<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Ludo&#039;s Sketches</title>
	<atom:link href="http://ludopoitou.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://ludopoitou.wordpress.com</link>
	<description>Ludovic Poitou blog about Identity, Directory and others...</description>
	<lastBuildDate>Mon, 23 Jan 2012 16:11:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='ludopoitou.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/b412afe8b62ea1f607c5c8e5bc714831?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Ludo&#039;s Sketches</title>
		<link>http://ludopoitou.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://ludopoitou.wordpress.com/osd.xml" title="Ludo&#039;s Sketches" />
	<atom:link rel='hub' href='http://ludopoitou.wordpress.com/?pushpress=hub'/>
		<item>
		<title>In the news&#8230;</title>
		<link>http://ludopoitou.wordpress.com/2012/01/23/in-the-news/</link>
		<comments>http://ludopoitou.wordpress.com/2012/01/23/in-the-news/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 16:11:08 +0000</pubDate>
		<dc:creator>Ludo</dc:creator>
				<category><![CDATA[Identity]]></category>
		<category><![CDATA[ForgeRock]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[openidm]]></category>
		<category><![CDATA[opensource]]></category>
		<category><![CDATA[partners]]></category>
		<category><![CDATA[release]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://ludopoitou.wordpress.com/?p=997</guid>
		<description><![CDATA[I&#8217;ve been traveling a little bit last week, visiting a major customer in the UK (helping with their OpenDJ based directory service that has grown from 13 Millions entries to 17 Millions in a about 6 months). Last week was also a busy week in term of news for ForgeRock. First, we&#8217;ve  announced the release of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=997&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been traveling a little bit last week, visiting a major customer in the UK (helping with their OpenDJ based directory service that has grown from 13 Millions entries to 17 Millions in a about 6 months).</p>
<p>Last week was also a busy week in term of news for ForgeRock. First, we&#8217;ve  announced the <a title="ForgeRock announces OpenIDM 2.0" href="http://www.forgerock.com/content/forgerock-announces-openidm-20">release of OpenIDM 2.0</a>, a major version of our real-time identity life-cycle management, provisioning and synchronization software product. OpenIDM 2.0 is a new release, but is already running in production at a few happy customers.</p>
<p><a title="ForgeRock, the global open source vendor behind the I³ Open Platform (OpenAM, OpenDJ, OpenIDM)" href="http://forgerock.com">ForgeRock</a> and <a title="Qubera Solutions" href="http://www.quberasolutions.com/">Qubera Solutions</a> have <a title="ForgeRock and Qubera Solutions Partner to Deliver Standards-Based Identity Services" href="http://www.quberasolutions.com/company_news.php?articleid=9">announced a partnership</a> for the delivery of Standard-based Identity Services based on ForgeRock <a title="ForgeRock I3 Open Platform" href="http://forgerock.com/strategy.html">I3 Open Platform</a>. Qubera Solutions offers workshops and migration tools to help former Sun Microsystems customers to move away legacy software solutions.</p>
<p>I&#8217;ve also came across a <a title="Identity and Access Management refections blog : Challengers : ForgeRock." href="http://iamreflections.blogspot.com/2012/01/challengers-forgerock.htmlhttp://iamreflections.blogspot.com/2012/01/challengers-forgerock.html">blog post from Martin Sandren</a>, that positions ForgeRock as one of the challengers on the Identity and Access Management market.  It&#8217;s an interesting reading and it looks like the previous announcement does start to address some of his concerns.</p>
<p>Martin was not the only one to talk about ForgeRock. <a title="Scott Mc Nealy twitter handle" href="https://twitter.com/scottmcnealy/">Scott Mc Nealy</a> has been <a title="RT Scott about ForgeRock on Twitter." href="https://twitter.com/ludomp/status/159231209765998592">nicely advertising</a> about us <a title="Scott about ForgeRock, on twitter." href="https://twitter.com/scottmcnealy/status/159780914359050240">on Twitter</a>.</p>
<p>And finally, we&#8217;re expanding and therefore we&#8217;ve published <a title="ForgeRock is hiring !" href="http://forgerock.com/node/175/">a few job postings on our web site</a>. I&#8217;m pretty confident that these are just a few to start with and we will have more, including some in our Grenoble Engineering Center.</p>
<br />Filed under: <a href='http://ludopoitou.wordpress.com/category/identity/'>Identity</a> Tagged: <a href='http://ludopoitou.wordpress.com/tag/forgerock/'>ForgeRock</a>, <a href='http://ludopoitou.wordpress.com/tag/identity-2/'>identity</a>, <a href='http://ludopoitou.wordpress.com/tag/news/'>news</a>, <a href='http://ludopoitou.wordpress.com/tag/openidm/'>openidm</a>, <a href='http://ludopoitou.wordpress.com/tag/opensource/'>opensource</a>, <a href='http://ludopoitou.wordpress.com/tag/partners/'>partners</a>, <a href='http://ludopoitou.wordpress.com/tag/release/'>release</a>, <a href='http://ludopoitou.wordpress.com/tag/software-2/'>software</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ludopoitou.wordpress.com/997/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ludopoitou.wordpress.com/997/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ludopoitou.wordpress.com/997/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ludopoitou.wordpress.com/997/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ludopoitou.wordpress.com/997/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ludopoitou.wordpress.com/997/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ludopoitou.wordpress.com/997/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ludopoitou.wordpress.com/997/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ludopoitou.wordpress.com/997/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ludopoitou.wordpress.com/997/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ludopoitou.wordpress.com/997/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ludopoitou.wordpress.com/997/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ludopoitou.wordpress.com/997/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ludopoitou.wordpress.com/997/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=997&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ludopoitou.wordpress.com/2012/01/23/in-the-news/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4c7d0f23ff8919a2720a7845ba1d4e5a?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=R" medium="image">
			<media:title type="html">Ludo</media:title>
		</media:content>
	</item>
		<item>
		<title>Disabling Replication in OpenDJ 2.4.</title>
		<link>http://ludopoitou.wordpress.com/2012/01/09/disabling-replication-in-opendj-2-4/</link>
		<comments>http://ludopoitou.wordpress.com/2012/01/09/disabling-replication-in-opendj-2-4/#comments</comments>
		<pubDate>Mon, 09 Jan 2012 12:04:10 +0000</pubDate>
		<dc:creator>Ludo</dc:creator>
				<category><![CDATA[Directory Services]]></category>
		<category><![CDATA[directory-server]]></category>
		<category><![CDATA[documentation]]></category>
		<category><![CDATA[ForgeRock]]></category>
		<category><![CDATA[ldap]]></category>
		<category><![CDATA[opendj]]></category>
		<category><![CDATA[opensource]]></category>
		<category><![CDATA[replication]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://ludopoitou.wordpress.com/?p=990</guid>
		<description><![CDATA[Enabling replication between multiple instances of the OpenDJ LDAP directory server is pretty simple and straightforward. You can check for yourself in the Replication chapter of the Administration Guide. But fully disabling replication can be tricky with OpenDJ 2.4, mostly because of a known issue with the dsreplication disable &#8211;disableAll command : OPENDJ-249 : Doing dsreplication disable [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=990&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Enabling replication between multiple instances of the <a title="OpenDJ, the open source LDAP directory services in Java" href="http://opendj.forgerock.org">OpenDJ LDAP directory server</a> is pretty simple and straightforward. You can check for yourself in the <a title="OpenDJ Administration Guide : Managing Replication" href="http://opendj.forgerock.org/doc/admin-guide/OpenDJ-Admin-Guide/chap-replication.html#configure-repl">Replication chapter of the Administration Guide</a>.</p>
<p>But fully disabling replication can be tricky with OpenDJ 2.4, mostly because of a known issue with the dsreplication disable &#8211;disableAll command : <a title="Issue OPENDJ-249" href="https://bugster.forgerock.org/jira/browse/OPENDJ-249">OPENDJ-249</a> : Doing dsreplication disable &#8211;disableAll is throwing a javax.naming.CommunicationException when removing contents of &#8220;cn=admin data&#8221;.</p>
<p>We are fixing this issue in OpenDJ 2.5, but for those who have deployed OpenDJ 2.4 and want to know how to fully remove all references to a replica in the topology, here are the steps to manually disable replication :</p>
<p><em>Note</em>, all these steps should be done using ldapmodify, or an LDAP browser such as OpenDJ Control-Panel&#8217;s Manage Entry or Apache Directory Studio.</p>
<ol>
<li>For each replica to be disabled connect to it on the admin port (4444) and:
<ol>
<li>MANDATORY: set the &#8220;ds-cfg-enabled&#8221; property to &#8220;false&#8221; in &#8220;cn=Multimaster Synchronization,cn=Synchronization Providers,cn=config&#8221;</li>
<li>OPTIONAL: recursively remove the entries beneath &#8220;cn=Multimaster Synchronization,cn=Synchronization Providers,cn=config&#8221; using individual delete operations. Note that the configuration backend does not support the sub-tree delete control, so this has to be done iteratively. This step is also not mandatory, since replication was fully disabled in the previous step</li>
<li>MANDATORY: remove each entry beneath &#8220;cn=Servers,cn=admin data&#8221; except the entry itself. I find the easiest way to do this is to perform a sub-tree delete and then add back the base entry</li>
<li>OPTIONAL: remove (purge) unused instance keys from beneath &#8220;cn=instance keys,cn=admin data&#8221; *except* own key. This step is really independent of replication: administrators should periodically purge unused instance keys anyway when they are sure that they are no longer needed (e.g. used for signing backups, etc)</li>
<li>MANDATORY: delete &#8220;uniqueMember&#8221; in &#8220;cn=all-servers,cn=Server Groups,cn=admin data&#8221;</li>
</ol>
</li>
<li>On one of the remaining enabled replicas, connect to it via the admin port and:
<ol>
<li>MANDATORY: remove each disabled server beneath &#8220;cn=Servers,cn=admin data&#8221;</li>
<li>OPTIONAL: remove (purge) each disabled instance key beneath &#8220;cn=Servers,cn=admin data&#8221; (see 1.4)</li>
<li>MANDATORY: remove each disabled server from uniqueMember in &#8220;cn=all-servers,cn=Server Groups,cn=admin data&#8221;</li>
<li>MANDATORY: get list of all remaining servers from &#8220;cn=all-servers,cn=Server Groups,cn=admin data&#8221;</li>
</ol>
</li>
<li>For each of the remaining enabled replicas obtained in step 2.4 connect to it via the admin port and:
<ol>
<li>MANDATORY: remove each disabled server(rsPort) from ds-cfg-replication-server in &#8220;cn=replication server,cn=Multimaster Synchronization,cn=Synchronization Providers,cn=config&#8221;</li>
<li>MANDATORY: remove each disabled server(rsPort) from ds-cfg-replication-server in &#8220;cn=*,cn=domains,cn=Multimaster Synchronization,cn=Synchronization Providers,cn=config&#8221;</li>
</ol>
</li>
</ol>
