Everybody Staze...

Nobody leavz...

  • Home
  • About Me
    • LinkedIn
    • Lab
  • Contact
  • Links
  • Reviews
  • Sitemap
  • Weather
You are here: Home / Archives for Open Directory

Thursday

2009/04/02 By staze

 

Maybe I’ll get into posting on Thursday.

So, I just added some nifty ajax to poll the power usage every 20 seconds. While the file is only updated every 60 seconds, I figure every 20 seconds is low enough bandwidth, and often enough to catch and update frequently enough. If I can figure it out, I’ll try to make this only update every minute right after the file gets updated (it gets updated about 2-3 seconds after the minute). I mainly did this for my own benefit since I wanted to be able to watch the power usage without reloading the whole page. Maybe I’ll set up an RSS script so I can subscribe to my energy usage. =P No, no twitter… seems like a waste of twitter’s bandwidth. 

I was up pretty late last night trying to fix OD replication that hasn’t worked right since my 5 hour marathon session prepping for the term. During that marathon, I demoted and re-promoted the OD Master, and apparently when I reset up the replica, it didn’t work right. Changes to passwords, or creation of user accounts weren’t getting replicated. So, I reconfigured stuff. I’m pretty convinced this is the best way to do it:

  1. Demote replica to standalone, reboot.
  2. Remove directory server from Directory Utility, if present. Reboot. If not present, go on.
  3. Check Permissions on replica, if things are clean, go to step 4. Otherwise, reboot again.
  4. Promote to replica. Once replication is complete (by watching Password Replication Log in Server Admin, or in /Library/Logs/PasswordServer/), reboot.
  5. Reboot the OD Master. 
  6. Do a test password change, account disable, something. Watch the replication log on the Master, or Replica to make sure replication takes place (You should see the replication nearly instantly if you have the master set to replicate upon any change). 
  7. Only other thing would be to add the directory info for replica SSL support, and change the slapd.plist to allow SSL. See here: http://www.afp548.com/article.php?story=20080624005724638 
  8. Optional: Reboot any systems that pointed at the Replica before you started this. There seems to be some directory caching that kept ahold of the “Incorrect Password/Invalid User” responses that the replica was returning when things weren’t working. 

That pretty much fixed it. Bitch is, it took me nearly an hour to do when I thought it would take about 15 minutes. Some of the reboots could probably be removed, but it seems safer this way. Replication now works better than it ever has I think (before, no matter what, replication seemed to happen based on a time period, rather than instantly. Easiest way to check this is to make a change to the Master in WGM or via the command line, then do a “mkpassdb -dump | grep username”. You should get back the password slot for that user, and a change date that corresponds to your change on the master. 

As always, make sure you are using NTP on all the servers/clients (ideally the same NTP server, even if it’s wrong, at least all the clients think it’s the same time), and that DNS is working (“changeip -checkhostname” is your friend). If either of these things are broken, kerberos most likely won’t work, and other things may not work right. DNS not working can cause weird issues, as can time differences (kerberos won’t work AT ALL if the times between client and server are off by more than a few minutes). Thankfully pool.ntp.org exists, as do most campuses and corporations run their own NTP servers (AD has one built in, as does ≥Mac OS 10.4 Server.)

See ya all later.

Filed Under: Energy, Sys Admin Tagged With: ajax, Open Directory

Night at work…

2009/03/29 By staze

Spent most of the night last night at work, or back at home waiting for something to finish. Huge PITA. 

The term starts on Monday, so I had to get everything rebooted, and systems updated for the term. Because there are always people in the SOJC, it’s difficult to schedule downtime. I hope to be able to schedule outages this term as I have in the past, so that I can apply various updates. Got the firmware updated on our primary server switch, and the fibre channel switch (things that really can’t be done during the term due to possible failure). 

After that, I tried to get kerberos fixed on the OD server. No love. Archive, Demote, Promote, restore. Then try a slapconfig -kerberize… boom! kerberos dies horribly. Tried removing all of kerberos and starting from scratch, no go. kdcsetup results in a segfault… awesome. So, going to have to push this one back to later in the term, or Summer break. I hope to have it fixed before migrating to 10.6. 

Speaking of which, the possibility of migrating to 10.6 looks tenuous at best. We currently have 5 Intel Xserves, hosting student data (users on one, group shares on another), FCS, the primary MDC, and the website. This leaves email, OD, and the secondary MDC on PPCs, which won’t do 10.6. I’m really really hoping to get 2 more Xserves out of our dwindling budget, but who knows what will happen. With two, I could move OD to the secondary MDC, then migrate mail to the other Xserve. This would be a bare minimum. I’d get to retire our old first generation Xserves, and put the backup server on a G5 Xserve, as well as have another G5 Xserve for… something. 

Add to this the fact that Xsan wants the MDCs to be on the latest OS being used on the SAN, and I REALLY need at least 1 new Xserve. Mail has waited this long… though, I think there is a big desire to use CalDAV this time around. So… money? 

My latest idea was to try to split up the cost. Maybe buy the FC cards, and extra HDs this fiscal year, then next year we buy the servers. Or maybe just buy one server this year, and another next. I really want to get this going. 

More next…

Filed Under: Sys Admin, Work Tagged With: CalDAV, Fibre Channel, Kerberos, MDC, Open Directory, Xsan, Xserve

« Previous Page

Weather

Categories / Archives

  • Apple
  • Coding
  • Electronics
  • Energy
  • Home Ownership
  • Miscellany
  • Politics
  • Prius
  • Sys Admin
  • Travel
  • Uncategorized
  • Work
  • June 2026
  • April 2026
  • August 2025
  • April 2025
  • January 2024
  • February 2021
  • July 2020
  • January 2020
  • April 2019
  • March 2018
  • February 2018
  • June 2017

Copyright © 2026 · Staze On Genesis Framework · WordPress · Log in