Topic: OpenLDAP error "Undefined attribute type (17)"
- iRedMail version (check /etc/iredmail-release): 0.9.8
- Deployed with iRedMail Easy or the downloadable installer? Downloadable
- Linux/BSD distribution name and version: CentOS Linux release 7.6.1810 (Core)
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): LDAP
- Web server (Apache or Nginx): Nginx
- Manage mail accounts with iRedAdmin-Pro? No
- [IMPORTANT] Related original log or error message is required if you're experiencing an issue.
Hi iRedMail Pros!
I tried out the ppolicy feature. Implementation went fine, but then I noticed that you cannot change user passwords anymore by LDAPadmin GUI or by shell. Changing user passwords works only by SOGo Web GUI.
So I want to roll back the ppolicy feature.
I performed the following steps in order to roll back, but since then I receive the following error message trying to change user passwords either way by LDAPadmin GUI or shell:
Undefined attribute type (17)
1) Removed the following lines from /etc/openldap/slapd.conf
include /etc/openldap/schema/ppolicy.schema
overlay ppolicy
ppolicy_default "cn=ppolicy,dc=mycompany,dc=com"
2) Removed the following line from /etc/sogo/sogo.conf
passwordPolicy = YES;
3) Removed the ppolicy.ldif and ppolicy.schema files from /etc/openldap/schema
4) Restarted the slapd and the sogod daemons
I assume that the ppolicy schema has to be removed additionaly by an ldapmodify command, because during implementation I also had to perform an ldapmodify command providing an LDIF file:
This was the command:
ldapmodify -x -a -H ldap://localhost -D cn=Manager,dc=mycompany,dc=com -w hdeki38dj23ghesui3idfhu3kidfoi3eudui -f /etc/openldap/schema/ppolicy.ldif
This was the LDIF file:
dn: cn=ppolicy,dc=mycompany,dc=com
objectClass: pwdPolicy
objectClass: person
objectClass: top
cn: passwordDefault
sn: passwordDefault
pwdAttribute: userPassword
pwdCheckQuality: 2
pwdMinAge: 0
pwdMaxAge: 0
pwdMinLength: 12
pwdInHistory: 0
pwdMaxFailure: 5
pwdFailureCountInterval: 3600
pwdLockout: TRUE
pwdLockoutDuration: 10
pwdAllowUserChange: TRUE
pwdExpireWarning: 0
pwdGraceAuthNLimit: 0
pwdMustChange: FALSE
pwdSafeModify: FALSE
I guess that I have to create a new LDIF file and then invoke an ldapmodify command in order to purge the ppolicy schema from the LDAP.
Can you help me to create the proper LDIF file and command?
Thank you very much!
Best Regards,
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.