This section lists the bugs fixed since the last release of Directory Server.
When synchronizing multi-domain Active Directory with Identity Synchronization for Windows, synchronization fails on Directory Server because of Active Directory's referrals.
An ACI problem may enable users to guess correct values.
A filter using a wildcard for an integer attribute may lead to inconsistent ldapsearch results.
When Active Directory servers are unavailable, Directory Server hangs in Identity Synchronization for Windows plug-ins.
When logging through a stale connector, Directory Server crashes in Identity Synchronization for Windows plug-ins.
After deploying Directory Server Enterprise Edition, defunct processes are created. This issue affects only the ZIP distribution on HP-UX.
The dsrepair tool does not work correctly on Microsoft Windows systems.
The replcheck tool does not work correctly on Microsoft Windows systems.
Replication over SSL may create memory leaks.
In the Suffix Usage tab of the DSCC console on versions of Directory Server Enterprise Edition 6, refresh does not display all suffixes.
When a long ACI is added, versions of Directory Server Enterprise Edition 6 might crash.
With large compound search filters, search performance is poor.
Use of the reversible password plug-in (des-plugin) might break replication.
Versions of Directory Server Enterprise Edition 6 do not support multiple certificate-authority certificates using the same dn in the certificate database.
Use of a large number of masters prevents proper monitoring of replication.
Enabling a password policy in a replication topology that includes both Directory Server Enterprise Edition 5.2 and Directory Server Enterprise Edition 6 causes replication to fail.
A race condition can cause a crash at the end of a replication session.
Some maintenance operations can cause a database recovery when the server restarts.
Use of pwdReset in a password policy prevents changing a password through proxy authorization.
A space after the quotation marks in an ACI string can cause erroneous ACI evaluations.
The DSCC console might fail to display a long ACI.
A complex CoS can reduce performance.
Insufficient access rights during logfile rotation cause versions of Directory Server Enterprise Edition 6 to hang.
Password policies now support a password timeout limit of 315360000 seconds (slightly less than 10 years), reduced from 2147483647 seconds (approximately 68 years).
If the NSS pin code is longer than eight characters, versions of Directory Server Enterprise Edition 6 do not start.
A candidate list of more than 2.5 million entries causes a server crash.
Using DSCC to edit an attribute with a binary syntax corrupts the attribute's value.
A race condition in opening and closing a connection can crash versions of Directory Server Enterprise Edition 6 in connection_getIp_string.
If attribute uniqueness plug-in is configured but not enabled, versions of Directory Server Enterprise Edition 6 can crash.
A race condition in ACI evaluation can cause the directory server to crash.
If a maintenance operation occurs while changelog trimming is running, a database panic or crash can occur.
Pass-through authentication prevents ns-slapd from shutting down.
When the password policy is running in compatibility mode, the password values are displayed in the clear in auditlog regardless of the value of passwordStorageScheme.
Restoring a backup containing a large changelog (larger than 30,000 database pages) logs the following messages:
DEBUG - conn=-1 op=-1 msgId=-1 - libdb: Lock table is out of available locks ERROR<8232> - Replication - conn=-1 op=-1 msgId=-1 - Internal error Truncate of changelog file failed, error 12 (Not enough space) |
Under Sun Cluster 3.2 control on Solaris 10 AMD64, Directory Server fails to start.
A race condition between changelog trimming and operation on the trimmed entry can cause the directory server to hang.
If the replication group size is larger than one, etimes of replicated operations are incorrectly computed.
An index can be imported incorrectly in multi-pass import.
Referral cannot be disabled with DSCC once it has been enabled.
DSCC does not handle attributes with subtypes correctly.
A race condition with an ACI containing DNS rules causes in DS crash.
The Replication changelog gets emptied after a backup restore with message as below
INFORMATION - NSMMReplicationPlugin - conn=-1 op=-1 msgId=-1 - replica_reload_ruv: Warning: new data for replica does not match the data in the changelog. Recreating the changelog file. This could affect replication with replica's consumers in which case the consumers should be reinitialized. |
Directory Server crashes when stopping the server while indexing is occurring.
If Directory Server crashes while under Sun Cluster 3.2 control, cluster failover is initiated, but it requires more than 4 minutes.
Rarely updated masters might result in backups becoming quickly obsolete.
In a replication configuration, deleting entries creates incorrect VLV indexes.
Database restore messages are inconsistent between DSCC and error log files.
In a race condition, the Directory Server Enterprise Edition 6.3 changelog is not trimmed.
In a race condition, deleting a suffix can result in a database panic error.
When a password policy is assigned using CoS, the directory server might not release memory.
In versions of Directory Server Enterprise Edition 6, the des-plugin.so is not signed.
The zipped distribution delivers JRE 1.5.0_12 instead 1.5.0_9 as in previous releases.
A race condition between updating and flushing database pages can cause a directory server crash, database panic errors, or lose of updates.
A SASL bind on a connection can lead to a directory server crash
Consumers can become out of sync when ds-polling-thread-count is greater than 1 (which is likely on a CMT machine).