<br />Filed under: <a href='http://ludopoitou.wordpress.com/category/directory-services/'>Directory Services</a> Tagged: <a href='http://ludopoitou.wordpress.com/tag/directory-server/'>directory-server</a>, <a href='http://ludopoitou.wordpress.com/tag/documentation/'>documentation</a>, <a href='http://ludopoitou.wordpress.com/tag/forgerock/'>ForgeRock</a>, <a href='http://ludopoitou.wordpress.com/tag/ldap/'>ldap</a>, <a href='http://ludopoitou.wordpress.com/tag/opendj/'>opendj</a>, <a href='http://ludopoitou.wordpress.com/tag/opensource/'>opensource</a>, <a href='http://ludopoitou.wordpress.com/tag/replication/'>replication</a>, <a href='http://ludopoitou.wordpress.com/tag/tips/'>Tips</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ludopoitou.wordpress.com/990/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ludopoitou.wordpress.com/990/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ludopoitou.wordpress.com/990/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ludopoitou.wordpress.com/990/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ludopoitou.wordpress.com/990/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ludopoitou.wordpress.com/990/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ludopoitou.wordpress.com/990/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ludopoitou.wordpress.com/990/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ludopoitou.wordpress.com/990/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ludopoitou.wordpress.com/990/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ludopoitou.wordpress.com/990/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ludopoitou.wordpress.com/990/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ludopoitou.wordpress.com/990/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ludopoitou.wordpress.com/990/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=990&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ludopoitou.wordpress.com/2012/01/09/disabling-replication-in-opendj-2-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4c7d0f23ff8919a2720a7845ba1d4e5a?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=R" medium="image">
			<media:title type="html">Ludo</media:title>
		</media:content>
	</item>
		<item>
		<title>A limited special offer&#8230;</title>
		<link>http://ludopoitou.wordpress.com/2012/01/09/a-limited-special-offer/</link>
		<comments>http://ludopoitou.wordpress.com/2012/01/09/a-limited-special-offer/#comments</comments>
		<pubDate>Mon, 09 Jan 2012 09:34:09 +0000</pubDate>
		<dc:creator>Ludo</dc:creator>
				<category><![CDATA[Directory Services]]></category>
		<category><![CDATA[directory]]></category>
		<category><![CDATA[directory-server]]></category>
		<category><![CDATA[ForgeRock]]></category>
		<category><![CDATA[france]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[ldap]]></category>
		<category><![CDATA[opendj]]></category>
		<category><![CDATA[Paris]]></category>
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://ludopoitou.wordpress.com/?p=984</guid>
		<description><![CDATA[As I&#8217;ve posted last week, we organize a training on OpenDJ in Paris from Jan 24 to 27, 2012. I&#8217;ve been told that there is a special one time offer on this training. If you book the training by Friday January 13th, there is a 20 % discount on the course fee, which bring down [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=984&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>As I&#8217;ve <a title="OpenDJ Training in Paris Jan 24-27 2012." href="http://ludopoitou.wordpress.com/2012/01/05/opendj-training-in-paris-jan-24-27-2012/">posted last week</a>, we organize a <a title="OpenDJ Training FR462" href="http://forgerock.com/content/fr-462-open-dj-maintenance-operations-and-tuning">training</a> on <a title="OpenDJ, the open source LDAP directory server in Java" href="http://opendj.forgerock.org">OpenDJ</a> in <strong>Paris</strong> from <strong>Jan 24 to 27, 2012</strong>.</p>
<p>I&#8217;ve been told that there is a special one time offer on this training. If you book the training by Friday January 13th, there is a <strong>20 %</strong> discount on the course fee, which bring down the price of the 4 days course down to 2350€.</p>
<p>Don&#8217;t wait and register today at <a title="Register by mail to training@forgerock.com" href="mailto:training@forgerock.com">training@forgerock.com</a>.</p>
<p>And if you still hesitate, here&#8217;s a couple of quotes from the people involved in the review of the materials :</p>
<p style="text-align:center;"><strong>&#8220;Firstly, I&#8217;m pretty blown away by the quantity and quality of the material. It is extremely impressive, well done! <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> &#8220;</strong></p>
<p style="text-align:center;"><strong>&#8220;Hell, this is going to be a GREAT directory server course!&#8221;</strong></p>
<br />Filed under: <a href='http://ludopoitou.wordpress.com/category/directory-services/'>Directory Services</a> Tagged: <a href='http://ludopoitou.wordpress.com/tag/directory/'>directory</a>, <a href='http://ludopoitou.wordpress.com/tag/directory-server/'>directory-server</a>, <a href='http://ludopoitou.wordpress.com/tag/forgerock/'>ForgeRock</a>, <a href='http://ludopoitou.wordpress.com/tag/france/'>france</a>, <a href='http://ludopoitou.wordpress.com/tag/java-2/'>java</a>, <a href='http://ludopoitou.wordpress.com/tag/ldap/'>ldap</a>, <a href='http://ludopoitou.wordpress.com/tag/opendj/'>opendj</a>, <a href='http://ludopoitou.wordpress.com/tag/paris/'>Paris</a>, <a href='http://ludopoitou.wordpress.com/tag/training/'>training</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ludopoitou.wordpress.com/984/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ludopoitou.wordpress.com/984/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ludopoitou.wordpress.com/984/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ludopoitou.wordpress.com/984/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ludopoitou.wordpress.com/984/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ludopoitou.wordpress.com/984/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ludopoitou.wordpress.com/984/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ludopoitou.wordpress.com/984/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ludopoitou.wordpress.com/984/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ludopoitou.wordpress.com/984/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ludopoitou.wordpress.com/984/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ludopoitou.wordpress.com/984/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ludopoitou.wordpress.com/984/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ludopoitou.wordpress.com/984/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=984&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ludopoitou.wordpress.com/2012/01/09/a-limited-special-offer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4c7d0f23ff8919a2720a7845ba1d4e5a?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=R" medium="image">
			<media:title type="html">Ludo</media:title>
		</media:content>
	</item>
		<item>
		<title>OpenDJ Training in Paris Jan 24-27 2012.</title>
		<link>http://ludopoitou.wordpress.com/2012/01/05/opendj-training-in-paris-jan-24-27-2012/</link>
		<comments>http://ludopoitou.wordpress.com/2012/01/05/opendj-training-in-paris-jan-24-27-2012/#comments</comments>
		<pubDate>Thu, 05 Jan 2012 07:44:11 +0000</pubDate>
		<dc:creator>Ludo</dc:creator>
				<category><![CDATA[Directory Services]]></category>
		<category><![CDATA[directory]]></category>
		<category><![CDATA[directory-server]]></category>
		<category><![CDATA[europe]]></category>
		<category><![CDATA[ForgeRock]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[ldap]]></category>
		<category><![CDATA[opendj]]></category>
		<category><![CDATA[opensource]]></category>
		<category><![CDATA[Paris]]></category>
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://ludopoitou.wordpress.com/?p=975</guid>
		<description><![CDATA[The OpenDJ Administration, Maintenance and Tuning (FR-462) training is taking place in Paris from Tuesday January 24th to Friday January 27th 2012. The course is mix of lecture and labs and is designed for system administrators, integrators, consultants, architects and developers that will be installing, configuring, administering and maintaining ForgeRock OpenDJ LDAP directory server. I&#8217;ve been reviewing [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=975&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-982" title="FR462_MaterialsCover" src="http://ludopoitou.files.wordpress.com/2012/01/screen-shot-2012-01-04-at-23-48-09.png?w=300&#038;h=224" alt="Material Cover Page." width="300" height="224" />The <a title="OpenDJ, the open source LDAP directory services in Java." href="http://opendj.forgerock.com/">OpenDJ</a> Administration, Maintenance and Tuning (<a title="ForgeRock OpenDJ Administration, Maintenance and Tuning (FR-462) training" href="http://forgerock.com/content/fr-462-open-dj-maintenance-operations-and-tuning">FR-462</a>) training is taking place in <strong>Paris</strong> from <strong>Tuesday January 24th to Friday January 27th 2012</strong>.</p>
<p>The course is mix of lecture and labs and is designed for system administrators, integrators, consultants, architects and developers that will be installing, configuring, administering and maintaining ForgeRock OpenDJ LDAP directory server. I&#8217;ve been reviewing the course materials, and I must say I&#8217;m really excited by it. The amount of information available in the materials is huge, and the hands-on exercises are very detailed and practical.</p>
<p>The training is definitely a must for anyone who is or will be deploying and managing OpenDJ. And as this is the first training for OpenDJ in Europe, I will be attending it as an observer, gathering feedback on both product and course, also possibly as an assistant to the trainer <a title="Bill Nelson's blog" href="http://idmdude.com/">Bill Nelson</a>.</p>
<p>The session will be hosted in <a title="Astect Training center, Access map" href="http://www.astec.tm.fr/plan_acces.php">Astec training facilities</a>, right in the heart of Paris, close to Gare Saint Lazare and Boulevard Haussmann.</p>
<p>There are still some slots available, so enroll quickly by email to <a title="training@forgerock.com" href="mailto:training@forgerock.com">training@forgerock.com</a>.</p>
<br />Filed under: <a href='http://ludopoitou.wordpress.com/category/directory-services/'>Directory Services</a> Tagged: <a href='http://ludopoitou.wordpress.com/tag/directory/'>directory</a>, <a href='http://ludopoitou.wordpress.com/tag/directory-server/'>directory-server</a>, <a href='http://ludopoitou.wordpress.com/tag/europe/'>europe</a>, <a href='http://ludopoitou.wordpress.com/tag/forgerock/'>ForgeRock</a>, <a href='http://ludopoitou.wordpress.com/tag/java-2/'>java</a>, <a href='http://ludopoitou.wordpress.com/tag/ldap/'>ldap</a>, <a href='http://ludopoitou.wordpress.com/tag/opendj/'>opendj</a>, <a href='http://ludopoitou.wordpress.com/tag/opensource/'>opensource</a>, <a href='http://ludopoitou.wordpress.com/tag/paris/'>Paris</a>, <a href='http://ludopoitou.wordpress.com/tag/training/'>training</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ludopoitou.wordpress.com/975/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ludopoitou.wordpress.com/975/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ludopoitou.wordpress.com/975/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ludopoitou.wordpress.com/975/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ludopoitou.wordpress.com/975/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ludopoitou.wordpress.com/975/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ludopoitou.wordpress.com/975/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ludopoitou.wordpress.com/975/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ludopoitou.wordpress.com/975/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ludopoitou.wordpress.com/975/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ludopoitou.wordpress.com/975/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ludopoitou.wordpress.com/975/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ludopoitou.wordpress.com/975/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ludopoitou.wordpress.com/975/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=975&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ludopoitou.wordpress.com/2012/01/05/opendj-training-in-paris-jan-24-27-2012/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4c7d0f23ff8919a2720a7845ba1d4e5a?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=R" medium="image">
			<media:title type="html">Ludo</media:title>
		</media:content>

