br>
</u></font><a moz-do-not-send="true"
href="mailto:Harry.Devine@faa.gov"><font face="sans-serif"
color="blue" size="2"><u>Harry.Devine@faa.gov</u></font></a><font
size="3">
</font><tt><font size="3"><br>
<br>
<br>
--<br>
389 users mailing list</font></tt><font color="blue" size="3"><u><br>
</u></font><a moz-do-not-send="true"
href="mailto:389-users@lists.fedoraproject.org"><tt><font
color="blue" size="3"><u>389-users@lists.fedoraproject.org</u></font></tt></a><font
color="blue" size="3"><u><br>
</u></font><a moz-do-not-send="true"
href="https://admin.fedoraproject.org/mailman/listinfo/389-users"><tt><font
color="blue" size="3"><u>https://admin.fedoraproject.org/mailman/listinfo/389-users</u></font></tt></a><font
size="3">
<br>
<br>
<br>
<br>
<br>
<br>
</font>
<br>
<br>
<br>
</blockquote>
<br>
</body>
</html>