background image

NOTE

The SSL databases or keystore are preserved and can be re-used after upgrade is
complete.

2. Copy the the updated

msi

files from

/opt/redhat-ds/winsync/

to the Windows system.

3. Double-click the new

msi

files to install them.

4. Reboot the Windows system after re-installing the Password Sync and, on NT, User Sync ser-

vices.

5. Perform a full resynchronization between the Directory Server and Windows sync servers.

a. In the Directory Server Console, click the Configuration tab.

b. Expand the Replication folder in the left navigation window.

c. Click the name of the Directory Server database which is synchronized with the Windows direct-

ory, and select the sync agreement.

d. Select manual synchronization from the drop-down menu.

3. Bugs Fixed in Directory Server 7.1 SP7

The following are some of the most important bugs fixed for Directory Server 7.1 SP7. Along with this
service pack, some erratas have been issued for Red Hat Directory Server, fixing important security
and performance issues. The complete list of erratas issued for Red Hat Directory Server 7.1 SP7 for
Red Hat Enterprise Linux is available through Red Hat Network at

ht-

tps://1rhn.redhat.com/1errata/1rhel-dirserv-71-errata.html

.

Red Hat Directory Server 7.1 SP7 is released as an update as Erratum RHSA 2008:0596, which is
asociated with Bugzilla #453229.

Bug Number

Alternate ID

Description

233642

The change sequence numbers in multi-master replication had
a built-in skew to accommodate differences in the clocks on
master servers. However, this skew could grow under some
circumstances to the point that it falsely hit the maximum al-
lowed skew (one day by default) and stopped replication en-
tirely. Because the problem was in the timestamps of the CSNs

Release Notes

8

Summary of Contents for DIRECTORY SERVER 7.1 SP7 - S

Page 1: ...d from the copy right holder Red Hat and the Red Hat Shadow Man logo are registered trademarks of Red Hat Inc in the United States and other countries All other trademarks referenced herein are the property of their respective owners The GPG fingerprint of the security redhat com key is CA 20 86 86 2B D6 9D FC 65 F6 EC C4 21 91 80 CD DB 42 A6 0E 1801 Varsity Drive Raleigh NC 27606 2072USAPhone 1 9...

Page 2: ...ation related to installing and upgrading Red Hat Directory Server 7 1 SP7 including prerequisites and hardware or platform requirements Directory Server Supported Platforms Directory Server 7 1 SP7 is supported on the following platforms HP UX 11i PA RISC 64 bit Red Hat Enterprise Linux 3 Update 4 i386 32 bit Red Hat Enterprise Linux 4 i386 32 bit Sun Solaris 9 SPARC 32 bit Sun Solaris 9 SPARC 64...

Page 3: ...Support Directory Server 7 1 SP7 supports the following browsers to access web based interfaces such as Admin Express for administrators Org Chart and Phonebook for all users Firefox 1 0 Red Hat Enterprise Linux 3 and 4 and Solaris 9 Mozilla 1 4 HP UX Mozilla 1 4 3 Red Hat Enterprise Linux 3 and Solaris 9 Mozilla 1 7 3 Red Hat Enterprise Linux 4 Microsoft Internet Explorer 6 0 Windows supported on...

Page 4: ...t Network RHN http 1rhn redhat com is the software distribution mechanism for Red Hat customers When purchasing the entitlements for Red Hat Directory Server 7 1 SP7 you will also have received account login information for Red Hat Network 1 Log into Red Hat Network 2 Go to the Channels tab and select the Red Hat Directory Server 7 1 channel Browse through the complete channel list if needed 3 Go ...

Page 5: ... 3 or 4 system 1 Log in as root 2 Run rpm to upgrade the Directory Server using the package appropriate for your version of Red Hat Enterprise Linux For Red Hat Enterprise Linux 3 rpm U redhat ds 7 1SP7 11 RHEL3 i386 rpm For Red Hat Enterprise Linux 4 rpm U redhat ds 7 1SP7 11 RHEL4 i386 rpm 3 For upgrading from SP4 or earlier Run the setup script again cd opt redhat ds setup setup r NOTE When upg...

Page 6: ... 3 Installing Directory Server 7 1 SP7 on HP UX and Sun Solaris 1 Log in as root 2 Create a new directory for the new Directory Server service pack version mkdir ds71sp7 3 Open the new directory cd ds71sp7 4 Download the Directory Server product binaries file to this directory 5 Unpack the product binaries gzip dc filename tar gz tar xvof filename is the product binaries file the exact name depend...

Page 7: ... and licensing terms The full path to the server root directory the installation directory where Directory Server 7 1 is located by default this is opt redhat ds servers The Configuration Administrator s password for the Directory Server 7 1 instance The upgrade process beings after all of the 7 1 instance information is given 2 4 Installing Synchronization Services If Windows synchronization will...

Page 8: ... The following are some of the most important bugs fixed for Directory Server 7 1 SP7 Along with this service pack some erratas have been issued for Red Hat Directory Server fixing important security and performance issues The complete list of erratas issued for Red Hat Directory Server 7 1 SP7 for Red Hat Enterprise Linux is available through Red Hat Network at ht tps 1rhn redhat com 1errata 1rhe...

Page 9: ...ttribute has a default limit of 3600 seconds one hour To shorten the time limit modify the nsslapd timelimit parameter in cn config For example ldapmodify D cn Directory Manager w password dn cn config changetype modify replace nsslapd timelimit nsslapd timelimit 30 450973 Password policy attributes are not replicated by default However if a password attribute such as accountunlock time was added ...

Page 10: ...ker could exploit this flaw to execute cross site attacks against Directory Server users or administrators who used those web services These errors have been fixed 458171 On HP UX when running an approximate search the search code could return an error code 3 which corresponds to the LDAP error code for exceeding the search time limit This meant that an appropximate search could end prematurely wi...

Page 11: ...rectory Server handled value sets where there were several duplicate non sequential values added to an attribute such as adding foo bar bat foo This leak could only be triggered by an authentic ated user to the Directory Server who had the rights to modify attributes in an entry including self write access and if replica tion was being used This error has been fixed 458677 CVE 2008 3283 458692 458...

Page 12: ...mapped by SASL mapping there are no mapping entries created for them The original SASL mapping entries point to the first suffix Manually create SASL map ping entries that are associ ated with the second suffix 400341 If a user other than the admin user logs into the Console and attempts to change the admin user s password the password is not properly updated Only change the admin user password th...

Reviews: