omldapsync sync group errors with AD

Discuss the Scalix Server software

Moderators: ScalixSupport, admin

tob
Posts: 17
Joined: Wed May 10, 2006 11:18 am

omldapsync sync group errors with AD

Postby tob » Tue Nov 28, 2006 2:12 am

Hi

On ActiveDirectory (Windows 2003) we have a security-group named "Alle Mitarbeiter". I've checked "Enable Scalix Services for this user" this week, and removed it
some minutes later as I decided to create another group instead of using this existing.

Since then, every time I add/remove a user to the "Alle Mitarbeiter" group I get the following error from omldapsync:

--
SOAP part:
<?xml version="1.0" encoding="UTF-8"?>
<SOAP-ENV:Envelope
xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/">
<SOAP-ENV:Body>
<SOAP-ENV:Fault>
<faultcode>SOAP-ENV:Server</faultcode>
<faultstring>CAA Service Error</faultstring>
<detail>
<scalix-caa:fault-details
xmlns:scalix-caa="http://www.scalix.com/caa">
<message>Failed to locate or retrieve information in
LDAP for id ig7CPyy8tUaCAdzM/iVxUA==</message>
<errorcode>UM-1015</errorcode>
</scalix-caa:fault-details>
</detail>
</SOAP-ENV:Fault>
</SOAP-ENV:Body>
</SOAP-ENV:Envelope>

--


It looks like omldapsync tries to update the "Alle Mitarbeiter" Group, but this group does not exist (Scalix Services are not enabled for this group anymore).

How can I stop to omldapsync trying to sync this scalix-disabled group?

Thanks for your help

tob

ScalixSupport
Scalix
Scalix
Posts: 5503
Joined: Thu Mar 25, 2004 8:15 pm

Postby ScalixSupport » Tue Nov 28, 2006 5:05 am

Try deleting /var/opt/scalix/ldapsync/sync-ID/import/search.curr.

Regards,
Don

tob
Posts: 17
Joined: Wed May 10, 2006 11:18 am

Postby tob » Tue Nov 28, 2006 3:00 pm

Hi Don

I only have search.curr.0 and search.curr.1.

I did a grep thru this directory and found out, that all search.* contain my disabled group.

What file should I delete and is it safe to delete this file? I don't want to loose my AD sync, because we have a lot of users on this system...

Thanks for your help.

Regards,
Tob

ScalixSupport
Scalix
Scalix
Posts: 5503
Joined: Thu Mar 25, 2004 8:15 pm

Postby ScalixSupport » Wed Nov 29, 2006 10:15 am

As you work through this you can put a fail safe in place. In your sync.cfg find:

# IM_DELETE_MAILBOX: whether sync of mailbox delete will be applied to Scalix
# NOTE: set to "FALSE" to keep the mailbox and handle the deletion manually
IM_DELETE_MAILBOX=TRUE

Change this to FALSE.

Have a look at the man page for omldapsync and pay particular attention to the -L, -M, and -A.

Regards,
Don

tob
Posts: 17
Joined: Wed May 10, 2006 11:18 am

Postby tob » Wed Nov 29, 2006 2:15 pm

Hi Don

I did a reload of the directory, but the problem still exists: omldapsync still tries to sync this group which is not scalix-enabled in AD anymore. Is it possible that the AD-Plugin leaves some information in the AD even if I disable Scalix services for this group?

Regards,
Tob


Return to “Scalix Server”



Who is online

Users browsing this forum: No registered users and 4 guests