SSL Replication - why supplier using regular port?

My consumer is using the default SSL port 636, but the supplier port is
fixed with 390. I am using regular port 390. Is that mean referrals are
made over non-SSL(regular) port, and only replications done over SSL? I
would like all communications between the consumer and the supplier to be
over SSL.
There is an optional item under "Replica Settings" where I could specify
URLs for write operations for referral, but it would not accept
ldaps://myhost:636. It would take ldap://myhost:636. The iPlanet doc said
that if I specify ldaps:// then referrals would be done over SSL not over
regular port. What am I doing wrong?
Also, the iPlanet doc said I must not use the same port number for regular
and SSL. But did not explain why. We are thinking of using only SSL port.
So the question came up - so why not just disable the regular port?
Thanks in advance,
Choi

Hallo Armin,
Please check the ownership of the files in your /opt/iplanet/servers/alias
directory. All files should be owned by the user under slapd is running.
I hope this helps.
Bertold
"Armin Wenz" <[email protected]> wrote in message
news:[email protected]..
Hallo all
We are using iDS 5.0 on a Solaris. When I want to try a replication over
SSL I got the following error from my supplier server:
NSMMReplicationPlugin - Connection Init Failed. Can not establish secure
replication to consumer leela:13636
- SSL alert:
ldapssl_clientauth_init(/opt/iplanet/servers/alias/slapd-replica-supplier-ce
rt7.db)
failed -8174 (error -8174 - security library: bad database.)
What does this mean: bad database? Is the database corrupt or are there
any entries missing?
Both Servers (supplier and consumer) are running with SSL enabled and I
can connect to both via ldaps. Replication over an unencrypted line is
working as well.

Similar Messages

  • HT3625 I have a 2012 macBook Pro 13" and the option "Use audio port for" does not appear at all in the sound menu. why is this? im running  mountain Lion 10.8.2

    I have a 2012 macBook Pro 13" and the option "Use audio port for" does not appear at all in the sound menu. why is this? im running  mountain Lion 10.8.2

    Because line-in has been removed.
    It does allow for an Apple headset with mic., but I don't know if it would work with third-party ones.
    You'll need to use a Griffin iMic or similar to use line-in via a USB port.
    The same goes for the 15" retina, the newest MBA and the new iMac (whenever it finally arrives).

  • Why can't I hear Siri when I use microphone earphones? She can hear Wme, and I can hear her when I use regular earphones? I thought it was the earphones, do I tried my

    CAnt hear Siri when using microphone headphones. She can hear me when using them; i tried another pair, and same thing. I can hear her when using regular headphones, though. Anybody have a suggestion?

    is I learn still around -? That was VERY HANDY!

  • What are the pros and cons of using a port system.

    Hello All,
    I'm a new explorer in the OS X UNIX world, and have installed macports, and, for the most part, succeeded in building and using a number of scientific applications.
    I have noted a somewhat negative attitude by some on the use of port systems, while others seem quite content with them.
    When making my decision to use macports, these "selling points" seemed desirable to me:
    ¤ Confines ported software to a private “sandbox” that keeps it from intermingling with your operating system and its vendor-supplied software to prevent them from becoming corrupted.
    ¤ Allows you to create pre-compiled binary installers of ported applications to quickly install software on remote computers without compiling from source code.
    Especially the first point seems valuable, but am I deluding myself? Or, am I losing functionality/ flexibility? Or, am I just missing out on manually installing lots of dependents?
    _I'm not trying to start a feud, here._
    I'm just looking for some pointers (preferably well-substantiated) from those more knowledgeable than me, before I am any further committed to a choice I might later regret.
    Thanks,
    PWK

