Showing posts with label Linux. Show all posts
Showing posts with label Linux. Show all posts

Monday, June 24, 2013

Fixing "bdb_equality_candidates" errors on your OpenLDAP server

Repost from
http://muzso.hu/2010/04/26/fixing-bdb_equality_candidates-errors-on-your-openldap-server
OR
http://trac.zentyal.org/wiki/Documentation/Community/HowTo/LDAPoptimization

  1. Stop the LDAP server:
    sudo stop slapd
  2. Open the right OpenLDAP config file with an editor:
    sudo vi /etc/ldap/slapd.d/cn\=config/olcDatabase\=\{1\}hdb.ldif
  3. Add new lines (after the one with olcDbIndex: objectClass eq in it) for the missing indexes.
    Eg.:
    olcDbIndex: cn eq
    olcDbIndex: gidNumber eq
    olcDbIndex: memberUid eq
    olcDbIndex: uid eq
    olcDbIndex: uidNumber eq
    olcDbIndex: uniqueMember eq
  4. Run the OpenLDAP indexer for your configuration:
    sudo -u openldap slapindex -F /etc/ldap/slapd.d/
  5. Start the LDAP server:
    sudo start slapd
PS: don't forget to back up your OpenLDAP database (in /var/lib/ldap) before you touch it.

Saturday, March 3, 2012

Linux Date Commands

Command to find out the date 2 weeks ago and format in %Y/%m/%d

date --date='-14 days' '+%Y/%m/%d'

Friday, December 10, 2010

Network Scan

Need to scan your network to find available ipaddress? If you are using a linux distro, then you have nmap at your service. One simple command is all it takes.

nmap –s 192.168.1.0/24

nmap has many other command switches available. Check our their website for more information.

http://nmap.org

Thursday, November 18, 2010

Motherboard failure today

We have a Zimbra mail server at work running on top of a 64bit Ubuntu 8.0.4 OS. The computer is a Dell Precision 380 and after a power outage last night, (yes it is connected to a UPS) the motherboard got fried. Luckly, I have another Precision 380 I could swap all the drives, memory and network interfaces to. When I booted up, all went as planned until I realized that my internal network card eth0 was not found. Eth0 is an on-board card, so I new it was working but Ubuntu was not finding it. I ifconfig’ed to check for eth1, eth2, eth3…etc…finally I found it…it was not eth4…weird, I thought. So then I went to /etc/network/interfaces to change eth0 to eth4 and all would be well. Correct? Not so fast. I could not get eth4 to come up with the static ipaddress that is listed in /etc/network/interfaces. What the heck…..did some more digging and found a udev rule that ties the mac address to the network card. So I had to edit the udev rule to reflect the new mac address of eth0 and then restart the udev service and what do you know…eth0 came up again. Awesome!

Rule to edit:
/etc/udev/rules.d/70-persistent-net.rules

eth0 was the first defined rule and all thast was needed was to modify the mac address to reflect the onboard nic in the new computer.

Wednesday, August 11, 2010

Watch errors in linux maillog fly by…

Whether you are using Postfix or Sendmail with Spamassassin, you can watch your maillogs within an ssh session by using the following code:

tail -f /var/log/maillog | egrep '(reject|error|warning|fatal|panic)'

This will help to troubleshoot rejected emails or emails rejected due to Spamassassin blocking the email as Spam.

Tuesday, September 9, 2008

Samba 3 Compile Options

Below is a custom compile of the samba source code used on Slackware 10.1. The samba server uses openldap for authentication and PDC user/computer management.

I created a user called compile to compile the code intead of using root. I only used root to do a make install

####Get the source code
cd /tmp
wget http://us1.samba.org/samba/ftp/stable/samba-3.2.3.tar.gz 

####Samba compile options

su compile

./configure \
--prefix=/usr/local/samba-3.2.3 \
--with-smbwrapper \
--with-smbmount \
--with-cifsmount \
--with-automount \
--with-acl-support \
--with-aio-support \
--with-ldap \
--with-winbind \
--enable-cups \
--enable-socket-wrapper \
--enable-nss-wrapper \

make
make test
su root
make install

#### Link to existing smb.conf in /etc/samba/smb.conf
ln -s /etc/samba/smb.conf /usr/local/samba-3.2.3/lib/smb.conf

#### Copy existing secrets.tdb to new install directory
cp -av /usr/local/samba3/private/*.tdb /usr/local/samba-3.2.3/private/

#### Copy existing databases to new install directory
cp -apRv /usr/local/samba3/var/locks/* /usr/local/samba-3.2.3/var/locks/

#### Store Admin LDAP password in secret.tdb, ((cn=Manager.dc=hharchitects,dc=com))
smbpasswd -w password

#### Winbind INformation

#### Copy the library from source
cp /usr/download/samba-3.2.3/source/nsswitch/libnss_winbind.so /lib

#### Create a link 
ln -s /lib/libnss_winbind.so /lib/libnss_winbind.so.2

#### Load the library
/sbin/ldconfig -v | grep winbind

#### Edit /etc/nsswitch.conf
passwd:     files winbind
shadow:     files 
group:      files winbind

#### Edit /etc/nsswitch.conf to look like this if using ldap
passwd:     files ldap
shadow:     files ldap
group:      files ldap

#### Edit SMB.conf file accordingly to add winbind support

#### Join the PDC Domain
/usr/local/samba3/bin/./net rpc join -S PDC -U Administrator

#### Repath samba3 symlink
cd /usr/local; rm samba3; ln -s /usr/local/samba-3.2.3 samba3

#### Create the correct net rights
cd /usr/local/samba3/bin; ./net rpc rights grant administrator SePrintOperatorPrivilege SeDiskOperatorPrivilege SeMachineAccountPrivilege SeTakeOwnershipPrivilege SeBackupPrivilege SeRestorePrivilege SeRemoteShutdownPrivilege SeAddUsersPrivilege

####Google research on using LDAP filters in /etc/ldap.conf
#################################################################################
# #
#Norbert Gomes wrote: #
# #
#    After some search, I read that I have to configure nss_ldap. But I #
#    don't know how to configure it properly to operate with our LDAP #
#    database. #
# #
#    Let me explain : #
# #
#    We used the 'ldap filter' parameter like this : #
#    ldap filter = (&(iufmLogin=%u)(gecos=#*)) #
# #
# #
#I think you want to use these settings in ldap.conf: #
# #
#nss_base_passwd ou=People,dc=example,dc=com?one?gecos=#* #
#nss_map_attribute uid iufmLogin #
#pam_login_attribute iufmLogin #
# #
#I'm not sure whether or not pam_login_attribute is strictly required. #
#I'd try with just the first two settings, and leave it at that if things #
#work as you expect. #
#   #
#################################################################################