mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2024-12-25 08:21:05 -06:00
624b34ab2b
The content synchronization plugin can be limited to the dns subtree in Directory Server. This increases performance and helps to prevent some potential issues. Fixes: https://pagure.io/freeipa/issue/6515 Signed-off-by: Tomas Krizek <tkrizek@redhat.com> Reviewed-By: Rob Crittenden <rcritten@redhat.com>
30 lines
1.2 KiB
Plaintext
30 lines
1.2 KiB
Plaintext
# Enable Retro changelog - it is necessary for SyncRepl
|
|
dn: cn=Retro Changelog Plugin,cn=plugins,cn=config
|
|
only:nsslapd-pluginEnabled: on
|
|
# Remember original nsuniqueid for objects referenced from cn=changelog
|
|
add:nsslapd-attribute: nsuniqueid:targetUniqueId
|
|
add:nsslapd-changelogmaxage: 2d
|
|
add:nsslapd-include-suffix: cn=dns,$SUFFIX
|
|
|
|
# Keep memberOf and referential integrity plugins away from cn=changelog.
|
|
# It is necessary for performance reasons because we don't have appropriate
|
|
# indices for cn=changelog.
|
|
dn: cn=MemberOf Plugin,cn=plugins,cn=config
|
|
add:memberofentryscope: $SUFFIX
|
|
add:memberofentryscopeexcludesubtree: cn=compat,$SUFFIX
|
|
add:memberofentryscopeexcludesubtree: cn=provisioning,$SUFFIX
|
|
add:memberofentryscopeexcludesubtree: cn=topology,cn=ipa,cn=etc,$SUFFIX
|
|
|
|
dn: cn=referential integrity postoperation,cn=plugins,cn=config
|
|
add:nsslapd-plugincontainerscope: $SUFFIX
|
|
add:nsslapd-pluginentryscope: $SUFFIX
|
|
add:nsslapd-pluginExcludeEntryScope: cn=provisioning,$SUFFIX
|
|
|
|
# Enable SyncRepl
|
|
dn: cn=Content Synchronization,cn=plugins,cn=config
|
|
only:nsslapd-pluginEnabled: on
|
|
|
|
# Make sure IPA UUID does not generate ipaUniqueID for Stage/Delete entries
|
|
dn: cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config
|
|
add:ipaUuidExcludeSubtree: cn=provisioning,$SUFFIX
|