    The biggest drawback/complaint I have is that you're bound by the implementation/installation policy of whoever built the port.
    For example, take the installation issue - all software gets installed into some specific directory which is great one one hand - fewer compatibility issues with conflicting versions from what Apple provide. The downside, though, is that nothing on your machine will use these versions unless/until you tweak them.
    For example, maybe you want to install the MacPorts version of PHP, great, but the standard Apache won't use that, so you either need to install the MacPorts version of Apache, or tweak your Apache installation to use the non-standard PHP version.
    Well, what about PATHs, I hear you ask? well, sure, you could prepend the MacPorts/fink/whatever directory to your $PATH, but then you always use the MacPorts/fink/whatever version of any installed software which might not be what you want.
    This becomes more of an issue in a multi-server environment where you have multiple systems that all need tweaking/maintaining - nothing worse than setting up a new server by copying an existing installation, only to find that it depends on MacPorts/fink/whatever being installed.
    The corollary to this is that these package managers often install ancillary software that you do not need, nor want. It might have improved since I last looked, but installing either MacPorts or fink, for example, installs whole new versions of perl, GNU tools (gzip/gunzip, etc.), curl, and more - they even install new copies of openssl/ssh.
    I don't want these. These already exist on my system so what are they needed for? Why can't they use the standard copies? Are they 'tweaked' in some way? How? why?
    The secondary issue is that you are limited to the port's implementation - especially compile options - which may not be ideal for your machine.
    Unlike most GUI-based software, much open-source software uses compile-time options to configure the executable. Now the port installer might do a reasonable job of tweaking the installation, but it's not psychic so there will be cases where you end up with sub-optimal installations. Sure, they might work well enough, but that doesn't beat knowing what those options are up-front and building your own.
    Now there have been cases where I've tried to install software and almost given up when faced with a daunting list of dependencies (try RRD, or PHP w/ GD, for example) and have almost given up, but when you succeed the satisfaction of getting it working, plus the fact you now know how to do it counts for a lot.
    Now, do I wish that Apple would do a better job of keeping up with the latest versions of the open source software they include in Mac OS X? absolutely - isn't that what Software Update is all about??). But I also wish the port maintainers would spend more of their time updating the original source configure and make scripts to incorporate whatever changes they're making to the code so that Mac users can easily use the same source distribution as other UNIX flavors.
    And right there is the final rub IMHO - all the while the port managers create their distributions of common tools Mac OS X is treated like a poor step-child that's kept in the cellar. OK, maybe not that bad, but there's no reason why anyone who wants to install open source software on a Mac should need much more than:
    (download>
    ./configure
    make
    sudo make install
    it really isn't all that hard. Too often the port managers perpetuate the myth that Mac OS X is too different from other UNIX systems to work with the standard tools that everyone else knows.
    Now, maybe I'm also too old for this game since you always downloaded and built tools yourself when I started, and maybe package managers on Linux (which may have the same issues I've complained about) have helped elevate Linux in the mindset of a younger generation who are looking for a quick fix. All I can say to that is…
    GET OFF MY LAWN! :-D

  • How to connect macbook to sony bravia using hd15 port

    Im trying to hook up my white macbook into my sony tv. the manual says to use a hd15-hd15 cable. what do i need?
    please help!

    IF your white MB has a miniDVI output, one of these should do the trick...
    http://store.apple.com/us/product/M9320G/A?fnode=MTY1NDA3Ng&mco=MjE0ODQzNQ
    Of course, you will also need a 3.5 to L/R audio cable for sound and you will need a VGA cable.
    Why not use an HDMI port if you have free one? Better picture.

  • Why to use JMS????

    Hi All,
    i am new to JMS, can any body tell me Why to use JMS??
    i know it used to send message but for why???
    if u answer me with an example it will be useful for me.
    thanks in advance.

    Hi,
    Well one very good reason to use JMS is to keep applications that produce information decoupled from applications that consume information. With this decoupled approach, you can any number of producers and consumers sending and processing information...thus making your solution very scalable.
    If you think of an online ordering system. A user plugs in a bunch of information about a product they wish to order. Once the form is completed, they hit the submit button. Now you can take one of two approaches:
    1. You can have an Enterprise Java Bean ( EJB ) service the order request. That EJB could then communicate with other EJBs within an inventory system to perform a bunch of checks and eventually hand it off to the appropriate system to fulfill the order. From the user's perspective, they are going to have to wait until all of that processing has completed before they can move on. Not a very nice situation. There is a potential that the user could be sitting on their order screen for mintues!!
    2. The other approach is to wrap all of the information supplied on the order form into a JMS message and forward the message to an appropriate Topic or Queue. On the other side of that Topic or Queue an inventory system subscribes for order messages. The nice thing about this approach: as soon as the message is sent off to the Topic or Queue, the user regains control of the screen and can continue browsing. Another benefit, you can have multiple consumers processing orders.
    I apologize for the length of the response. These are only two benefits of using a Messaging-based approach....there are many, many more.
    Regards,
    J.

