" /> Frank's Activity Log: July 2005 Archives

« June 2005 | Main | August 2005 »

July 30, 2005

30. Juli 2005 -- Samstag

LDAP: RHEL4 Upgrade. Peregrine is a nasty little piece of hardware. It refused to allow the raid-1 array disk to be repartitioned. Final solution was to delete the raid-1 array and then create it again. After that, the RHEL4U1 disks installed (partitioned etc) just fine.

July 29, 2005

29. Juli 2005 -- Freitag

LDAP: Another Banner entry with lastname that begins with Delete: ... ignore it for now, as those are going to be removed from the feed.

LDAP: Continue with the mink installation:


  • install /etc/init.d/vips
  • install root's bin (ldap-stats.pl, skipit)
  • install monitor scripts (/usr/local/tsg/*)
  • regenerate raidcheck.template file...
  • install root's crontab
  • update /etc/logrotate.conf (daily/31 copies)
  • set up BB monitoring
  • ph2ldap ... requires openldap-devel (cyrus-devel)

    • /etc/ph2ldap/ph2ldap.cfg from ldap.uvm.edu (please)...

  • declare victory...
  • add into LVS.

LDAP: post rhel4 update checklist at ~fcs/ldap_rhel4.html and post to tsg mailinglist for review.

CALENDAR: worked with Account Services on a problem with provisioning new calendar accounts and found a bug in the PHP code that builds the LDAP entry required. It was not changing the surname as requested (the code was just missing).

LDAP: RHEL4 upgrade. 2/3 completed. Failed on third system (peregrine). Will try again tomorrow after the drives finish sync'ing after the bios update caused the card to think they were out of sync.

July 28, 2005

28. Juli 2005 -- Donnerstag

LDAP: another Student Employee problem. This time it was really fun because the person has a bogus SSN, and no barcode, birthday, pidm info to go on... Hopefully, I found the correct (the only) match with the name.

LDAP: build Mink as RHEL4/OpenLDAP 2.2.26 replica server...


  • Save /etc/krb5.keytab and /etc/sysconfig/rhn/systemid
  • Install December 2004 UpdateXpress CD (4.01 doesn't seem to work)
  • Update BIOS to do Console Redirection on COM1 at 19200,8N1
  • Install RHEL4 Update 1 from CD (Minimal Install)

    Oops... missmatch... ServeRaid 7.10.18 got part way installed, but the card is still at 7.00.14... this is a problem :(

    Ahhh... Figured out how and got the ServeRaid 7.10 code installed by hand! YeeHaw... use the .htm! ;-)

  • Restore /etc/sysconfig/rhn/systemid file
  • up2date -p
  • up2date -uf
  • up2date -i ntp
  • Configure /etc/ntp.conf (add UVM servers and remove redhat's)
  • Install uvmhidden kernel (carcajou has them)
  • Configure saslauthd to work (kerberos in general too)
  • Install UVM OpenLDAP packages
  • generate UVM SSL certificate
  • Don't forget the /usr/lib/sasl2/slapd.conf file...
  • update iptables rules
  • update ldap master to replicate here...
  • dump database... install... start....
  • stand back and watch out for sparks...
  • update /etc/syslog.conf for slapd.log
  • install /etc/logrotate.d/slapd

July 27, 2005

27. Juli 2005 -- Mittwoch

LDAP: I can't type! Had to fix a typo and rerun part2/3 of the nightly update. Discovered that a rename of an account didn't work yesterday.

CALENDAR: MetaLink... shutdown server... turn on debug... send more info... rinse/repeat... ARGH!

ACCOUNTS/LDAP: bug in accountrename :(... why is it sending an email address as an attribute name??? must find and fix. Have added code to make it explode in large fashion when it breaks again.

LDAP/RFC2307: UVM Directory change will be simple... and is done. Testing nss_ldap (/etc/ldap.conf) changes. YAY, it works!

scripts: perseus scripts copied... need a volunteer (or direction) to test.

July 26, 2005

26. Juli 2005 -- Dienstag

SSL: timesheet certificate installed

LDAP: get mac lab configuration problem figured out. Right attributes wrong server. For some unknown reason, the mac lab machine being tested was not properly updating it's plist file so it was trying to use the UID attribute to search on ldap.uvm.edu which just isn't going to work (yet).

CALENDAR: create a calendar account for ERP.

