Unable to make OD replicas - what are IDRangeBegin/IDRangeEnd?

Hello:
I've been having a bit of a struggle with my OD Master (10.4.11 on Intel Xserve, moved from a G5 Xserve). The function of the OD Master seems to be just fine - clients can log in using any method, including kerberos. I was having trouble with creating replicas that were related to kerberos, but I've resolved that. I've been creating and destroying replicas like a madman trying to figure this kerberos deal out, and now it seems that I'm running in to a problem when the password server information is transferred to the replica. Below is a snippet from the log of a replica that I just tried to make a bit ago:
BEGIN SNIPPET *
2008-02-15 16:01:23 -0500 - command: /usr/sbin/NeST -setupreplica 128.175.16.194 diradmin **
2008-02-15 16:10:25 -0500 - NeST command output:
Workaround Bonjour: Unknown error: 0
Workaround Bonjour: Unknown error: 0
END SNIPPET *
During this 'NeST -setupreplica' stage a HUGE ( 25 GB, take a look:
-rw------- 1 root wheel 25274676248 Feb 15 16:09 authservermain
) authservermain file is created. I tried this procedure on another machine that didn't have that much space, and it filled the drive, so I was concerned that it was a procedure that would never end, but today's experiment with a freshly-installed iMac showed that the process really does end.
Now, I have a theory about what's causing the problem, but I don't know enough about the inner workings of the OD replication setup process to know. During the 'NeST -setupreplica' process, a 'mkpassdb' process runs with the following parameters:
/usr/sbin/mkpassdb -zoq -s 5796443 -e 5796943 -n Replica1
So that made me wonder what was causing mkpassdb to create such a huge authservermain file.
I looked at the PasswordServerList attribute of the /Config/passwordserver item of the OD on the master, and it shows the following which is troubling:
<dict>
<key>EntryModDate</key>
<date>2008-02-02T08:22:13Z</date>
<key>IDRangeBegin</key>
<string>0x00000000000000000000000000587053</string>
<key>IDRangeEnd</key>
<string>0x00000000000000000000000000587247</string>
<key>IP</key>
<string>128.175.16.194</string>
<key>LastSyncDate</key>
<date>2008-02-14T21:02:43Z</date>
</dict>
It looks like these IDRangeBegin and IDRangeEnd values are influencing the oversized authservermain file made on the replica and they either ARE the values use when mkpassdb is run during replica creation or are related. I looked at a working OD Master that I have for my classrooms, and the IDRangeBegin (0x00000000000000000000000000000001) and IDRangeEnd (0x000000000000000000000000000001f5) values seem to be reasonable.
Does anyone know what these IDRangeBegin and IDRangeEnd values represent? The number of slots in the Password Server database?
It seems that I'm very close to getting myself back to having a "perfect" OD Master that I can make replicas from. It seems that everything besides the password server gets created correctly when I make my replicas. If there was some way to "reset" the OD Master's ability to make replicas, that would be great. Right now, I don't have any replicas, and it makes me nervous, so I'd like to resolve this as soon as I can. Any help would be greatly appreciated. Thanks.

After looking at the Apple knowledgebase article 304666, which seemed to imply that the IDRangeBegin and IDRangeEnd values do not have anything to do with the contents of the password server database, I decided to edit the LDAP and /var/db/authserver/authserverreplicas file to change the values to 0x1 and 0x1f5, respectively. I also got rid of the EntryModDate and LastSyncDate key/value pairs and the DecommissionedReplicas key/value pair. I did this to sorta get it back to a pristine, pre-replica state.
I restarted the server, and all the functions seemed to be okay. I looked in the Password Server logs, and it seemed okay, too. So, I decided to make a replica, and it went without a hitch. The resulting replica has a running password server on it, and kerberos and replication seems to be okay, too.
So far, it looks like a success, but I'm always nervous about changing stuff in the guts of a system without really knowing why I did it. I will keep an eye on it.

