Hi, 389ds'ers,I have two 2012 r2 domain controllers with passsync 1.6 x64 installed. They're both targeting 389-ds-base-1.3.4.9-1.fc22.x86_64 . They're working flawlessly. I dont know if it's been a software update or a change in the domain settings. Thing is today, one of the controllers has stopped sync'ing. Whenever I change one password in that controller, the following message is logged in passsync.log:08/29/16 11:30:07: Password list has 1 entries08/29/16 11:30:07: Attempting to sync password for juankar08/29/16 11:30:07: Searching for (ntuserdomainid=juankar)08/29/16 11:30:07: Checking password failed for remote entry: uid=juankar,ou=xxx....08/29/16 11:30:07: Deferring password change for juankarand in the server access log I get ldap bind err=53 when the passsync user tries to check the password:[29/Aug/2016:11:30:07 +0200] conn=276 fd=67 slot=67 SSL connection from xxxx[29/Aug/2016:11:30:07 +0200] conn=276 TLS1.2 128-bit AES[29/Aug/2016:11:30:07 +0200] conn=276 op=0 BIND dn="uid=juankar,ou=xxx...." method=128 version=3[29/Aug/2016:11:30:07 +0200] conn=276 op=0 RESULT err=53 tag=97 nentries=0 etime=0[29/Aug/2016:11:30:07 +0200] conn=276 op=1 UNBIND
[29/Aug/2016:11:30:07 +0200] conn=276 op=1 fd=67 closed - U1[29/Aug/2016:11:30:07 +0200] conn=275 op=2 UNBINDAny hints? Could be a problem with certificates? They're both using the same CA (windows CA Cert serv is installed in one of the DCs)Regards!![]()
--
389-users mailing list
389-users@lists.fedoraproject.org
https://lists.fedoraproject.org/admin/lists/389-users@ lists.fedoraproject.org