[SAC] osgeo1 - ldap

Folks,

John was having problems logging into hypervisor using the OSGeo LDAP
access and it turns out the issue was that the johng and gupteshwar
account had the same uidNumber value. I have a mechanism to ensure the
web script that enables shell access does not duplicate uidNumber values
but it appears that one or more previously created values overlapped.

I deleted the johng account, and it was recreated to resolve this
circumstance, but it might happen to others.

Also, I discovered that /var/log/local4, the ldap daemon log file,
had grown to 13GB on osgeo1. I disabled logging in /etc/openldap/slapd.conf
and restarted the service and then deleted the old log file.

We can re-enable logging when exmaining problems, but should not likely
leave it active - at least a the level it was at.

PS. I believe John is willing to provide extensive OSGeo access to
hypervisor (or perhaps it's twin?) and it is a heck of a machine.
Suitable to run a number of VMs. It would be sweet if we could actually
sling VMs back and forth between OSU OSL and hypervisor. I think the most
obvious VM(s) I'd like to have on hypervisor would be a Linux and a
Windows build slave for buildbot. Anyone interested in taking on that
task?

I particular we have pretty much depended on Tamas' windows machine
for windows buildbot slaves but it isn't all that reliable. I'm not
sure if it is connection problems, overloading or what. So a windows
buildslave at telascience would be wonderful.

Best regards,
--
---------------------------------------+--------------------------------------
I set the clouds in motion - turn up | Frank Warmerdam, warmerdam@pobox.com
light and sound - activate the windows | http://pobox.com/~warmerdam
and watch the world go round - Rush | Geospatial Programmer for Rent

On Tue, Mar 09, 2010 at 11:48:57PM -0500, Frank Warmerdam wrote:

John was having problems logging into hypervisor using the OSGeo LDAP
access and it turns out the issue was that the johng and gupteshwar
account had the same uidNumber value. I have a mechanism to ensure the
web script that enables shell access does not duplicate uidNumber values
but it appears that one or more previously created values overlapped.

Apparently this LDAP service never had a schemacheck enabled (which is
just now getting to my attention since I've never checked before). I'd
like to claim a maintenance window of maybe just 5 minutes up to one
hour to fix this sort of issues.

Cheers,
  Martin.
--
Unix _IS_ user friendly - it's just selective about who its friends are !
--------------------------------------------------------------------------

On Wed, Mar 10, 2010 at 06:15:41PM +0100, Martin Spott wrote:

Apparently this LDAP service never had a schemacheck enabled (which is
just now getting to my attention since I've never checked before). I'd
like to claim a maintenance window of maybe just 5 minutes up to one
hour to fix this sort of issues.

Will start at 18:00 UTC, expect minor hiccups - when logging into TRAC,
SVN, Telascience machines and the such - for a couple of minutes.
The Wiki is not affected.

Cheers,
  Martin.
--
Unix _IS_ user friendly - it's just selective about who its friends are !
--------------------------------------------------------------------------

On Wed, Mar 10, 2010 at 06:48:30PM +0100, Martin Spott wrote:

Will start at 18:00 UTC, expect minor hiccups - when logging into TRAC,
SVN, Telascience machines and the such - for a couple of minutes.

Outage is over and the tests I've done so far look promising.

Cheers,
  Martin.
--
Unix _IS_ user friendly - it's just selective about who its friends are !
--------------------------------------------------------------------------