  • Send command to modem using serial port and capture the response in the labview

    hello.
    I am doing my shool project.
    I want to send command to modem using serial port and get the response in the labview.
    When i run my program and enter"AT", only messy code will be displayed.
    can anyone help me? thanks 

    Dora0512 wrote:
    Thanks for you all. My partner got it already.
    I am doing send sms part.
    Can anyone tell me why my program is not so steadily?
    It means this program can run. But somtimes I cannot receive sms. sometimes can
    Basically, it is not well-written from both a LabVIEW and a communications point of view.  Unfortunately, I can't elaborate because today is an exrtremely busy day at work.  I'm hoping this bump will prompt someone to help you with your problem.  If you could also provide us with the programmer's guide or the manual for your equipment, that would be extremely helpful.
    Bill
    (Mid-Level minion.)
    My support system ensures that I don't look totally incompetent.
    Proud to say that I've progressed beyond knowing just enough to be dangerous. I now know enough to know that I have no clue about anything at all.

  • Why we use exception ???

    Why we use Exception ??anyone knows what are the 3 keys point below describe about..??
    There are 3 main Advantages of using Exception
    1.Separates error handling code from "regular code
    2.Propagating erros up the call stack (without tedious programming)
    3.Grouping error type and error differentiation
    TQ.

    hi,
    1) you can catch those exceptions and write extra classes for handling/log them, so you do not have to do between the lines of source
    2) if an uncaught exception happens an errorstack will be invoked. On the stack you can see, where the exception started and which classes are involved
    3) you can have very special erros, for example all errors which occurs on files (normally it is an IOException), you can define your own exceptions so you can say, i.e. line 503 doesn't contain what it should.
    With this way you can resolve very well where an exception raises and why it happens.
    hope it answers
    regards
    freak

  • X4200 - static IP configuration  error (using serial port)

    I try to setup a static IP address of ILOM on a Sun X4200 server using serial port
    After login as root I use command from manual:
    set /SP/network pendingipaddress=192.168.2.123 pendingipnetmask=255.255.255.0 pendingipgateway=192.168.2.1 pendingipdiscovery=static commitpending=true
    but system say
    "invalid command syntax"
    Usage: set [target] <property>=value> [<property>=<value>...]
    Problem is with "commitpending" command but i don't know why, anyone know the possible reason?
    Sincerrelyy
    Cyprian Sawicki

    I try to setup a static IP address of ILOM on a Sun X4200 server using serial port
    After login as root I use command from manual:
    set /SP/network pendingipaddress=192.168.2.123 pendingipnetmask=255.255.255.0 pendingipgateway=192.168.2.1 pendingipdiscovery=static commitpending=true
    but system say
    "invalid command syntax"
    Usage: set [target] <property>=value> [<property>=<value>...]
    Problem is with "commitpending" command but i don't know why, anyone know the possible reason?
    Sincerrelyy
    Cyprian Sawicki

  • Mail changes "Use custom port:" to 587

    I have set Mail to use SMTP port 25 "Outgoing Mail Server (SMTP)->Edit SMTP server list...->Advanced->Use custom port: 25"
    Restarting Mail doesn't effect the setting, but if I restart the system it will change that custom setting to 587. Why?
    Anyone else having this problem?

    I was having this problem too. I ended up rebuilding my user account, and then my mail accounts, from scratch. The problem, and several others, are gone now.
    I am testing SL on two other computers and one of them is having the problem -- Mail forgets to use port 25 for SMTP.

  • Oracle. CentOS 6.2. NETCA. Use another port number.

    Hello! I know that oracle is not supported Centos.
    But question is why netca can not use standart port, or any other port.
    OS and oracle run in vmware. Network NAT. Os is run without X server. But it connect on ssh with other OS with X server.
    P.S.
    Sorry if my English is bad for you.
    Edited by: 948645 on 25.07.2012 3:24

    948645 wrote:
    Hello! I know that oracle is not supported Centos.
    But question is why netca can not use standart port, or any other port.
    OS and oracle run in vmware. Network NAT. Os is run without X server. But it connect on ssh with other OS with X server.
    P.S.
    Sorry if my English is bad for you.
    Edited by: 948645 on 25.07.2012 3:24lsnrctl start
    above will succeed when NO listener.ora file exists
    in other words, you do not need to run netca.

  • Why when using Adobe Bridge,  I apply a star rating,  the rating does not show up in Photoshop Elements? [tags]

    Why when using Adobe Bridge,  I apply a star rating,   the rating does not show up in Photoshop Elements.  I use Elements as my organizer and Bridge to view as it is much more user friendly.  Anyone any solutions??