		<media:content url="http://ludopoitou.files.wordpress.com/2012/01/screen-shot-2012-01-04-at-23-48-09.png?w=300" medium="image">
			<media:title type="html">FR462_MaterialsCover</media:title>
		</media:content>
	</item>
		<item>
		<title>Happy New Year 2012 !</title>
		<link>http://ludopoitou.wordpress.com/2012/01/03/happy-new-year-2012/</link>
		<comments>http://ludopoitou.wordpress.com/2012/01/03/happy-new-year-2012/#comments</comments>
		<pubDate>Tue, 03 Jan 2012 16:22:57 +0000</pubDate>
		<dc:creator>Ludo</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[grenoble]]></category>
		<category><![CDATA[happy]]></category>
		<category><![CDATA[happy new year]]></category>
		<category><![CDATA[new]]></category>
		<category><![CDATA[year]]></category>

		<guid isPermaLink="false">http://ludopoitou.wordpress.com/?p=970</guid>
		<description><![CDATA[2011 is gone and we&#8217;re back to work. Welcome in 2012. We ended the year beautifully and we&#8217;re hoping the new one is starting the same way. So far the signs are good. On behalf of ForgeRock and more specifically ForgeRock Grenoble Engineering Center, I&#8217;d like to wish you a very Happy New Year ! [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=970&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>2011 is gone and we&#8217;re back to work. Welcome in 2012. We ended the year beautifully and we&#8217;re hoping the new one is starting the same way. So far the signs are good.</p>
<p>On behalf of ForgeRock and more specifically ForgeRock Grenoble Engineering Center, I&#8217;d like to wish you a very Happy New Year ! May the year be even better than last one&#8230;</p>
<p><a href="http://ludopoitou.files.wordpress.com/2012/01/bw2012_txt.jpg"><img class="aligncenter size-full wp-image-971" title="Best Wishes for 2012" src="http://ludopoitou.files.wordpress.com/2012/01/bw2012_txt.jpg?w=620&#038;h=412" alt="Hot balloon over lake with Mont Blanc in the back." width="620" height="412" /></a></p>
<br />Filed under: <a href='http://ludopoitou.wordpress.com/category/general/'>General</a> Tagged: <a href='http://ludopoitou.wordpress.com/tag/grenoble/'>grenoble</a>, <a href='http://ludopoitou.wordpress.com/tag/happy/'>happy</a>, <a href='http://ludopoitou.wordpress.com/tag/happy-new-year/'>happy new year</a>, <a href='http://ludopoitou.wordpress.com/tag/new/'>new</a>, <a href='http://ludopoitou.wordpress.com/tag/year/'>year</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ludopoitou.wordpress.com/970/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ludopoitou.wordpress.com/970/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ludopoitou.wordpress.com/970/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ludopoitou.wordpress.com/970/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ludopoitou.wordpress.com/970/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ludopoitou.wordpress.com/970/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ludopoitou.wordpress.com/970/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ludopoitou.wordpress.com/970/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ludopoitou.wordpress.com/970/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ludopoitou.wordpress.com/970/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ludopoitou.wordpress.com/970/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ludopoitou.wordpress.com/970/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ludopoitou.wordpress.com/970/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ludopoitou.wordpress.com/970/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=970&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ludopoitou.wordpress.com/2012/01/03/happy-new-year-2012/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4c7d0f23ff8919a2720a7845ba1d4e5a?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=R" medium="image">
			<media:title type="html">Ludo</media:title>
		</media:content>

		<media:content url="http://ludopoitou.files.wordpress.com/2012/01/bw2012_txt.jpg" medium="image">
			<media:title type="html">Best Wishes for 2012</media:title>
		</media:content>
	</item>
		<item>
		<title>Seasons Greetings&#8230;</title>
		<link>http://ludopoitou.wordpress.com/2011/12/24/seasons-greetings/</link>
		<comments>http://ludopoitou.wordpress.com/2011/12/24/seasons-greetings/#comments</comments>
		<pubDate>Sat, 24 Dec 2011 17:27:09 +0000</pubDate>
		<dc:creator>Ludo</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">https://ludopoitou.wordpress.com/?p=964</guid>
		<description><![CDATA[2011 has been an amazing year for me and ForgeRock. I&#8217;m so thankful to ForgeRock for offering me the opportunity build a strong engineering team in Grenoble, and to Matthew, Gary and Mark for taking on brilliantly the lead on so many fronts. OpenDJ is a very strong product, successfully deployed in production at many [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=964&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.flickr.com/photos/ludovicpoitou/6560194635/" title="LP0_1707 by ludovicp, on Flickr"><img src="http://farm8.staticflickr.com/7027/6560194635_bb482d89e6.jpg" width="500" height="333" align="center" alt="Xmas picture" /></a><br />
2011 has been an amazing year for me and ForgeRock. I&#8217;m so thankful to ForgeRock for offering me the opportunity build a strong engineering team in Grenoble, and to Matthew, Gary and Mark for taking on brilliantly the lead on so many fronts. OpenDJ is a very strong product, successfully deployed in production at many customers. Matthew is driving excellence in the project development and there&#8217;s been more contributions to the project in the last 6 months than in the 4 years of the life of OpenDS. The quality of all ForgeRock products is improving under Gary&#8217;s leadership. And  the documentation is thickening under Mark&#8217;s pen.<br />
I&#8217;m looking forward to the new year as we will, with no doubt, continue to thrive and have fun. And we will grow our engineering team worldwide and more specifically in Grenoble. </p>
<p>But now it is time for some vacation and quality time with the family. So I wish you all a Merry Christmas and a Happy New Year 2012. May peace, love and prosperity follow you always.</p>
<br />Filed under: <a href='http://ludopoitou.wordpress.com/category/general/'>General</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ludopoitou.wordpress.com/964/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ludopoitou.wordpress.com/964/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ludopoitou.wordpress.com/964/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ludopoitou.wordpress.com/964/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ludopoitou.wordpress.com/964/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ludopoitou.wordpress.com/964/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ludopoitou.wordpress.com/964/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ludopoitou.wordpress.com/964/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ludopoitou.wordpress.com/964/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ludopoitou.wordpress.com/964/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ludopoitou.wordpress.com/964/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ludopoitou.wordpress.com/964/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ludopoitou.wordpress.com/964/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ludopoitou.wordpress.com/964/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=964&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ludopoitou.wordpress.com/2011/12/24/seasons-greetings/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4c7d0f23ff8919a2720a7845ba1d4e5a?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=R" medium="image">
			<media:title type="html">Ludo</media:title>
		</media:content>

