13.07.2015 Views

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>NIS</strong>-to-<strong>LDAP</strong> RestrictionsWhen the N2L server has been set up, the <strong>NIS</strong> source files are no longer used.Therefore, do not run ypmake on an N2L server. If ypmake is accidentally run, such asfor an existing cron job, the N2L service is unaffected. However, a warning is loggedsuggesting that yppush should be called explicitly.<strong>NIS</strong>-to-<strong>LDAP</strong> TroubleshootingThis section covers two areas of troubleshooting:■ “Common <strong>LDAP</strong> Error Messages” on page 244■ “<strong>NIS</strong>-to-<strong>LDAP</strong> Issues” on page 245Common <strong>LDAP</strong> Error MessagesSometimes the N2L server logs errors that relate to internal <strong>LDAP</strong> problems, resultingin <strong>LDAP</strong>-related error messages. Although the errors are nonfatal, they indicateproblems to investigate. For example, the N2L server might continue to operate, butprovide out-of-date or incomplete results.The following list includes some of the common <strong>LDAP</strong> error messages that you mightencounter when implementing the N2L service. Error descriptions, <strong>and</strong> possiblecauses <strong>and</strong> solutions for the errors, are included.Administrative limit exceededError Number: 11Cause: An <strong>LDAP</strong> search was made that was larger than allowed by the directoryserver’s nsslapd-sizelimit attribute. Only partial information will be returned.Solution: Increase the value of the nsslapd-sizelimit attribute, or implementa VLV index for the failing search.Invalid DN SyntaxError Number: 34Cause: An attempt has been made to write an <strong>LDAP</strong> entry with a DN that containsillegal characters. The N2L server attempts to escape illegal characters, such as the+ symbol, that are generated in DNs.Solution: Check the <strong>LDAP</strong> server error log to find out which illegal DNs werewritten, then modify the <strong>NIS</strong><strong>LDAP</strong>mapping file that generated the illegal DNs.244 System Administration Guide: <strong>Naming</strong> <strong>and</strong> <strong>Directory</strong> <strong>Services</strong> (<strong>DNS</strong>, <strong>NIS</strong>, <strong>and</strong> <strong>LDAP</strong>) • January 2005

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!