A proposal for how to set msDS-KeyVersionNumber

Stefan (metze) Metzmacher metze at samba.org
Tue Jun 8 08:11:02 MDT 2010

Am 07.06.2010 13:13, schrieb Andrew Bartlett:
> Attached is a proposal for how to set msDS-KeyVersionNumber
> The idea is that if the knvo is incorrect in an upgraded DB, which may
> cause trouble for unix clients joined to a Samba domain (but not Samba3,
> or windows), that we want to manually set the knvo.
> If this is too intrusive, then I suggest we just omit 'fixing' this, as
> only a very small subset of our clients actually care about this value.
> (I've have no complaints since I changed how we calculate this value 3
> months ago). 
> (untested, intended to be used with a future upgradeprovision)
> Any comments?

I think we shouldn't put such logic into the modules,
the upgrade logic should be in the upgradeprovision script,
which should just rebuild the replPropertyMetaData attribute completely,
and use a control to set it from above the repl_meta_data module.


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 262 bytes
Desc: OpenPGP digital signature
URL: <http://lists.samba.org/pipermail/samba-technical/attachments/20100608/59f65625/attachment.pgp>

More information about the samba-technical mailing list