LDAP: make certain the uvmAlt* attributes are created for all accounts as they are created (modify the update_ldap_ldif.pl and adduser scripts)

July 25, 2005

25. Juli 2005 -- Montag

LDAP: handle a "Student Employee" primary affiliation. (adduser and modify ldap entry -- because unable to find "student" information)

CALENDAR: Toss one to John and Sharon... Oops, shouldn't have. Appears to have been user error. There was a message queued at 15:41 Friday that had no recipients. Purged the queued item (it happened before the server upgrade). Will report it to Oracle if it happens again. Used unireqdump to find/purge the item.

July 22, 2005

22. Juli 2005 -- Freitag

Calendar: prepare for tonight's updates.

LDAP: entry in ou=Expired tree unable to update via UVM Directory interface question from account services -- this is by design -- plus the attributes they desire to change are only supplied from the HRS feed.

Calendar: (5:00pm - 8:30pm) upgrade and fix db.

July 20, 2005

20. Juli 2005 -- Mittwoch

Web: multiple spiders sucking down the uvm webspace at the same time cause the circle of death event.

LDAP: continue with exploring the separate error log thought. Announce RFC2307 work...

VPN: Vendor access... think about it some more

WebCT: planning discussion...

July 19, 2005

19. Juli 2005 -- Dienstag

Calendar: Review 12. Juli critical patch notes. No critical patches apply to calendar product, will ignore for this week.

LDAP: RFC2307 work; explore creating a true STDERR output from nightly updates.

WebCT: SSL Certificate renewal

TimeSheet: SSL Certificate renewal

FootPrints: FP7.0 webinar...

July 18, 2005

18. Juli 2005 -- Montag

Calendar: Update TAR 4476859.993 about DB_VISTA error from Saturday night to see if this is a new concern or if it should be fixed with upgrades Friday night.

LDAP: Research HRS feed question...which turns into a bug in my code search...bug located and repaired. Updates that failed to happen on Thursday and Friday have been run and applied.

July 7, 2005

7. Juli 2005 -- Donnerstag

LDAP: Banner updated an entry and gave enough information that we could determine it was a duplicate of an existing employee entry. Merged the two entries and purged the one created yesterday by banner.

Calendar: started the wheels moving to get administrative permission to perform the calendar maintenance on Friday July 22 (5pm to 11pm). Hopefully, everyone will be happy with that time and the upgrade will go as smoothly as the one on the test server did yesterday (with the exception of having to call Oracle because the readme didn't include all the conf file updates that were required).

RFC2307: test server configured... I think it's ready for testing! Will make a few checks tomorrow and go from there...

Storage: meeting to discuss connectivity, etc...

July 6, 2005

6. Juli 2005 -- Mittwoch

LDAP: verification that nightly update process on the test server ran ok. Posting to OpenLDAP-software list asking if someone has written the code in PHP or PERL to figure out the canonical name of an attribute so the application can go after the correct attribute name (search for netid; get back uid; code go boom -- not a real cool situation)

Calendar: upgrade test server to OCAL 9.0.4.2.10 (seems to work fine) and OCAS 9.0.4.2.40 (oops... it no run -- open TAR 4494932.993 to resolve). Test unidbfix on test server. Oracle wants a web conference to work on the TAR. YAY! The problem is fixed. Seems there were some changes that needed to be made to the ocas.conf and ocwc.conf files that were NOT detailed in the 9.0.4.2.40 README.html file. Oops... minor QA issue there.. Updates saved in 9.0.4.2.40_fixit.patch in homedir.

CATalyst: Meeting about privacy...

July 5, 2005

5. Juli 2005 -- Dienstag

Calendar: MODRDN/unidssync to rename the resource entry for Account Services.

Accounts: Update account-deletion-2005 project pages.

Calendar: generate the list of machines (and who is likely using them) that are running old calendar clients since June 1.

LDAP: more work on rfc2307 support. Oh the headache this is becoming.

July 1, 2005

1. Juli 2005 -- Freitag

Printer Queues: Request forwarded to Account Services -- Kent trained ;-)

LDAP: an account rename didn't work right yesterday. Had to clean up the pieces. Asked Account Services if they had noticed any error messages and notified anyone...

continued code testing for rfc2307 support.

Calendar: Opened another TAR to see how to change the name of a resource. The documentation appears to indicate it is not possible.

Accounts: Prepare for annual purge to start tomorrow.