		<media:content url="http://farm8.staticflickr.com/7027/6560194635_bb482d89e6.jpg" medium="image">
			<media:title type="html">Xmas picture</media:title>
		</media:content>
	</item>
		<item>
		<title>Benchmark proves OpenDJ fastest directory server !</title>
		<link>http://ludopoitou.wordpress.com/2011/12/21/benchmark-proves-opendj-fastest-directory-server/</link>
		<comments>http://ludopoitou.wordpress.com/2011/12/21/benchmark-proves-opendj-fastest-directory-server/#comments</comments>
		<pubDate>Wed, 21 Dec 2011 10:49:48 +0000</pubDate>
		<dc:creator>Ludo</dc:creator>
				<category><![CDATA[Directory Services]]></category>
		<category><![CDATA[ldap]]></category>
		<category><![CDATA[directory]]></category>
		<category><![CDATA[directory-server]]></category>
		<category><![CDATA[opensource]]></category>
		<category><![CDATA[performance]]></category>
		<category><![CDATA[opendj]]></category>

		<guid isPermaLink="false">http://ludopoitou.wordpress.com/?p=953</guid>
		<description><![CDATA[Isode has just released a benchmark of their M-Vault R15.1 directory server, and has run some comparative tests against OpenLDAP and OpenDJ. While the benchmark demonstrates that M-Vault is one of the best directory server out there (the new release has some really impressive search performance) , I paid more attention to the write performance, and I [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=953&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Isode has just <a title="M-Vault R15.1 directory benchmark whitepaper" href="http://www.isode.com/whitepapers/m-vault-benchmarks.html">released a benchmark</a> of their <a title="Isode M-Vault LDAP/X.500 directory server" href="http://www.isode.com/products/m-vault-directory.html">M-Vault R15.1 directory server</a>, and has run some comparative tests against <a title="OpenLDAP" href="http://www.openldap.org">OpenLDAP</a> and <a title="OpenDJ, the open source LDAP directory server in Java" href="http://opendj.forgerock.org/">OpenDJ</a>.</p>
<p>While the benchmark demonstrates that M-Vault is one of the best directory server out there (the new release has some really impressive search performance) , I paid more attention to the write performance, and I really like those results that are showing the OpenDJ is the fastest directory server for write operations, even when modifications are mixed with searches.</p>
<p><img class="aligncenter size-full wp-image-954" title="Summary of write performances from M-Vault benchmark/" src="http://ludopoitou.files.wordpress.com/2011/12/mvault_modperfs.png?w=620" alt="Benchmark write performance summary" /></p>
<p style="text-align:center;"><span style="color:#999999;"><em>Captured from Isode benchmark white-paper.</em></span></p>
<p>Thanks Isode for running those tests, and making those numbers publicly available.</p>
<br />Filed under: <a href='http://ludopoitou.wordpress.com/category/directory-services/'>Directory Services</a> Tagged: <a href='http://ludopoitou.wordpress.com/tag/directory/'>directory</a>, <a href='http://ludopoitou.wordpress.com/tag/directory-server/'>directory-server</a>, <a href='http://ludopoitou.wordpress.com/tag/ldap/'>ldap</a>, <a href='http://ludopoitou.wordpress.com/tag/opendj/'>opendj</a>, <a href='http://ludopoitou.wordpress.com/tag/opensource/'>opensource</a>, <a href='http://ludopoitou.wordpress.com/tag/performance/'>performance</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ludopoitou.wordpress.com/953/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ludopoitou.wordpress.com/953/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ludopoitou.wordpress.com/953/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ludopoitou.wordpress.com/953/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ludopoitou.wordpress.com/953/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ludopoitou.wordpress.com/953/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ludopoitou.wordpress.com/953/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ludopoitou.wordpress.com/953/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ludopoitou.wordpress.com/953/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ludopoitou.wordpress.com/953/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ludopoitou.wordpress.com/953/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ludopoitou.wordpress.com/953/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ludopoitou.wordpress.com/953/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ludopoitou.wordpress.com/953/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=953&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ludopoitou.wordpress.com/2011/12/21/benchmark-proves-opendj-fastest-directory-server/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4c7d0f23ff8919a2720a7845ba1d4e5a?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=R" medium="image">
			<media:title type="html">Ludo</media:title>
		</media:content>

		<media:content url="http://ludopoitou.files.wordpress.com/2011/12/mvault_modperfs.png" medium="image">
			<media:title type="html">Summary of write performances from M-Vault benchmark/</media:title>
		</media:content>
	</item>
		<item>
		<title>An important tuning flag for OpenDJ with 64bit JVM&#8230;</title>
		<link>http://ludopoitou.wordpress.com/2011/12/16/an-important-tuning-flag-for-opendj-with-64bit-jvm/</link>
		<comments>http://ludopoitou.wordpress.com/2011/12/16/an-important-tuning-flag-for-opendj-with-64bit-jvm/#comments</comments>
		<pubDate>Fri, 16 Dec 2011 11:47:13 +0000</pubDate>
		<dc:creator>Ludo</dc:creator>
				<category><![CDATA[Directory Services]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[ldap]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[directory-server]]></category>
		<category><![CDATA[opensource]]></category>
		<category><![CDATA[performance]]></category>
		<category><![CDATA[opendj]]></category>
		<category><![CDATA[tuning]]></category>
		<category><![CDATA[database]]></category>

		<guid isPermaLink="false">http://ludopoitou.wordpress.com/?p=951</guid>
		<description><![CDATA[If you&#8217;re running OpenDJ with a 64bit JVM with less than 32GB of heap size, be aware of the need to explicitly set the -XX:+UseCompressedOops option (unless you want to disable it). Compressed oops is supported and enabled by default in Java SE 6u23 and later, when running a 64bit JBM with a value of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=951&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;re running <a title="OpenDJ, the open source LDAP directory services in Java" href="http://opendj.forgerock.org/">OpenDJ</a> with a 64bit JVM with less than 32GB of heap size, be aware of the need to explicitly set the <strong>-XX:+UseCompressedOops</strong> option (unless you want to disable it).</p>
<p>Compressed oops is supported and enabled by default in Java SE 6u23 and later, when running a 64bit JBM with a value of -Xmx lower than 32GB. You can find more information about Compressed Oops in Java technical notes here: <a href="http://download.oracle.com/javase/7/docs/technotes/guides/vm/performance-enhancements-7.html">http://download.oracle.com/javase/7/docs/technotes/guides/vm/performance-enhancements-7.html</a></p>
<p>However, OpenDJ internal database, in order to estimate properly the occupation of the DB cache and tune the cache eviction threads, needs to take into account the compressed oops option. For this is relies on the JVM option to be set explicitly. If the option is not explicitly set, the database may consider the cache full when it&#8217;s not, and run cache eviction too early, resulting in less optimized performances.</p>
<p>So, with 64bit JVM, make sure you add the <strong>-XX:+UseCompressedOops</strong> option to the <em>start-ds</em> line in the <em>config/java.properties</em> file. Then run <em>bin/dsjavaproperties</em> and restart OpenDJ to benefit from the new settings.</p>
<br />Filed under: <a href='http://ludopoitou.wordpress.com/category/directory-services/'>Directory Services</a> Tagged: <a href='http://ludopoitou.wordpress.com/tag/database/'>database</a>, <a href='http://ludopoitou.wordpress.com/tag/directory-server/'>directory-server</a>, <a href='http://ludopoitou.wordpress.com/tag/java-2/'>java</a>, <a href='http://ludopoitou.wordpress.com/tag/ldap/'>ldap</a>, <a href='http://ludopoitou.wordpress.com/tag/opendj/'>opendj</a>, <a href='http://ludopoitou.wordpress.com/tag/opensource/'>opensource</a>, <a href='http://ludopoitou.wordpress.com/tag/performance/'>performance</a>, <a href='http://ludopoitou.wordpress.com/tag/tips/'>Tips</a>, <a href='http://ludopoitou.wordpress.com/tag/tuning/'>tuning</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ludopoitou.wordpress.com/951/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ludopoitou.wordpress.com/951/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ludopoitou.wordpress.com/951/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ludopoitou.wordpress.com/951/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ludopoitou.wordpress.com/951/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ludopoitou.wordpress.com/951/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ludopoitou.wordpress.com/951/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ludopoitou.wordpress.com/951/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ludopoitou.wordpress.com/951/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ludopoitou.wordpress.com/951/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ludopoitou.wordpress.com/951/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ludopoitou.wordpress.com/951/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ludopoitou.wordpress.com/951/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ludopoitou.wordpress.com/951/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=951&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ludopoitou.wordpress.com/2011/12/16/an-important-tuning-flag-for-opendj-with-64bit-jvm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4c7d0f23ff8919a2720a7845ba1d4e5a?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=R" medium="image">
			<media:title type="html">Ludo</media:title>
		</media:content>
	</item>
		<item>
		<title>OpenDJ success story : Ziggo</title>
		<link>http://ludopoitou.wordpress.com/2011/12/13/opendj-success-story-ziggo/</link>
		<comments>http://ludopoitou.wordpress.com/2011/12/13/opendj-success-story-ziggo/#comments</comments>
		<pubDate>Tue, 13 Dec 2011 15:38:55 +0000</pubDate>
		<dc:creator>Ludo</dc:creator>
				<category><![CDATA[Directory Services]]></category>
		<category><![CDATA[customer]]></category>
		<category><![CDATA[directory]]></category>
		<category><![CDATA[directory-server]]></category>
		<category><![CDATA[ForgeRock]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[ldap]]></category>
		<category><![CDATA[opendj]]></category>
		<category><![CDATA[opensource]]></category>
		<category><![CDATA[success]]></category>

