Bug 32690 - S4 connector should no longer synchronize the password for Slave PDC DCs from S4 to UCS
S4 connector should no longer synchronize the password for Slave PDC DCs from...
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: S4 Connector
UCS 3.1
Other Linux
: P5 normal (vote)
: UCS 3.1-1-errata
Assigned To: Stefan Gohmann
Felix Botner
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2013-09-26 06:16 CEST by Stefan Gohmann
Modified: 2013-10-07 14:44 CEST (History)
1 user (show)

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Gohmann univentionstaff 2013-09-26 06:16:18 CEST
See Bug #32522 for more details.

The S4 connector should no longer synchronize the password for Slave PDC DCs from S4 to UCS to prevent sync loops in a selective replication scenario.
Comment 1 Stefan Gohmann univentionstaff 2013-09-26 06:26:15 CEST
fixed

YAML 3.1-1: r44468
Code 3.1-1: r44466
Changelog 3.2: r44469
Code 3.2: r44467
Comment 2 Felix Botner univentionstaff 2013-09-26 10:38:46 CEST
OK - errata3.1-1 | ucs3.2-0
OK - YAML        | changelog


root@ucsschoolslave-> /usr/lib/univention-server/server_password_change
root@ucsschoolslave-> /var/log/univention/connector-s4.log
...
sync from ucs: [ dc] [ modify] cn=slave,ou=domain controllers,dc=fff,dc=ggg
sync to ucs:   [ dc] [ modify] cn=slave,cn=dc,cn=server,cn=computers,ou=s...
password_sync_s4_to_ucs: 
   cn=slave,cn=dc,cn=server,cn=computers,ou=school1,dc=fff,dc=ggg  is a S4 
   SlavePDC server, skip password sync
DEBUG_INIT
Building internal group membership cache
Internal group membership cache was created
DEBUG_INIT
Building internal group membership cache
Internal group membership cache was created
sync to ucs:   [ dc] [ modify] cn=slave,cn=dc,cn=server,cn=computers,ou=scho...
password_sync_s4_to_ucs: 
    cn=slave,cn=dc,cn=server,cn=computers,ou=school1,dc=fff,dc=ggg is a S4 
    SlavePDC server, skip password sync
...

OK - univention-ldapsearch -h master
OK - kinit 'slave$'
OK - replication
Comment 3 Moritz Muehlenhoff univentionstaff 2013-10-07 14:44:32 CEST
http://errata.univention.de/ucs/3.1/188.html