Similar Messages

  • Unable to make Port Replicator 43R8770 work with T400

    I have a relatively new (four months old) T400 ThinkPad running on Windows XP SP3, and I have been unable to get the Port Replicator to work at all with it.  I am attempting to simply mirror my notebook display on a larger monitor, and have installed the latest driver for the replicator from the Lenovo website.  The system tray icon for the replicator never appears, even after installing and uninstalling the driver, and so I am unable to get the two monitors to mirror each other. 
    The only indication I have that something is wrong is during the driver install I receive an "Application Error" message for some file labeled ed_16208.exe.  I know that the Port Replicator works fine, as I have been using it for the last four months with an older T42 notebook running on XP SP2.
    The Lenovo phone rep was completely unable to help me.  His only suggestion was that it must be that the replicator doesn't work with SP3, since it worked with SP2 on the older model, and that I shouldn't have had Windows automatic updates turned on.  (I'm serious.)  I reminded him that Lenovo shipped the new T400 to me with SP3 installed, and his response was that it was therefore a Microsoft problem and that I should try to roll the notebook back to SP2.  At that point I told him I might as well just use the replicator as a door stop.
    I am completely frustrated.

    An update.  I was able to get the Lenovo Display Adapter system tray icon to appear.  However, I can't adjust the settings on it to get it to mirror, and when I attempt to do so there is an error message on the icon for the Lenovo Display Adapter that states "Change Display Settings Failed: Bad mode while setting \\.  \DISPLAYV1 enabled in registry"
    Does anyone have any ideas?

  • Unable to contact previous owner, what are the options? (2nd hand phone)

    here in the philippines, buying second hand products is a common practice as we are not as economically endowed like the united states. so if we're lucky to earn enough, outside of our regular expenses, we too would like to enjoy the fascinating technology of apple. hence, 2nd hand phones. but what do we do with this icloud lock? does it mean that the money set aside from our measly income is for naught?

    Welcome to the Apple community Don.
    Unfortunately, you cannot do very much with your phone unless you get assistance from the previous owner, they should either provide you with the password to unlock it or remove their account from the phone entirely remotely through iCloud.com > Find My Phone.
    Surely it's not common to purchase 2nd hand phones I the Philippines without checking them, knowing the seller or obtaining a receipt.

  • What are the logical decisions to make a plant

    Dear All,
    i know that i am going to ask a very basic question but it is not as simple as seems to be.
    Scenario is as undermentioned:
    At one premises there is a production unit for cement manufacturing and another unit for power generation. i have made cement plant now please tell me eighter we should make power generation plant or we can handle it under the same cement plant.
    Requirement for power generation are that they have to produce power for cement plant and also they sell power to Gowernment. please guide me why we make plant and on the bais of what factors we decide plant.what r the technical reasons to make a plant. what are the requirements which are fulfilled if we make power generation as a plant and what r the requirements which are not fulfilled if we dont make it as a plant. 
    please guide me the basic factors on the basis of which we decide plant.  in detail

    Hi,
    You might be knowing that, a Plant is a place where production of goods, services are done and provided to external parties.
    As you are generating cement from one plant and power from another plant and selling both the product. So, you have to capture the cost and profit for both and you create two different plant.
    Now you come to conclusion, if you don't create two plants what will happen? It's self explanatory.
    Madhava

  • I am unable to make any purchases in the App Store. PLEASE HELPPPP!

    I am unable to make any purchases in the App Store. I have $15 in the account but I still can't buy any games. It only lets me purchase free games. It says "this Apple ID is now locked and unable to make any purchases"

    You are in the same country as you have on your iTunes account, and you haven't been trying to use another country's store ?
    Try contacting iTunes Support (these are user-to-user forums) and see if they can/will unlock it : http://www.apple.com/support/itunes/contact/ - click on Contact iTunes Store Support on the right-hand side of the page

  • Yosemite is awful- unable to empty trash, volume options are haywire, error codes on file management, and files won't replace when moved. What are my options at this point?

    Like the topic - "Yosemite is awful- unable to empty trash, volume options are haywire, error codes on file management, and files won't replace when moved. What are my options at this point?"
    I installed this OS, and it looks nice, but it's terrible to use. I randomly have the volume controls get disabled, and sometimes the volume menu in the system tray does nothing when adjusted which I've never seen in an OS before. The trash won't empty. When I try to drag and drop newer files over existing ones, nothing happens. The old ones just stay there. I have to delete the old ones and then move the new ones. And when I go into the protected files to manage audio plugins (I make music), the first thing I hit are error codes galore, and password prompts that either don't popup when they should, or don't execute the command after I provide my password.
    What can I do now that I installed the flames of **** onto my computer?