		<guid isPermaLink="false">http://ludopoitou.wordpress.com/?p=946</guid>
		<description><![CDATA[A few months ago, we worked with Ziggo in Netherland, to help them transition their legacy environment to ForgeRock I3 Open Platform. Part of the transition, they&#8217;ve replaced Sun Directory Server Enterprise Edition (DSEE) with OpenDJ, running in 3 data-centers (and different sites), and over 2.5 Million entries, in a very smooth and well controlled migration [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=946&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A few months ago, we worked with <a title="Ziggo company" href="https://www.ziggo.com/en/">Ziggo</a> in Netherland, to help them transition their legacy environment to <a title="ForgeRock I3 Open Platform" href="http://forgerock.com/strategy.html">ForgeRock I3 Open Platform</a>. Part of the transition, they&#8217;ve replaced Sun Directory Server Enterprise Edition (DSEE) with OpenDJ, running in 3 data-centers (and different sites), and over 2.5 Million entries, in a very smooth and well controlled migration process.</p>
<p>They&#8217;ve now been running OpenDJ and OpenAM in production for a few months and we&#8217;re really happy to be able to share the details of the story with you. Get the <a title="Ziggo case study (PDF, A4)" href="http://forgerock.com/sites/default/files/Ziggo%20Case%20Study%20TRS%20A4.pdf">Ziggo Case Study (PDF)</a>.</p>
<p>You can find more details about <a title="OpenDJ, the open source LDAP directory services in Java." href="http://forgerock.com/opendj.html">OpenDJ on ForgeRock web site</a>.</p>
<br />Filed under: <a href='http://ludopoitou.wordpress.com/category/directory-services/'>Directory Services</a> Tagged: <a href='http://ludopoitou.wordpress.com/tag/customer/'>customer</a>, <a href='http://ludopoitou.wordpress.com/tag/directory/'>directory</a>, <a href='http://ludopoitou.wordpress.com/tag/directory-server/'>directory-server</a>, <a href='http://ludopoitou.wordpress.com/tag/forgerock/'>ForgeRock</a>, <a href='http://ludopoitou.wordpress.com/tag/java-2/'>java</a>, <a href='http://ludopoitou.wordpress.com/tag/ldap/'>ldap</a>, <a href='http://ludopoitou.wordpress.com/tag/opendj/'>opendj</a>, <a href='http://ludopoitou.wordpress.com/tag/opensource/'>opensource</a>, <a href='http://ludopoitou.wordpress.com/tag/success/'>success</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ludopoitou.wordpress.com/946/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ludopoitou.wordpress.com/946/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ludopoitou.wordpress.com/946/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ludopoitou.wordpress.com/946/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ludopoitou.wordpress.com/946/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ludopoitou.wordpress.com/946/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ludopoitou.wordpress.com/946/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ludopoitou.wordpress.com/946/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ludopoitou.wordpress.com/946/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ludopoitou.wordpress.com/946/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ludopoitou.wordpress.com/946/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ludopoitou.wordpress.com/946/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ludopoitou.wordpress.com/946/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ludopoitou.wordpress.com/946/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=946&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ludopoitou.wordpress.com/2011/12/13/opendj-success-story-ziggo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4c7d0f23ff8919a2720a7845ba1d4e5a?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=R" medium="image">
			<media:title type="html">Ludo</media:title>
		</media:content>
	</item>
		<item>
		<title>OpenDJ 2.4.4 is now available</title>
		<link>http://ludopoitou.wordpress.com/2011/10/14/opendj-2-4-4-is-now-available/</link>
		<comments>http://ludopoitou.wordpress.com/2011/10/14/opendj-2-4-4-is-now-available/#comments</comments>
		<pubDate>Fri, 14 Oct 2011 15:57:36 +0000</pubDate>
		<dc:creator>Ludo</dc:creator>
				<category><![CDATA[Directory Services]]></category>
		<category><![CDATA[directory]]></category>
		<category><![CDATA[directory-server]]></category>
		<category><![CDATA[documentation]]></category>
		<category><![CDATA[ForgeRock]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[ldap]]></category>
		<category><![CDATA[opendj]]></category>
		<category><![CDATA[opensource]]></category>
		<category><![CDATA[release]]></category>

