Re: Need help syncing with syncrepl 2.3

"L. B." <[email protected]> Thu, 20 May 2010 15:27:05 -0700
Newsgroups gmane.network.openldap.general
Message-ID <[email protected]>
Hi Buchan - I updated the limits statement to the following:

limits dn.exact=3D"cn=3DReplicator,dc=3Dswa,dc=3Dcom"
    size=3Dunlimited
    time=3Dunlimited

and now it appears to be working as expected!

On a side note, I never received a "Size limit exceeded" using the same =
parameters from the syncrepl configuration (I'm under 500 entries).

Thanks!

Rafael

Below is the new output after a synchronization:

May 20 22:16:06 admin-agis01 last message repeated 3 times
May 20 22:16:48 admin-agis01 slapd2.3[32501]: do_syncrep2: rid 001 =
LDAP_RES_INTERMEDIATE - SYNC_ID_SET=20
May 20 22:16:48 admin-agis01 slapd2.3[32501]: syncrepl_del_nonpresent: =
rid 001 be_delete uid=3Ddyrnaesd,ou=3DSoftware =
Applications,dc=3Dswa,dc=3Dcom (0)=20
May 20 22:16:48 admin-agis01 slapd2.3[32501]: syncrepl_entry: rid 001 =
LDAP_RES_SEARCH_ENTRY(LDAP_SYNC_ADD)=20
May 20 22:16:48 admin-agis01 slapd2.3[32501]: syncrepl_entry: rid 001 =
be_search (0)=20
May 20 22:16:48 admin-agis01 slapd2.3[32501]: syncrepl_entry: rid 001 =
cn=3Dusers,ou=3Dgroups,dc=3Dswa,dc=3Dcom=20
May 20 22:16:48 admin-agis01 slapd2.3[32501]: syncrepl_entry: rid 001 =
be_modify (0)=20
May 20 22:16:48 admin-agis01 slapd2.3[32501]: syncrepl_entry: rid 001 =
LDAP_RES_SEARCH_ENTRY(LDAP_SYNC_ADD)=20
May 20 22:16:48 admin-agis01 slapd2.3[32501]: syncrepl_entry: rid 001 =
be_search (0)=20
May 20 22:16:48 admin-agis01 slapd2.3[32501]: syncrepl_entry: rid 001 =
cn=3Dswa,ou=3Dgroups,dc=3Dswa,dc=3Dcom=20
May 20 22:16:48 admin-agis01 slapd2.3[32501]: syncrepl_entry: rid 001 =
be_modify (0)=20
May 20 22:16:48 admin-agis01 slapd2.3[32501]: syncrepl_entry: rid 001 =
LDAP_RES_SEARCH_ENTRY(LDAP_SYNC_ADD)=20
May 20 22:16:48 admin-agis01 slapd2.3[32501]: syncrepl_entry: rid 001 =
be_search (0)=20
May 20 22:16:48 admin-agis01 slapd2.3[32501]: syncrepl_entry: rid 001 =
uid=3Dbarreror,ou=3DSoftware Applications,dc=3Dswa,dc=3Dcom=20
May 20 22:16:48 admin-agis01 slapd2.3[32501]: syncrepl_entry: rid 001 =
be_modify (0)=20
May 20 22:16:48 admin-agis01 slapd2.3[32501]: syncrepl_entry: rid 001 =
LDAP_RES_SEARCH_ENTRY(LDAP_SYNC_ADD)=20
May 20 22:16:48 admin-agis01 slapd2.3[32501]: syncrepl_entry: rid 001 =
be_search (0)=20
May 20 22:16:48 admin-agis01 slapd2.3[32501]: syncrepl_entry: rid 001 =
uid=3Dairftp,ou=3DSystemUsers,ou=3DSystemAccounts,dc=3Dswa,dc=3Dcom=20
May 20 22:16:48 admin-agis01 slapd2.3[32501]: syncrepl_entry: rid 001 =
be_modify (0)=20
May 20 22:16:48 admin-agis01 slapd2.3[32501]: do_syncrep2: rid 001 =
LDAP_RES_SEARCH_RESULT=20
May 20 22:17:23 admin-agis01 slapd2.3[32501]: <=3D =
bdb_equality_candidates: (uniqueMember) not indexed=20


On Mar 30, 2010, at 4:10 AM, Buchan Milne wrote:

> On Monday, 29 March 2010 21:30:20 L.B. wrote:
>> Hi;
>>=20
>> I've finally decided to make the move to syncrepl after much delay =
and
>> procrastination. I've read the guide and also reviewed several =
howto's
>> on the topic... It still isn't running correctly for me because it
>> doesn't replicate a few new users I've added to the provider. Also =
I'm
>> seeing the following issue over and over (every time it tries a sync
>> on my 10m interval):
>=20
> This normally indicates that the consumer didn't get the final =
control, usually=20
> because it didn't have sufficient (size/time) access to get the full =
search=20
> results.
>=20
>=20
>> #########
>> Mar  5 20:25:19 admin-agis01 slapd2.3[6147]: do_syncrep2: rid 001
>> LDAP_RES_INTERMEDIATE - SYNC_ID_SET
>> Mar  5 20:25:19 admin-agis01 slapd2.3[6147]: syncrepl_del_nonpresent:
>> rid 001 be_delete
>> uid=3Dairftp,ou=3DSystemUsers,ou=3DSystemAccounts,dc=3Dswa,dc=3Dcom =
(0)
>> Mar  5 20:25:19 admin-agis01 slapd2.3[6147]: syncrepl_entry: rid 001
>> LDAP_RES_SEARCH_ENTRY(LDAP_SYNC_ADD)
>> Mar  5 20:25:19 admin-agis01 slapd2.3[6147]: syncrepl_entry: rid 001
>> be_search (0)
>> Mar  5 20:25:19 admin-agis01 slapd2.3[6147]: syncrepl_entry: rid 001
>> uid=3Dairftp,ou=3DSystemUsers,ou=3DSystemAccounts,dc=3Dswa,dc=3Dcom
>> Mar  5 20:25:19 admin-agis01 slapd2.3[6147]: syncrepl_entry: rid 001 =
be_add
>> (0) Mar  5 20:25:19 admin-agis01 slapd2.3[6147]: do_syncrep2: rid 001
>> LDAP_RES_SEARCH_RESULT
>> #########
>>=20
>> My setup is RHEL4 with Buchan's RPMs
>> (openldap2.3-servers-2.3.39-3.rhel4, etc.).
>=20
> 2.3.43 has been available for a long time ...
>=20
>> I have a fairly simple
>> setup, one provider and one consumer.
>>=20
>> Here is my provider config:
>> ######################
>>=20
>> include /usr/share/openldap2.3/schema/core.schema
>> include /usr/share/openldap2.3/schema/cosine.schema
>> include /usr/share/openldap2.3/schema/inetorgperson.schema
>> include /usr/share/openldap2.3/schema/nis.schema
>> include /usr/share/openldap2.3/schema/misc.schema
>> include /usr/share/openldap2.3/schema/corba.schema
>> include /usr/share/openldap2.3/schema/openldap.schema
>> include /usr/share/openldap2.3/schema/ppolicy.schema
>> include /usr/share/openldap2.3/schema/ldapns.schema
>>=20
>> access to *
>>  by dn.exact=3D"cn=3DReplicator,dc=3Dswa,dc=3Dcom" read
>>  by self read
>>  by * none break
>>=20
>> limits group=3D"cn=3DReplicator,dc=3Dswa,dc=3Dcom"
>>  size=3Dunlimited
>>  time=3Dunlimited
>=20
> The intention in my limits example is that you would create a =
groupOfNames for=20
> cn=3DReplicator, and add additional host-specific DNs to this =
groupOfNames=20
> object. But, it seems you have only one cn=3DReplicator non-group =
entry, changed=20
> the ACL appropriately, but not the limits statement.
>=20
> [...]
>=20
>> syncrepl rid=3D001
>>     provider=3Dldap://ldap-agis01.mascorp.com
>>     type=3DrefreshOnly
>>     interval=3D00:00:10:00
>>     retry=3D"60 10 300 +"
>>     searchbase=3D"dc=3Dswa,dc=3Dcom"
>>     filter=3D"(objectClass=3D*)"
>>     binddn=3D"cn=3DReplicator,dc=3Dswa,dc=3Dcom"
>>     bindmethod=3Dsimple
>>     credentials=3Dyadayadayada
>>     schemachecking=3Doff
>> updateref ldap://ldap-agis01.mascorp.com/
>=20
>=20
> Assuming you have more than 500 entries, if you do a search as this =
syncrepl=20
> binddn, with the rest of the search parameters based on the syncrepl=20=

> configuration, do you get all entries, or a "Size limit exceeded" ?
>=20
> Regards,
> Buchan