<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#ffffff" text="#000000">
    On 04/13/2011 05:27 AM, jean-No&euml;l Chardron wrote:
    <blockquote cite="mid:4DA58895.5040105@dr15.cnrs.fr" type="cite">
      <meta content="text/html; charset=ISO-8859-1"
        http-equiv="Content-Type">
      <title></title>
      Le 12/04/2011 20:45, Rich Megginson a &eacute;crit&nbsp;:
      <blockquote cite="mid:4DA49DB8.9020608@redhat.com" type="cite">
        <meta content="text/html; charset=ISO-8859-1"
          http-equiv="Content-Type">
        On 04/12/2011 12:21 PM, Diego Woitasen wrote:
        <blockquote
          cite="mid:BANLkTinUZytGVzW6H024Oqn0LpkgcaZcYg@mail.gmail.com"
          type="cite"><br>
          <br>
          <div class="gmail_quote">On Tue, Apr 12, 2011 at 11:52 AM,
            jean-No&euml;l Chardron <span dir="ltr">&lt;<a
                moz-do-not-send="true"
                href="mailto:Jean-Noel.Chardron@dr15.cnrs.fr">Jean-Noel.Chardron@dr15.cnrs.fr</a>&gt;</span>
            wrote:<br>
            <blockquote class="gmail_quote" style="margin: 0pt 0pt 0pt
              0.8ex; border-left: 1px solid rgb(204, 204, 204);
              padding-left: 1ex;">
              <div bgcolor="#ffffff" text="#000000"> Le 12/04/2011
                16:37, Diego Woitasen a &eacute;crit&nbsp;:
                <blockquote type="cite">
                  <div class="im"><br>
                    <br>
                    <div class="gmail_quote">On Tue, Apr 12, 2011 at
                      11:13 AM, jean-No&euml;l Chardron <span dir="ltr">&lt;<a
                          moz-do-not-send="true"
                          href="mailto:Jean-Noel.Chardron@dr15.cnrs.fr"
                          target="_blank">Jean-Noel.Chardron@dr15.cnrs.fr</a>&gt;</span>
                      wrote:<br>
                      <blockquote class="gmail_quote" style="margin: 0pt
                        0pt 0pt 0.8ex; border-left: 1px solid rgb(204,
                        204, 204); padding-left: 1ex;"> Hello,<br>
                        <br>
                        In a first time &nbsp;I configured the
                        synchronisation between one AD and one<br>
                        389DS. it is working fine. Now, I would like to
                        mount a new one 389DS<br>
                        that will be a replica read-only of the first :<br>
                        I read this doc :<br>
                        <a moz-do-not-send="true"
href="http://docs.redhat.com/docs/en-US/Red_Hat_Directory_Server/8.2/html/Administration_Guide/Managing_Replication-Configuring_Multi_Master_Replication.html"
                          target="_blank">http://docs.redhat.com/docs/en-US/Red_Hat_Directory_Server/8.2/html/Administration_Guide/Managing_Replication-Configuring_Multi_Master_Replication.html</a><br>
                        <a moz-do-not-send="true"
href="http://docs.redhat.com/docs/en-US/Red_Hat_Directory_Server/7.1/html/Administrators_Guide/sync.htm#2876133"
                          target="_blank">http://docs.redhat.com/docs/en-US/Red_Hat_Directory_Server/7.1/html/Administrators_Guide/sync.htm#2876133</a><br>
                        &nbsp;From this picture I want something more simple
                        like :<br>
                        <br>
                        Consumer read-only (replica)&lt;-----&gt;
                        Supplier Read-Write &lt;----Sync---&gt;<br>
                        Windows AD<br>
                        <br>
                        I don't see how I can configure the replication
                        on the Supplier<br>
                        The supplier sync with AD a database that
                        contains user and group of the AD<br>
                        The supplier has one more database with Unix
                        user and group (I can<br>
                        enable replica on this database and it is
                        working (it is a single<br>
                        master) , I got the replication &nbsp;of this
                        database on the consumer)<br>
                        <br>
                        The problem is for the first database (AD) that
                        is a dedicated consumer<br>