		<guid isPermaLink="false">http://ludopoitou.wordpress.com/?p=939</guid>
		<description><![CDATA[Months goes by, but the pace of releases remains. Today, I&#8217;m happy to announce that a new revision of OpenDJ, the open source LDAP directory server in Java has just been released. OpenDJ 2.4.4 is an update release of the OpenDJ project and improves reliability  by resolving issues found around the External Change Log, Replication, Password [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=939&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://ludopoitou.files.wordpress.com/2010/12/opendj-300x100.png"><img class="size-thumbnail wp-image-667 alignleft" title="OpenDJ-300x100" src="http://ludopoitou.files.wordpress.com/2010/12/opendj-300x100.png?w=150&#038;h=50" alt="" width="150" height="50" /></a>Months goes by, but the pace of releases remains. Today, I&#8217;m happy to announce that a new revision of <a title="OpenDJ, the open source LDAP directory services in Java" href="http://opendj.org/">OpenDJ, the open source LDAP directory server in Java</a> has just been released. OpenDJ 2.4.4 is an update release of the OpenDJ project and improves reliability  by resolving issues found around the External Change Log, Replication, Password Policy and GSSAPI. It also resolves a memory leak that occurred with specific LDAP extended operations, such as the Password Modify Extended Operation. The full details about the release have been posted in the <a title="OpenDJ 2.4.4 LDAP Directory Server Release Notes" href="https://wikis.forgerock.org/confluence/display/OPENDJ/OpenDJ+2.4.4+Release+Notes">OpenDJ 2.4.4 Release Notes</a>.</p>
<p>The release is built out of revision 7357 of the <a title="See activity on the b2.4 branch of the OpenDJ code repository with FishEye" href="http://sources.forgerock.org/changelog/opendj/branches/b2.4">b2.4 branch</a> of the code repository.</p>
<p>As usual, you can find every thing on the <a title="OpenDJ LDAP directory services Download page" href="http://www.forgerock.org/opendj.html">OpenDJ Downloads</a> page:</p>
<ul>
<li>The <a title="Install or Upgrade to OpenDJ 2.4.4 with the Java WebStart installer" href="http://www.forgerock.org/downloads/opendj/2.4.4/install/QuickSetup.jnlp">Java WebStart Installer</a></li>
<li>The <a title="OpenDJ 2.4.4 Zip package" href="http://www.forgerock.org/downloads/opendj/2.4.4/OpenDJ-2.4.4.zip">Zip package</a> (the SHA signature is <a title="SHA signature of the OpenDJ 2.4.4 Zip package" href="http://download.forgerock.org/downloads/opendj/2.4.4/OpenDJ-2.4.4.zip.sha">here</a>).</li>
<li>The <a title="OpenDJ 2.4.4 SVR4 package" href="http://www.forgerock.org/downloads/opendj/2.4.4/opendj.zip">SVR4 package for Solaris users</a>.</li>
<li>The <a title="OpenDJ 2.4.4 DSML Gateway" href="http://www.forgerock.org/downloads/opendj/2.4.4/OpenDJ-2.4.4-DSML.war">DSML gateway</a> for those who want to provide a web service access to their LDAP directory server.</li>
</ul>
<p>The draft documentation for OpenDJ, and more specifically the <a title="OpenDJ LDAP directory services Administration Guide" href="http://opendj.forgerock.org/doc/admin-guide/OpenDJ-Admin-Guide.html">Administration Guide</a>, has been updated on the <a title="Projet site for OpenDJ, the open source LDAP directory services in Java" href="http://opendj.forgerock.org/">OpenDJ project site</a>, still on the track for an accurate, reviewed version for OpenDJ 2.5.</p>
<p>Feedback is important to us and you can participate on the <a title="#OpenDJ IRC channel, the chat about OpenDJ LDAP directory services in Java" href="irc://irc.freenode.net/#opendj">IRC channel</a>, the <a title="ForgeRock.org mailing list information, regarding OpenDJ LDAP directory server, OpenAM Web SSO project, OpenIDM ..." href="http://lists.forgerock.org/mailman/listinfo/">mailing lists</a> or <a title="Register to ForgeRock.Org community site" href="http://idp.forgerock.org/openam/UI/Login?service=register">join our community</a>.</p>
<p>Enjoy !</p>
<br />Filed under: <a href='http://ludopoitou.wordpress.com/category/directory-services/'>Directory Services</a> Tagged: <a href='http://ludopoitou.wordpress.com/tag/directory/'>directory</a>, <a href='http://ludopoitou.wordpress.com/tag/directory-server/'>directory-server</a>, <a href='http://ludopoitou.wordpress.com/tag/documentation/'>documentation</a>, <a href='http://ludopoitou.wordpress.com/tag/forgerock/'>ForgeRock</a>, <a href='http://ludopoitou.wordpress.com/tag/java-2/'>java</a>, <a href='http://ludopoitou.wordpress.com/tag/ldap/'>ldap</a>, <a href='http://ludopoitou.wordpress.com/tag/opendj/'>opendj</a>, <a href='http://ludopoitou.wordpress.com/tag/opensource/'>opensource</a>, <a href='http://ludopoitou.wordpress.com/tag/release/'>release</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ludopoitou.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ludopoitou.wordpress.com/939/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ludopoitou.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ludopoitou.wordpress.com/939/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ludopoitou.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ludopoitou.wordpress.com/939/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ludopoitou.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ludopoitou.wordpress.com/939/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ludopoitou.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ludopoitou.wordpress.com/939/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ludopoitou.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ludopoitou.wordpress.com/939/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ludopoitou.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ludopoitou.wordpress.com/939/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=939&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ludopoitou.wordpress.com/2011/10/14/opendj-2-4-4-is-now-available/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4c7d0f23ff8919a2720a7845ba1d4e5a?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=R" medium="image">
			<media:title type="html">Ludo</media:title>
		</media:content>

		<media:content url="http://ludopoitou.files.wordpress.com/2010/12/opendj-300x100.png?w=150" medium="image">
			<media:title type="html">OpenDJ-300x100</media:title>
		</media:content>
	</item>
		<item>
		<title>Upcoming events</title>
		<link>http://ludopoitou.wordpress.com/2011/10/07/upcoming-events/</link>
		<comments>http://ludopoitou.wordpress.com/2011/10/07/upcoming-events/#comments</comments>
		<pubDate>Fri, 07 Oct 2011 12:03:12 +0000</pubDate>
		<dc:creator>Ludo</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[ForgeRock]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[ldapcon]]></category>
		<category><![CDATA[opensource]]></category>

		<guid isPermaLink="false">http://ludopoitou.wordpress.com/?p=936</guid>
		<description><![CDATA[I&#8217;ve been pretty busy at ForgeRock and haven&#8217;t found much time to post here. I&#8217;ll try to improve in the coming weeks. Meanwhile, I&#8217;d like to share a number of events in which I&#8217;m participating: October 10, 11. LDAPCon in Heidelberg, Germany. I have a couple of presentations on the first day, and will be [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=936&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been pretty busy at <a title="ForgeRock, open source Identity Management software vendor" href="http://www.forgerock.com/">ForgeRock</a> and haven&#8217;t found much time to post here. I&#8217;ll try to improve in the coming weeks. Meanwhile, I&#8217;d like to share a number of events in which I&#8217;m participating:</p>
<p>October 10, 11. <a title="3rd LDAP International Conference." href="http://www.daasi.de/ldapcon2011/index.php?site=main">LDAPCon</a> in Heidelberg, Germany. I have a <a title="LDAPCon program" href="http://www.daasi.de/ldapcon2011/index.php?site=program">couple of presentations</a> on the first day, and will be around until the end of the conference. If you want to meet and discuss, drop me a note.</p>
<p>October 26, 27, 28. <a title="Free and Open Source Software in Academia, the conference" href="http://fossa.inria.fr/">fOSSA</a> in Lyon, France. I will be attending the 3 days of the conference, presenting on Thursday 27th in the <a title="fOSSA Program, development track" href="http://fossa.inria.fr/program/development/">Development track</a>. FOSSa is a free conference, that focuses on open source communities and projects, without any marketing spin. <a title="FOSSa Registration" href="http://fossa.inria.fr/register/">Register now</a>.</p>
<p>November 8th, <a title="OpenIDM Summit" href="http://summit.openidm.forgerock.org/">OpenIDM Summit</a> in Darmstadt, Germany. I won&#8217;t be able to attend that summit, but it&#8217;s a great opportunity to learn more about ForgeRock open source Identity Management solutions.  <a title="OpenIDM Summit Registration" href="http://summit.openidm.forgerock.org/register.html">Registration is already open</a>, don&#8217;t wait !</p>
<p>We&#8217;re also working on a one day broader <a title="ForgeRock I3 Open Platform" href="http://www.forgerock.com/strategy.html">ForgeRock I3 Open Platform</a> event, some time late November. I&#8217;ll let you know when it&#8217;s finalized, but I will be presenting OpenDJ along with the other ForgeRock product managers.</p>
<p>I hope to see you soon, <a title="LDAPCon venue" href="http://www.daasi.de/ldapcon2011/index.php?site=venue">here</a> or <a title="FOSSA venue" href="http://fossa.inria.fr/conference-organisation/venue/">there</a>.</p>
<br />Filed under: <a href='http://ludopoitou.wordpress.com/category/general/'>General</a> Tagged: <a href='http://ludopoitou.wordpress.com/tag/conference/'>conference</a>, <a href='http://ludopoitou.wordpress.com/tag/forgerock/'>ForgeRock</a>, <a href='http://ludopoitou.wordpress.com/tag/identity-2/'>identity</a>, <a href='http://ludopoitou.wordpress.com/tag/ldapcon/'>ldapcon</a>, <a href='http://ludopoitou.wordpress.com/tag/opensource/'>opensource</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ludopoitou.wordpress.com/936/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ludopoitou.wordpress.com/936/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ludopoitou.wordpress.com/936/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ludopoitou.wordpress.com/936/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ludopoitou.wordpress.com/936/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ludopoitou.wordpress.com/936/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ludopoitou.wordpress.com/936/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ludopoitou.wordpress.com/936/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ludopoitou.wordpress.com/936/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ludopoitou.wordpress.com/936/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ludopoitou.wordpress.com/936/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ludopoitou.wordpress.com/936/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ludopoitou.wordpress.com/936/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ludopoitou.wordpress.com/936/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=936&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ludopoitou.wordpress.com/2011/10/07/upcoming-events/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4c7d0f23ff8919a2720a7845ba1d4e5a?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=R" medium="image">
			<media:title type="html">Ludo</media:title>
		</media:content>
	</item>
		<item>
		<title></title>
		<link>http://ludopoitou.wordpress.com/2011/10/07/%ef%a3%bf/</link>
		<comments>http://ludopoitou.wordpress.com/2011/10/07/%ef%a3%bf/#comments</comments>
		<pubDate>Fri, 07 Oct 2011 09:50:41 +0000</pubDate>
		<dc:creator>Ludo</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://ludopoitou.wordpress.com/?p=929</guid>
		<description><![CDATA[Think Different Filed under: General<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=929&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://us1.campaign-archive1.com/?u=028de8672d5f9a229f15e9edf&amp;id=4286a78f97&amp;e=0639015b9a"><img class="size-full wp-image-930 alignnone" title="steve-jobs-1011j" src="http://ludopoitou.files.wordpress.com/2011/10/steve-jobs-1011j.jpeg?w=620&#038;h=487" alt="" width="620" height="487" /></a></p>
<p style="text-align:center;">Think Different</p>
<br />Filed under: <a href='http://ludopoitou.wordpress.com/category/general/'>General</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ludopoitou.wordpress.com/929/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ludopoitou.wordpress.com/929/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ludopoitou.wordpress.com/929/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ludopoitou.wordpress.com/929/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ludopoitou.wordpress.com/929/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ludopoitou.wordpress.com/929/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ludopoitou.wordpress.com/929/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ludopoitou.wordpress.com/929/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ludopoitou.wordpress.com/929/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ludopoitou.wordpress.com/929/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ludopoitou.wordpress.com/929/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ludopoitou.wordpress.com/929/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ludopoitou.wordpress.com/929/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ludopoitou.wordpress.com/929/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=929&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ludopoitou.wordpress.com/2011/10/07/%ef%a3%bf/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4c7d0f23ff8919a2720a7845ba1d4e5a?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=R" medium="image">
			<media:title type="html">Ludo</media:title>
		</media:content>