    Back up all data before proceeding.
    This procedure will unlock all your user files (not system files) and reset their ownership, permissions, and access controls to the default. If you've intentionally set special values for those attributes on any of your files, they will be reverted. In that case, either stop here, or be prepared to recreate the settings if necessary. Do so only after verifying that those settings didn't cause the problem. If none of this is meaningful to you, you don't need to worry about it, but you do need to follow the instructions below.
    Step 1
    If you have more than one user, and the one in question is not an administrator, then go to Step 2.
    Triple-click anywhere in the following line on this page to select it:
    sudo find ~ $TMPDIR.. -exec chflags -h nouchg,nouappnd,noschg,nosappnd {} + -exec chown -h $UID {} + -exec chmod +rw {} + -exec chmod -h -N {} + -type d -exec chmod -h +x {} + 2>&-
    Copy the selected text to the Clipboard by pressing the key combination command-C.
    Launch the built-in Terminal application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ Open LaunchPad. Click Utilities, then Terminal in the icon grid.
    Paste into the Terminal window by pressing command-V. I've tested these instructions only with the Safari web browser. If you use another browser, you may have to press the return key after pasting.
    You'll be prompted for your login password, which won't be displayed when you type it. Type carefully and then press return. You may get a one-time warning to be careful. If you don’t have a login password, you’ll need to set one before you can run the command. If you see a message that your username "is not in the sudoers file," then you're not logged in as an administrator.
    The command may take several minutes to run, depending on how many files you have. Wait for a new line ending in a dollar sign ($) to appear, then quit Terminal.
    Step 2 (optional)
    Take this step only if you have trouble with Step 1, if you prefer not to take it, or if it doesn't solve the problem.
    Start up in Recovery mode. When the OS X Utilities screen appears, select
              Utilities ▹ Terminal
    from the menu bar. A Terminal window will open. In that window, type this:
    resetp
    Press the tab key. The partial command you typed will automatically be completed to this:
    resetpassword
    Press return. A Reset Password window will open. You’re not going to reset a password.
    Select your startup volume ("Macintosh HD," unless you gave it a different name) if not already selected.
    Select your username from the menu labeled Select the user account if not already selected.
    Under Reset Home Directory Permissions and ACLs, click the Reset button.
    Select
               ▹ Restart
    from the menu bar.

  • Unable to make in app purchases in one app. What do I do?

    Unable to make in app purchases in one app. What do I do?

    What happens when you try to do the in-app purchase, does the 'buy' button not work, do you get any error messages ... ?
    If you are getting a message to contact iTunes Support then you can do so via this link and ask them for help (we are fellow users here on these forums) : http://www.apple.com/support/itunes/contact/ - click on Contact iTunes Store Support on the right-hand side of the page, then Purchases, Billing & Redemption
    If it's a different problem ... ?

  • I have created a quotation in CRM system. I want that to be downloaded into ECC, so that, I can create a sales order there with reference to that quotation. So, what are the parameters that I need to set in CRM system so that my quotation gets replicated?

    Dear Experts,
    I have created a quotation in CRM system. I want that to be downloaded into ECC, so that, I can create a sales order there with reference to that quotation. What are the parameters that I need to set in CRM system so that my quotation gets replicated without any error?
    Please help me in this regard. An early and in detail step by step guidance is highly appreciated.
    Thanks,
    SMTP

    It may be best to recreate the folder and the smart playlists from scratch.
    tt2

  • What are the steps to make it seamless for a customer to use the install program and then use the installed program?

    I wrote an install program (.exe) that is downloaded from a website.  When run, it 1) leads a customer to browse to a directory, and 2) copies files (.exe, .dll, etc.) from a website to that directory.  When I run, the installed program works.
    What are the steps to make it seamless for a customer to use the install program and then use the installed program? 
    bhs67

    This site https://msdn.microsoft.com/en-us/library/vstudio/2kt85ked%28v=vs.110%29.aspx provides a basic description of the Visual Studio Windows Installer. 
    Near the bottom of the page is "You can unlock all the features of InstallShield by paying to upgrade to the full version of InstallShield."  Where do I find info that describes the differences between the "free" and the "full"
    versions?
    bhs67
    Hello,
    The default feature does support the task for your requirement, so there is no need to pay for the other features unless you want to use some feature which is not free.
    In addition, as this thread
    InstallShield LE not available with VS 2012 RTM? shared, even through there is a link to InstallShield LE in the New Project dialog under Deployment solutions, but it belongs to third-party that I would recommend you consider posting this issue
    at the following forum to get supports about InstallShield.
    http://community.flexerasoftware.com/forumdisplay.php?133-InstallShield
    Regards.
    Carl
    We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
    Click
    HERE to participate the survey.

