Skip navigation.
Home

jbeekman's blog

What is it that you do now?

Infrastructure

Since my transition to Manager of Network Engineering, and with the hire of a new Network Engineer, my role has changed significantly in IMT.  At this point in time my primary role is to oversee the installation and configuration of new telecommunications systems.  This most often includes working with project managers and contractors to facilitate the proper installation of cabling and equipment in new constructions.

Furthermore as manager of the group, I am responsible for the successfull operations of all inter-host communications.  This includes data and voice networking at a logical and physical level.

In addition I continue to work with AWG on architecture issues, and I am available to assist the rest of Network Services for consultation.

eduPerson changed to AUX type objectClass

IdM
Educause has decided to make the eduPerson objectClass an AUX type. It was formerly STRUCT. This allows for flexibility in implementing eduPerson. Educause recommends using person, organizationalPerson, and inetOrgPerson as the structural objectClasses. This document discusses the relationship.

OpenLDAP Simple Bind {KERBEROS} depricated.

Authentication

Bad news for us, good news for security standards. So it seems that the OpenLDAP project is starting to work towards elimination of most simple bind functionality. There are a few posts here and there about it. As part of this, versions 2.1.23 and greater of OpenLDAP do not support the simple bind {KERBEROS} functionality that we are currently using. We are currently running version 2.1.21 in production.

Some options for working around this problem include:

  1. Switching to the simple bind {SASL} option which uses a ldap->saslauthd->kerberos or ldap->saslauthd->pam->kerberos method of credentials authentication. (Haven't been able to make this work right yet)
  2. Not upgrading OpenLDAP.. ever.
  3. Eliminating ldap simple binds in the environment.
  4. Moving authentication directly to Active Directory.

Related OpenLDAP FAQ Article

RedHat refresh updates

Linux
We currently have 8 remaining production servers running non-enterprise versions of the Red Hat Linux operating system. Work is ongoing to refresh these to RHEL 3.

aslan.apu.edu PostgreSQL upgrade

WorkBlog
I upgraded aslan.apu.edu this morning: IBM x335 2x2600 mhz, 1500 M RAM RedHat Enterprise Linux AS 3 PostgreSQL 7.3 Redhat Edition There have been some minor syntax issues with multiple sites, including some pear issues with this one.
XML feed