		<media:content url="http://ludopoitou.files.wordpress.com/2011/10/steve-jobs-1011j.jpeg" medium="image">
			<media:title type="html">steve-jobs-1011j</media:title>
		</media:content>
	</item>
		<item>
		<title>LDAPCon 2011 program is available</title>
		<link>http://ludopoitou.wordpress.com/2011/08/31/ldapcon-2011-program-is-available/</link>
		<comments>http://ludopoitou.wordpress.com/2011/08/31/ldapcon-2011-program-is-available/#comments</comments>
		<pubDate>Wed, 31 Aug 2011 16:01:28 +0000</pubDate>
		<dc:creator>Ludo</dc:creator>
				<category><![CDATA[Directory Services]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[directory]]></category>
		<category><![CDATA[directory-server]]></category>
		<category><![CDATA[ldap]]></category>
		<category><![CDATA[ldapcon]]></category>
		<category><![CDATA[opendj]]></category>
		<category><![CDATA[opensource]]></category>

		<guid isPermaLink="false">http://ludopoitou.wordpress.com/?p=926</guid>
		<description><![CDATA[LDAPCon 2011, the 3rd International Conference on LDAP, has finalized its program and the registration is open. The program looks awesome with the participation of many active developers of open source projects, as well as directory vendors and deployment specialists. This year, I have the immense honor to open the conference with a presentation titled: [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=926&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" title="Picture of Location of LDAPCon 2011." src="http://www.daasi.de/ldapcon2011/images/pma.jpg" alt="" width="180" height="238" /></p>
<p><a title="LDAPCon, the 3rd International conference on LDAP" href="http://ldapcon.org/">LDAPCon 2011, the 3rd International Conference on LDAP</a>, has finalized its program and the registration is open.</p>
<p>The <a title="LDAPCon 2011 program" href="http://www.daasi.de/ldapcon2011/index.php?site=program">program</a> looks awesome with the participation of many active developers of open source projects, as well as directory vendors and deployment specialists. This year, I have the immense honor to open the conference with a presentation titled: &#8220;<a title="Is LDAP Dead ? - presentation abstract" href="http://www.daasi.de/ldapcon2011/index.php?site=ldap-dead">Is LDAP dead ?</a>&#8221; which will be followed by a short general discussion. You don&#8217;t want to miss it !</p>
<p>I will also <a title="OpenDJ: Life after OpenDS and Sun - a presentation about the OpenDJ project" href="http://www.daasi.de/ldapcon2011/index.php?site=opendj">present where we are</a> with the <a title="OpenDJ, open source ldap directory server for the Java platform" href="http://opendj.forgerock.org/">OpenDJ</a> project which is continuing what Sun initiated with OpenDS to replace its aging Sun Directory Server Enterprise Edition product.</p>
<p>The conference will take place on October 10-11 2011, in Heidelberg, Germany. Don&#8217;t wait until the last minute, <a title="LDAPCon 2011 Registration information and form" href="http://www.daasi.de/ldapcon2011/index.php?site=registration">register NOW</a>.</p>
<p>&nbsp;</p>
<br />Filed under: <a href='http://ludopoitou.wordpress.com/category/directory-services/'>Directory Services</a> Tagged: <a href='http://ludopoitou.wordpress.com/tag/conference/'>conference</a>, <a href='http://ludopoitou.wordpress.com/tag/directory/'>directory</a>, <a href='http://ludopoitou.wordpress.com/tag/directory-server/'>directory-server</a>, <a href='http://ludopoitou.wordpress.com/tag/ldap/'>ldap</a>, <a href='http://ludopoitou.wordpress.com/tag/ldapcon/'>ldapcon</a>, <a href='http://ludopoitou.wordpress.com/tag/opendj/'>opendj</a>, <a href='http://ludopoitou.wordpress.com/tag/opensource/'>opensource</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ludopoitou.wordpress.com/926/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ludopoitou.wordpress.com/926/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ludopoitou.wordpress.com/926/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ludopoitou.wordpress.com/926/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ludopoitou.wordpress.com/926/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ludopoitou.wordpress.com/926/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ludopoitou.wordpress.com/926/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ludopoitou.wordpress.com/926/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ludopoitou.wordpress.com/926/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ludopoitou.wordpress.com/926/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ludopoitou.wordpress.com/926/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ludopoitou.wordpress.com/926/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ludopoitou.wordpress.com/926/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ludopoitou.wordpress.com/926/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=926&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ludopoitou.wordpress.com/2011/08/31/ldapcon-2011-program-is-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4c7d0f23ff8919a2720a7845ba1d4e5a?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=R" medium="image">
			<media:title type="html">Ludo</media:title>
		</media:content>

