background image

# cd serverRoot./stop-admin

# cd serverRoot/slapd-instance./restart-slapd

7. Open the new

ds71sp7

directory, and extract the binary files for the new service pack setup pro-

gram by running the

setup

command with the

-b

option.

# cd /path/to/ds71sp7
# ./setup -b serverRoot

8. Run the

setup

program again to install the service pack.

NOTE

When upgrading from an Directory Server instance version 7.1SP4 or older, you must
run the setup script to resolve security issues addressed in 7.1SP5. If you are upgrad-
ing from version 7.1SP5, then this is not necessary.

9. Supply the configuration information as prompted by the installer. An upgrade usually requires this

information:

• Agreeing to the setup and licensing terms.

• The full path to the server root directory (the installation directory) where Directory Server 7.1 is

located; by default, this is

/opt/redhat-ds/servers

.

• The Configuration Administrator's password for the Directory Server 7.1 instance.

The upgrade process beings after all of the 7.1 instance information is given.

2.4. Installing Synchronization Services

If Windows synchronization will be used on a Windows server in conjunction with a Red Hat Directory
Server 7.1 server, then install the 7.1 SP7 Windows Sync services on the Windows machine:

1. Uninstall the Password Sync services. If the Windows sync peer is an NT server, then also unin-

stall the User Sync service. This is described in the Directory Server 7.1 Administrator's Guide,
available at

http://1www.redhat.com/1docs/1manuals/1dir-server/1ag/17.1/1sync.html#2878810

.

Installing Synchronization Services

7

Summary of Contents for DIRECTORY SERVER 7.1 SP7 - S

Page 1: ...d from the copy right holder Red Hat and the Red Hat Shadow Man logo are registered trademarks of Red Hat Inc in the United States and other countries All other trademarks referenced herein are the property of their respective owners The GPG fingerprint of the security redhat com key is CA 20 86 86 2B D6 9D FC 65 F6 EC C4 21 91 80 CD DB 42 A6 0E 1801 Varsity Drive Raleigh NC 27606 2072USAPhone 1 9...

Page 2: ...ation related to installing and upgrading Red Hat Directory Server 7 1 SP7 including prerequisites and hardware or platform requirements Directory Server Supported Platforms Directory Server 7 1 SP7 is supported on the following platforms HP UX 11i PA RISC 64 bit Red Hat Enterprise Linux 3 Update 4 i386 32 bit Red Hat Enterprise Linux 4 i386 32 bit Sun Solaris 9 SPARC 32 bit Sun Solaris 9 SPARC 64...

Page 3: ...Support Directory Server 7 1 SP7 supports the following browsers to access web based interfaces such as Admin Express for administrators Org Chart and Phonebook for all users Firefox 1 0 Red Hat Enterprise Linux 3 and 4 and Solaris 9 Mozilla 1 4 HP UX Mozilla 1 4 3 Red Hat Enterprise Linux 3 and Solaris 9 Mozilla 1 7 3 Red Hat Enterprise Linux 4 Microsoft Internet Explorer 6 0 Windows supported on...

Page 4: ...t Network RHN http 1rhn redhat com is the software distribution mechanism for Red Hat customers When purchasing the entitlements for Red Hat Directory Server 7 1 SP7 you will also have received account login information for Red Hat Network 1 Log into Red Hat Network 2 Go to the Channels tab and select the Red Hat Directory Server 7 1 channel Browse through the complete channel list if needed 3 Go ...

Page 5: ... 3 or 4 system 1 Log in as root 2 Run rpm to upgrade the Directory Server using the package appropriate for your version of Red Hat Enterprise Linux For Red Hat Enterprise Linux 3 rpm U redhat ds 7 1SP7 11 RHEL3 i386 rpm For Red Hat Enterprise Linux 4 rpm U redhat ds 7 1SP7 11 RHEL4 i386 rpm 3 For upgrading from SP4 or earlier Run the setup script again cd opt redhat ds setup setup r NOTE When upg...

Page 6: ... 3 Installing Directory Server 7 1 SP7 on HP UX and Sun Solaris 1 Log in as root 2 Create a new directory for the new Directory Server service pack version mkdir ds71sp7 3 Open the new directory cd ds71sp7 4 Download the Directory Server product binaries file to this directory 5 Unpack the product binaries gzip dc filename tar gz tar xvof filename is the product binaries file the exact name depend...

Page 7: ... and licensing terms The full path to the server root directory the installation directory where Directory Server 7 1 is located by default this is opt redhat ds servers The Configuration Administrator s password for the Directory Server 7 1 instance The upgrade process beings after all of the 7 1 instance information is given 2 4 Installing Synchronization Services If Windows synchronization will...

Page 8: ... The following are some of the most important bugs fixed for Directory Server 7 1 SP7 Along with this service pack some erratas have been issued for Red Hat Directory Server fixing important security and performance issues The complete list of erratas issued for Red Hat Directory Server 7 1 SP7 for Red Hat Enterprise Linux is available through Red Hat Network at ht tps 1rhn redhat com 1errata 1rhe...

Page 9: ...ttribute has a default limit of 3600 seconds one hour To shorten the time limit modify the nsslapd timelimit parameter in cn config For example ldapmodify D cn Directory Manager w password dn cn config changetype modify replace nsslapd timelimit nsslapd timelimit 30 450973 Password policy attributes are not replicated by default However if a password attribute such as accountunlock time was added ...

Page 10: ...ker could exploit this flaw to execute cross site attacks against Directory Server users or administrators who used those web services These errors have been fixed 458171 On HP UX when running an approximate search the search code could return an error code 3 which corresponds to the LDAP error code for exceeding the search time limit This meant that an appropximate search could end prematurely wi...

Page 11: ...rectory Server handled value sets where there were several duplicate non sequential values added to an attribute such as adding foo bar bat foo This leak could only be triggered by an authentic ated user to the Directory Server who had the rights to modify attributes in an entry including self write access and if replica tion was being used This error has been fixed 458677 CVE 2008 3283 458692 458...

Page 12: ...mapped by SASL mapping there are no mapping entries created for them The original SASL mapping entries point to the first suffix Manually create SASL map ping entries that are associ ated with the second suffix 400341 If a user other than the admin user logs into the Console and attempts to change the admin user s password the password is not properly updated Only change the admin user password th...

Reviews: