Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 11 Aug 2021 05:33:49 -0400
From:      Carmel <carmel_ny@outlook.com>
To:        freebsd-ports@freebsd.org
Subject:   Re: Update of OpenLdap
Message-ID:  <PH0PR16MB4245C4AD54C5E74910DFC0B380F89@PH0PR16MB4245.namprd16.prod.outlook.com>
In-Reply-To: <46245ca6-3f26-5acb-933b-fd8ab864ff30@nethead.se>
References:  <20210807072442.0000095d@seibercom.net> <46245ca6-3f26-5acb-933b-fd8ab864ff30@nethead.se>

next in thread | previous in thread | raw e-mail | index | archive | help
--Sig_/G5Ss7HZfDU7JK_c3+odoYX1
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: quoted-printable

On Wed, 11 Aug 2021 10:49:49 +0200, Per olof Ljungmark stated:
>On 8/7/21 1:24 PM, Jerry Seibert wrote:
>> FreeBSD 11.4-RELEASE-p9
>>=20
>> After the recent updating of "openldap", the follow error/warning
>> message is presented whenever I attempt to access the database.
>>=20
>> Aug  7 07:13:57 scorpio slapd[82175]: OTP unavailable because can't
>> read/write key database /etc/opiekeys: Permission denied
>>=20
>> Everything works fine so I don't understand what the problem is or
>> how to correct it, or if it even needs correction.
>>  =20
>
>I have a similar problem and I think the reason is that the=20
>openldap24-sasl-client port vanished and was merged into
>openldap24-client.
>
>However, this made one of our ldap slaves stop working, I think this
>is a showstopper. A switch for this is needed, in the meantime, how do
>we build the client WITHOUT sasl?
>
>20210801:
>   AFFECTS: users of OpenLDAP
>   AUTHOR: delphij@FreeBSD.org
>
>   SASL is now always enabled for OpenLDAP.
>
>   If you use portmaster:
>         portmaster -o net/openldap24-client openldap-sasl-client
>   If you use portupgrade:
>         portupgrade -fo net/openldap24-client openldap-sasl-client
>   If you use pkg with binary packages:
>         pkg set -o net/openldap24-sasl-client:net/openldap24-client
>

I had to change the permissions on the /etc/opiekeys file to 0666 to
stop the message from repeating. I don't know if that is actually a
safe solution, but it works.

I agree with you that the change to this port was probably not well
thought out.

--=20
Carmel

--Sig_/G5Ss7HZfDU7JK_c3+odoYX1
Content-Type: application/pgp-signature
Content-Description: OpenPGP digital signature