                        for the Windows AD. I dont see how configure as
                        a single master to do<br>
                        the replication to the consumer.<br>
                        Support or explanation will help me<br>
                        Thanks,<br>
                        <br>
                      </blockquote>
                    </div>
                    <br clear="all">
                  </div>
                  <div class="im"> It's documented in the section 9.5.1
                    and 9.5.2.</div>
                </blockquote>
                Yes, but I don't find the answer to my question in the
                documentation.<br>
                In my configuration of the replica settings are :<br>
                In replica role : "Dedicated consumer" (Must&nbsp; I change
                it to "Multiple Master" ? )<br>
                Common settings : Replica ID = 65535&nbsp; (now I read this
                must be a digit between 1 and 65534) Must I change it
                and what are t<span><span style="background-color:
                    rgb(255, 255, 255);" title="cons&eacute;quence si je change
                    la valeur">herefore if I change the value</span></span>
                ?</div>
            </blockquote>
          </div>
        </blockquote>
        Only writable masters use the ReplicaID.&nbsp; For a hub or dedicated
        consumer, use 65535.<br>
      </blockquote>
      Actually the 389ds syncing with the AD is in "dedicated consumer".
      So do you mean that I need to change from dedicated consumer to
      (single or multi) Master ?</blockquote>
    It needs to be a supplier, which means it needs to either be a hub
    or a master.&nbsp; If you want it to be read-only from clients, use hub,
    otherwise use master.<br>
    <blockquote cite="mid:4DA58895.5040105@dr15.cnrs.fr" type="cite">but
      what will be the consequence of this change on the syncing with
      the AD , is there a possibility that the synchronisation doesn't
      work anymore ?<br>
      <br>
      <blockquote cite="mid:4DA49DB8.9020608@redhat.com" type="cite">
        <blockquote
          cite="mid:BANLkTinUZytGVzW6H024Oqn0LpkgcaZcYg@mail.gmail.com"
          type="cite">
          <div class="gmail_quote">
            <blockquote class="gmail_quote" style="margin: 0pt 0pt 0pt
              0.8ex; border-left: 1px solid rgb(204, 204, 204);
              padding-left: 1ex;">
              <div bgcolor="#ffffff" text="#000000">
                <div class="im"><br>
                  <blockquote type="cite">
                    <div><br>
                    </div>
                    <div>Question, what version of AD are you using?
                      Because I was able to configure Windows Sync
                      agaisnt AD 2008r2 but it doesn't work with 2003. I
                      wrote a patch to the windows sync pluging to get
                      it working.</div>
                  </blockquote>
                </div>
                I use 2008r2 </div>
            </blockquote>
          </div>
          <br>
          Yes, let it configured as "Multiple Master". If you have a
          read-only consumer, the master could be configured as
          "multi-master" &nbsp;or "single master".
          <div><br>
          </div>
          <div> If don't remember the allowed range for ID, but don't
            use 65535 to be sure.<br clear="all">
            <br>
          </div>
          <div>Thanks for the information about 2008r2.&nbsp;</div>
          <div><br>
          </div>
          <div>Regards,</div>
          <div>&nbsp;Diego<br>
            -- <br>
            Diego Woitasen<br>
          </div>
          <pre wrap=""><fieldset class="mimeAttachmentHeader"></fieldset>
--
389 users mailing list
<a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:389-users@lists.fedoraproject.org">389-users@lists.fedoraproject.org</a>
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://admin.fedoraproject.org/mailman/listinfo/389-users">https://admin.fedoraproject.org/mailman/listinfo/389-users</a></pre>
        </blockquote>
        <br>
      </blockquote>
      <br>
      <br>
    </blockquote>
    <br>
  </body>
</html>