  • What are the settings required to block a particular IP to make connection on particular port no running on another IP?

    Problem:
    -   What are the settings required to block a particular IP to make connection on particular port no running on another IP?
    Environment:
    Operating System            : - Windows XP Service
    Pack 1
    System type                     : - 32 – bit Operating System
    Description: - We
    have requirement to block Port access from particular IP. It is specific requirement for a machine.
    We have service which is running on
    Server with IP: - 10.14.15.116 on
    Port Number 3366 and we need to
    block Client Machine IP: - 10.14.15.114 to make
    any connections with server on this port. Not even client machine
    should be able to telnet on server on port 3366.
     I
    will be really thankful.
    For any kind of input which can assist us to complete the requirement.

    Does it allow in same way with firewall setting in Windows Server 2008?
    I will read in details shared link, but as a matter of urgency; kindly let us know, if we can follow some concise instruction to do above activity.
     I
    will be really thankful

  • What are the steps needed to make the field in the DFF Additional Information for Agent only take numbers, commas & hyphens?

    Hello All,
    What are the steps needed to make the field in the DFF Additional Information for Agent only take numbers, commas & hyphens?
    Navigation
    Bob Sales manager<Ebiz form<service request tab<SR type<DFF<additional information for agents <cheque number
    The field Cheque number Character allowed (, -) in the DFF Additional Information for Agent should only take numbers
    Thanks & Regards
    Ayesha

    Thanks Sridar
    If we use Number we cannot separate the cheque numbers with , or -
    We need to enter numbers along with comma and '_' in cheque number field.
    Thanks & Regards
    Ayesha

  • What are the materials used to make a macbook pro?

    What are the material used to make a macbook pro?

    http://www.apple.com/environment/reports/
    In these reports are breakdowns like this:
    as well as other information regarding, for instance, restircted substances.

  • My phone just has searching... up in the top left hand corner and it has been like this for 4 hours now! i am unable to make calls or texts. what should i do? It is an iphone 5 by the way

    my phone just has searching... up in the top left hand corner and it has been like this for 4 hours now! i am unable to make calls or texts. what should i do? It is an iphone 5 by the way

    Take a look at this link, http://support.apple.com/kb/TS4148

  • What are the differences between the Time Capsule MC344LL/A and MD032LL/A, do both havethe same make of server grade HDD, also any changes in WiFi coverage and networking abilities?

    What are the differences between the Time Capsule MC344LL/A and MD032LL/A, do both have the same make of server grade hard drive, also any changes in WiFi coverage or networking abilities?  Thanks

    Found this info regarding original question:
    What are the differences between the Time Capsule MC344LL/A and MD032LL/A, do both have the same make of server grade hard drive, also any changes in WiFi coverage or networking abilities?  Thanks
    http://www.hardmac.com/articles/402/page1
    http://www.applefritter.com/node/23907
    Hope this helps -
    ; >}

  • I forgot my answers to security questions. I could not change and I am unable to make purchases at the Apple store. What do I do?

    I forgot my answers to security questions. I could not change and I am unable to make purchases at the Apple store. What do I do?

    Go to http://appleid.apple.com and select "Manage your account". Log in with your Apple ID and password, then select Password and Security from the left column.
    You need to know the answers to your existing questions to reset them. If you don't remember your answers, there may be a link on that page where you can have a reset email send to your Rescue email address. This will not appear if you have not provided a Rescue email address, and may not appear even if you did.
    If there does not seem to be any way to reset your security questions, contact iTunes Support here: http://www.apple.com/support/itunes/contact/ They will respond within a business day. Be sure to check your spam or junk mail folders for their response.

Maybe you are looking for