    Most likely you have set the wrong file as the external editor. You don't want the obvious one; that's just a link to the welcome screen. Go back and choose this one, which is hidden away inside the folder Support Files:

  • Help in query using regular expression

    HI,
    I need a help to get the below output using regular expression query. Please help me.
    SELECT REGEXP_SUBSTR ('PWRPKG(P/W+P/L+CC)', '[^+]+', 1, lvl) val, lvl
    FROM DUAL,(SELECT LEVEL lvl FROM DUAL
    CONNECT BY LEVEL <=(SELECT MAX ( LENGTH ('PWRPKG(P/W+P/L+CC)') - LENGTH (REPLACE ('PWRPKG(P/W+P/L+CC)','+',NULL))+ 1) FROM DUAL));
    I need the output as
    correct result:
    ==============
    val lvl
    P/W 1
    P/L 2
    CC 3
    But i tried the above it is not coming the above result. Please help me where i did a mistake.
    Thanks in advance

    Frank gave you a solution in your other thread. You could simplify it if you are on 11g:
    SQL> select * from table_x
      2  /
    TXT
    TECHPKG(INTELLI CC+FRT SONAR)
    PWRPKG(P/W+P/L+CC)
    select  txt,
            regexp_substr(
                          txt,
                          '(.*\()*([^+)]+)',
                          1,
                          column_value,
                          null,
                          2
                         ) element,
            column_value element_number
      from  table_x,
            table(
                  cast(
                       multiset(
                                select  level
                                  from  dual
                                  connect by level <= regexp_count(txt,'\+') + 1
                       as sys.OdciNumberList
      order by rowid,
               column_value
    TXT                                      ELEMENT    ELEMENT_NUMBER
    TECHPKG(INTELLI CC+FRT SONAR)            INTELLI CC              1
    TECHPKG(INTELLI CC+FRT SONAR)            FRT SONAR               2
    PWRPKG(P/W+P/L+CC)                       P/W                     1
    PWRPKG(P/W+P/L+CC)                       P/L                     2
    PWRPKG(P/W+P/L+CC)                       CC                      3
    SQL>  SY.

  • I want to ask something about firefox. why firefox use very much memory? can you develop to reduce memory comsume? this problem is very distrub in my PC with low memory.

    I want to ask something about firefox.
    why firefox use very much memory?
    can you develop to reduce memory comsume?
    this problem is very distrub in my PC with low memory.
    == This happened ==
    Every time Firefox opened

    How much memory is Firefox using right now?
    # Press '''CTRL+SHIFT+ESC''' to load the Task Manager window
    # Click the Processes tab at the top. (Click once near the top of the window if you don't see tab
    # Find firefox.exe, and see how many kilobytes of memory it's using.
    Showing around 80MB when Firefox first starts is normal. Right now, I have 75 tabs open and it's using 500MB - this varies a lot depending on what you have in the tabs.
    Other than high memory usage, what other problems are you experiencing? (Examples include slowness, high CPU usage, and failure to load certain sites)
    Many of these issues, including high memory usage, can be caused by misbehaving add-ons. To see if this is the case, try the steps at [[Troubleshooting extensions and themes]]. Outdated plugins are another cause of this issue - you can check for this at http://www.mozilla.com/plugincheck

  • How to connect Portege M700 to TV using VGA port?

    I bought a VGA to S-video/audio adapter and connected it to my VGA port and to the TV.
    Nothing happened.
    In control panel.... no other display/external display was detected.
    The only postings I have come across use a port emulator or something.
    I have the Portege M700 preinstalled with Vista Business tablet.
    Any ideas would be most welcome.
    Thanks

    Thanks for answering.
    I used an adapter which plugs into the VGA port on my M700 and allows either audio/display or S-video to connect to it. That is what I used, trying to connect via S-video or scart... and I'm afraid it did not work for me ;-(
    It is a VGA to S-video/audio convertor.
    Here is thye ebay link to the adapter I bought for this:
    http://cgi.ebay.co.uk/VGA-to-TV-Converter-S-Video-RCA-Out-Cable-Adapter-UK_W0QQitemZ120343643231QQihZ002QQcategoryZ41993QQ tcZphotoQQcmdZViewItemQQ_trksidZp1742.m153.l1262
    I may be doing something stoopid... I hope I am but it worries me that if it works for you, there must be something wrong with my notebook :-(
    The graphics adapter shows "single display" and the multiple display option is not available there.
    I am confused as my old laptop used to work just fine.
    I am wondering if there is something I need to activate, but there is nothing in the bios setup or control panel.
    I just physically connected them and then clicked on the "connect to external display" as well as checking the graphics options.
    Perhaps the cable is the wrong one ?
    Message was edited by: cinnamongirl
    Also, when I use FN + F5, nothing happens. No windows come up.

Maybe you are looking for