-----BEGIN PGP SIGNATURE-----

iQiOBAEBCAb4FiEELeCiu2K+9VmEYYgTgHBP8gv9FXcFAmETmYPGGSYAmQGNBF+4
XLcBDACugGY6FgAQjxK3dis7pVaE6Fb4yPpCb4NXprsj3yXXoFmCPbXwitivNxmb
ec8elKabvywFSzOy5aZ6R3jeYu4ksLDPrZ6Pli40XRTkmIpGMeGzraRU6PbiQUbn
1DB8mpZSSI7Kcye/CwITTBnEWH9VMEYa+OPqTyl3GaJlbk46Gf3hYKsYVMt6a+SD
y6FUIVlhUgj80aZa9JVgI7zLrGPktPE45deNJXF+R0jXUXyDWRuhjPv/wOYUUkdh
Z9UhGcLJaQHBGbuOJWC5JI/uHwv6JA3KYC0k4tvKSG+zt1eqjjOYGQ15zIfsPB6d
WzKEr0doB2E3YGyGmfPF4Tjxx43CvJGzuOjnQx/372lM+3/fyCESO4quJJmS2GfB
UUW0OpP68/zcI9poSQa5Vmql/AnxL0SUY5WWtC8dpUqOlnYWz9+/nPq48WQZue49
XlMXOZILHcJUqKnGnOWVe9o5imP0TNFN09rhYuLAxi0GgudgS84sXoqHFPFyWM6b
C+RV/YEAEQEAAbQoR2VyYXJkIEUuIFNlaWJlcnQgPGdlcmFyZEBzZWliZXJjb20u
bmV0PokB0QQTAQgAOwIbAwULCQgHAgYVCgkICwIEFgIDAQIeAQIXgBYhBC3gorti
vvVZhGGIE4BwT/IL/RV3BQJfuGKyAhkBAAoJEIBwT/IL/RV39AgL/izMdmr1Qucb
hMzTvcRp3bGEyJpNDC1OQ87ZrwjEjjIKeInSo9h05eS7c4Sfr1t4EnhemuH5PyZC
N1TZN4aE8BKH//B2ohJl9dC+4Os6kkSbGtZ6WMXvndOHzEmmYGMHNIR2Yyq+ujGm
vvbWwKbVUKWpXV2hhhdwGQafSyuWEryQ4dDP5wpDBvLv3VSVoyJsMJPuLDi3v59P
ZiJEMuDEPfWVHFU6ZhFi9sP/0b3qNezklzKuKi25PS/dm/300PSwJPoI82hW/MkN
180rAJx2oWU80r7wkhDUHlBqFTAQ13c1/qcXEdF732l0fu/0j3HGYZusamGeY2Yw
/ymEOQcadf3xT2at5fDhR8nKQm8kr1YH3X22I7WzoLIKkQcTnRUWqaXo0LRQkFKU
zOmwCf6lqCpMCWmliRNls2jwsjscGFI8arLCIfawm8JtsUxeiRWZdC9PTGi/zMFX
I27JBPYavFZxx1bPyLzLLsQI8pjP7z2+AxiycGalMWZWgnSJHGB/UbkBjQRfuFy3
AQwA2mcUiW4P7Gy/dSyt/H02g+3E2OL6nuJ9vg3isebMPhTjUQwGdUKF8MLEfR9L
rrb866h0VITW2kD60YZziUtY5GgChPgqnFO1ynDDX742RKdUkzEQunXrNxZBeuHw
JIazEU5lBTaKrtI+MfkLlD88EBlfQhZnpG7E/wkGOAhmorpTIecAxA07kV5+2XH5
EGYPjceb+kU4k97I7b6V/UeLyd28ude3aMf69OHFAyMHpxZqMEoXaOOLrRF+MuS+
RiB75heLc5TIdv86yZZGYU2o0HnIA6Q9rF3n3xUC2OUTrzHZ3AFFkyERh3CbvUDt
vxrbPBNbBs6r1IOdcaDvtwb+c1Ug6lz2AzbldyJWoZunDO4gR2MdXhKAqZLBtQF4
rcDKS6U8KknyMMCPjPhOWXGneCsmT3bY4Qem7uAFepMZIzR0Sj2Bqf8XaRuKE8j2
LwecOKev5bGAkmI3i8D/3d+w5ttFYrag79Ofd2fJYfGUnqkdz4JLuQa38N+9D6g8
yPLbABEBAAGJAbYEGAEIACAWIQQt4KK7Yr71WYRhiBOAcE/yC/0VdwUCX7hctwIb
DAAKCRCAcE/yC/0Vd94EDACghnb9rXxQK63+EGuGTJA0Vm3N9lQXMLXOGx00+p36
vxKDeN+/JIm3aMdP1WdCrZlWLiI8SQUDbFUrG/7j2GmCkVpi2/EOFJBvrTP5zLh4
yHE2ZwaKi+YH+ugUxFXgrWrvn6yQzDetakAnwFvbBTG5uUNgVBqOwCr6MzWKBe/g
yruRojHyHTFY6kX3B7RPzzLDc9BnPWdewQLvavsrTKayjuIIhanPKSK9+7sSIybu
0BgGyGBRAaWJ6M1Uh+AURMZLz6l37+/fGJrSzb4DiwvlE4AVSIbY42MVco8GK9tA
8QBeFua4+e4dU7dCUEkTMu5hlIp22Zt1Yktut2IzOzTD7GVvSOoQWYqvLow+6i0V
gQ5Tot75wn4zPhyPv7A/iJLmWqxiz1kc2bato1u+3ap9s48UKa7nWMwA78gOAIV8
SUaeoQ1qA859TrFJejISkJEBTMH6tQuPIu17XG/oIABy/WzuGIBeL5X9StZv9a06
H94HvlnAwn48TZxSvamIu5QACgkQgHBP8gv9FXc+Igv+IF7QKUHD+W9mjeB9xnI7
ym5/rIRxuRjl7MQ/ws648ns7KxtaYPaXhYrtPehsgpAzk4LMP0R9ee8tTEz2aAQE
HLQsSiPN6nth8LuuvjPHoLn6attpkqasdTVvTsMo/wfhh6CnuueKId+zjZPRO1G9
OwKw/cwHPhmXVQxqn+/Lrl0dwgzajlARZ96Sp2p+/HiYnaATqC4v0IwiVBkm0SRj
NSTXDxGAGGHNWQZHBwtMDzsE3p531Ct2ZTpjCY778pIbOInBpgtAiNQAwwn02yng
MOIf3qND/PSWGuTN47LNNptcb+CCk8emDlntb5AE/D3r/v4yaPUiUKHresM4zd0d
6pzAs6IUOzDq/GbQ0wksKXTKSfm7XAw97DPO51+q2t9t91m81yCnRyR0Sa6zVeRO
7hpRoONvQTXcVsNf0peyhiC7y5Khqw3qP35mNa5bf3B9jRTCXaSpvLSqBTu7rdfU
PMTMS5nKMF5rH3vRbCm+0o8O8dpc4OanucmFxtH8sczc
=FcZZ
-----END PGP SIGNATURE-----

--Sig_/G5Ss7HZfDU7JK_c3+odoYX1--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?PH0PR16MB4245C4AD54C5E74910DFC0B380F89>