		<media:content url="http://www.daasi.de/ldapcon2011/images/pma.jpg" medium="image">
			<media:title type="html">Picture of Location of LDAPCon 2011.</media:title>
		</media:content>
	</item>
		<item>
		<title>LDAP: Matching against the current time in OpenDJ</title>
		<link>http://ludopoitou.wordpress.com/2011/08/25/ldap-matching-against-the-current-time-in-opendj/</link>
		<comments>http://ludopoitou.wordpress.com/2011/08/25/ldap-matching-against-the-current-time-in-opendj/#comments</comments>
		<pubDate>Thu, 25 Aug 2011 14:39:01 +0000</pubDate>
		<dc:creator>Ludo</dc:creator>
				<category><![CDATA[Directory Services]]></category>
		<category><![CDATA[directory]]></category>
		<category><![CDATA[directory-server]]></category>
		<category><![CDATA[filter]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[ldap]]></category>
		<category><![CDATA[matching-rules]]></category>
		<category><![CDATA[opendj]]></category>
		<category><![CDATA[opensource]]></category>
		<category><![CDATA[searching]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://ludopoitou.wordpress.com/?p=885</guid>
		<description><![CDATA[In LDAP, attributes have different syntaxes. The one used to indicate date and time is the GeneralizedTime, a string representation of the date and time, typically expressed in GMT time. For example, when an entry is modified, the server maintains the modifytimestamp attribute and sets a value like 20110825120001Z (for 2011, Aug 25, 12:00:01 GMT). [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=885&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In LDAP, attributes have different syntaxes. The one used to indicate date and time is the GeneralizedTime, a string representation of the date and time, typically expressed in GMT time. For example, when an entry is modified, the server maintains the modifytimestamp attribute and sets a value like 20110825120001Z (for 2011, Aug 25, 12:00:01 GMT).</p>
<p>LDAP client applications often have to search for entries based on these date and time attributes, whether it is to find the entries that have been modified , or had the password changed recently&#8230; The way it is typically done, is the following: get from the system the current date, add or substract some fixed time (for example if you want to know the entries modified in the last 10 minutes), transform  to a GeneralizedTime, use that string in a search filter: (modifyTimestamp &gt;= 20110825130000Z). If the application repeats that search a minute later, it has to recompute the value again, and again&#8230;</p>
<p>Ideally what application writers would like is to express the filter as an expression like (modifyTimestamp&gt;=${CurrentTime} &#8211; 10 mn). However this is not compliant with LDAP. The proper way to solve this is to use extensible matching rules, and for that purpose, we&#8217;ve added 2 &#8220;relative time&#8221; matching rules in <a title="OpenDJ, the open source LDAP directory services for Java" href="http://opendj.forgerock.org/">OpenDJ, the Open source LDAP Directory services for Java</a>: one for &#8220;lower than&#8221; and one for &#8220;greater than&#8221;.</p>
<pre>matchingrules: ( 1.3.6.1.4.1.26027.1.4.6 NAME ( 'relativeTimeLTOrderingMatch' 'relativeTimeOrderingMatch.lt' )
  SYNTAX 1.3.6.1.4.1.1466.115.121.1.24 )
matchingrules: ( 1.3.6.1.4.1.26027.1.4.5 NAME ( 'relativeTimeGTOrderingMatch' 'relativeTimeOrderingMatch.gt' )
  SYNTAX 1.3.6.1.4.1.1466.115.121.1.24 )</pre>
<p>The way the matching rules work is pretty simple : (attribute:MatchingRule:=Offset), where the offset is a signed integer follow by its unit, either s for seconds, m for minutes, h for hours, d for days or w for weeks.</p>
<p>You can translate a statement to &#8220;is Attribute greater than (or lower than) CurrentTime +/- Offset&#8221;</p>
<p>(lastLoginTime:1.3.6.1.4.1.26027.1.4.6:=-4w) will match all entries who have a lastLoginTime value smaller than the Current Time minus 4 weeks, i.e. all entries who have a lastLoginTime older than 4 weeks.</p>
<p>(pwdExpirationTime:1.3.6.1.4.1.26027.1.4.5:=5d) will match all entries that have pwdExpirationTime greater than the Current Time plus 5 days, i.e. all entries that will expire in more than 5 days.</p>
<p>The true benefit of those matching rules, is actually when expressing policies in the OpenDJ server, for example for granting or denying access based on some attribute with a generalizedTime syntax, such as last login time, pwdChangedTime, modifyTimeStamp &#8230;</p>
<p>For example, imagine an auxiliary objectClass representing a service, with some specific attributes including an expiration date : validUntil. Now, you want to allow these attributes to be read only if the expiration date is not passed.</p>
<pre>aci: (targetattr="serviceAttr1 || serverAttr2")(targetfilter="(validUntil:1.3.6.1.4.1.26027.1.4.5:=0s)")
  (version 3.0; acl "Read Valid service attributes"; allow (read, search, compare)
  userdn="ldap:///all";)</pre>
<p>As you can see, this is a good way to hide (deny access to) stale data in a directory server, and to simplify client applications that need to search for entries based on some generalizedTime attributes. For example, consider using these &#8220;relative time&#8221; matching rules for all your audit queries for expired or unused accounts.</p>
<p>Finally, remember that the OpenDJ directory server doesn&#8217;t allow unindexed searches by default. So you might also want to create an index for the &#8220;relative time&#8221; matching rules. That&#8217;s a 2 steps process :</p>
<p>Define the index</p>
<pre>$ bin/dsconfig create-local-db-index --backend-name userRoot --set index-type:extensible \
 --set index-extensible-matching-rule:1.3.6.1.4.1.26027.1.4.5 \
 --set index-extensible-matching-rule:1.3.6.1.4.1.26027.1.4.6 \
 --index-name createTimestamp -h localhost -p 4444 \
 -D cn=Directory\ Manager -w secret12 -n -X</pre>
<p>Rebuild the index</p>
<pre>$ bin/rebuild-index -b dc=example,dc=com -i createTimestamp \
 -h localhost -p 4444 -D cn=directory\ manager -w secret12 -X</pre>
<br />Filed under: <a href='http://ludopoitou.wordpress.com/category/directory-services/'>Directory Services</a> Tagged: <a href='http://ludopoitou.wordpress.com/tag/directory/'>directory</a>, <a href='http://ludopoitou.wordpress.com/tag/directory-server/'>directory-server</a>, <a href='http://ludopoitou.wordpress.com/tag/filter/'>filter</a>, <a href='http://ludopoitou.wordpress.com/tag/java-2/'>java</a>, <a href='http://ludopoitou.wordpress.com/tag/ldap/'>ldap</a>, <a href='http://ludopoitou.wordpress.com/tag/matching-rules/'>matching-rules</a>, <a href='http://ludopoitou.wordpress.com/tag/opendj/'>opendj</a>, <a href='http://ludopoitou.wordpress.com/tag/opensource/'>opensource</a>, <a href='http://ludopoitou.wordpress.com/tag/searching/'>searching</a>, <a href='http://ludopoitou.wordpress.com/tag/tips/'>Tips</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ludopoitou.wordpress.com/885/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ludopoitou.wordpress.com/885/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ludopoitou.wordpress.com/885/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ludopoitou.wordpress.com/885/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ludopoitou.wordpress.com/885/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ludopoitou.wordpress.com/885/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ludopoitou.wordpress.com/885/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ludopoitou.wordpress.com/885/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ludopoitou.wordpress.com/885/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ludopoitou.wordpress.com/885/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ludopoitou.wordpress.com/885/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ludopoitou.wordpress.com/885/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ludopoitou.wordpress.com/885/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ludopoitou.wordpress.com/885/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=885&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ludopoitou.wordpress.com/2011/08/25/ldap-matching-against-the-current-time-in-opendj/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4c7d0f23ff8919a2720a7845ba1d4e5a?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=R" medium="image">
			<media:title type="html">Ludo</media:title>
		</media:content>
	</item>
		<item>
		<title>OpenAM universal gateway presentation at RMLL 2011</title>
		<link>http://ludopoitou.wordpress.com/2011/08/01/openam-universal-gateway-presentation-at-rmll-2011/</link>
		<comments>http://ludopoitou.wordpress.com/2011/08/01/openam-universal-gateway-presentation-at-rmll-2011/#comments</comments>
		<pubDate>Mon, 01 Aug 2011 16:40:25 +0000</pubDate>
		<dc:creator>Ludo</dc:creator>
				<category><![CDATA[Identity]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[authorization]]></category>
		<category><![CDATA[ForgeRock]]></category>
		<category><![CDATA[openam]]></category>
		<category><![CDATA[opensource]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[websso]]></category>

		<guid isPermaLink="false">http://ludopoitou.wordpress.com/?p=911</guid>
		<description><![CDATA[Last month, just before the French national day, I was in Strasbourg to participate in the RMLL. On the occasion, I did a presentation in the security track, about OpenAM Universal Gateway, another piece in the complex puzzle of Web Single Sign-On. The Universal Gateway solves an important problem in Access Management: allowing single sign-on [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=911&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Last month, just before the French national day, I was in <a title="Picture of Strasbourg cathedrale" href="https://picasaweb.google.com/ludovic.poitou/RMLL2011Strasbourg#5628832742850527298">Strasbourg</a> to participate in the <a title="RMLL 2011" href="http://2011.rmll.info/">RMLL</a>.</p>
<div class="wp-caption alignright" style="width: 267px"><a href="http://sbahloul.files.wordpress.com/2011/07/dsc_3635.jpg"><img class="  " title="Ludovic Poitou, presenting at RMLL" src="http://sbahloul.files.wordpress.com/2011/07/dsc_3635.jpg?w=257&#038;h=170" alt="" width="257" height="170" /></a><p class="wp-caption-text">Photo by Sebastien Bahloul</p></div>
<p>On the occasion, I did a presentation in the <a title="Security track at RMLL 2011" href="http://2011.rmll.info/-Securite-">security track</a>, about OpenAM Universal Gateway, another piece in the complex puzzle of Web Single Sign-On. The Universal Gateway solves an important problem in Access Management: allowing single sign-on for applications that are usually left out because they are based on legacy or non standard based technology.</p>
<p>The Universal Gateway comes from ApexIdentity, an acquisition that ForgeRock did in the spring. It&#8217;s been <a title="OpenAM Universal Gateway sources" href="http://sources.forgerock.org/browse/openam/trunk/gateway">released in open source</a> as part of the <a title="OpenAM: Browse through the sources" href="http://sources.forgerock.org/browse/openam/">OpenAM source code repository</a>.</p>
<p>The presentation I did was in French, and so are the <a title="OpenAM presentation slides on Slideshare" href="http://www.slideshare.net/ludomp/protection-des-applications-web-avec-openam">slides</a>.</p>
<p>You can find more about the Universal Gateway on <a title="ApexIdentity web site" href="http://apexidentity.com/">ApexIdentity web site</a>, and soon on <a title="OpenAM, opensource access management and federation product documentation" href="http://openam.forgerock.org/docs.html">OpenAM documentation</a>.</p>
<br />Filed under: <a href='http://ludopoitou.wordpress.com/category/identity/'>Identity</a> Tagged: <a href='http://ludopoitou.wordpress.com/tag/authentication/'>authentication</a>, <a href='http://ludopoitou.wordpress.com/tag/authorization/'>authorization</a>, <a href='http://ludopoitou.wordpress.com/tag/forgerock/'>ForgeRock</a>, <a href='http://ludopoitou.wordpress.com/tag/openam/'>openam</a>, <a href='http://ludopoitou.wordpress.com/tag/opensource/'>opensource</a>, <a href='http://ludopoitou.wordpress.com/tag/security/'>security</a>, <a href='http://ludopoitou.wordpress.com/tag/websso/'>websso</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ludopoitou.wordpress.com/911/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ludopoitou.wordpress.com/911/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ludopoitou.wordpress.com/911/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ludopoitou.wordpress.com/911/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ludopoitou.wordpress.com/911/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ludopoitou.wordpress.com/911/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ludopoitou.wordpress.com/911/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ludopoitou.wordpress.com/911/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ludopoitou.wordpress.com/911/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ludopoitou.wordpress.com/911/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ludopoitou.wordpress.com/911/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ludopoitou.wordpress.com/911/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ludopoitou.wordpress.com/911/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ludopoitou.wordpress.com/911/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=911&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ludopoitou.wordpress.com/2011/08/01/openam-universal-gateway-presentation-at-rmll-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4c7d0f23ff8919a2720a7845ba1d4e5a?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=R" medium="image">
			<media:title type="html">Ludo</media:title>
		</media:content>

		<media:content url="http://sbahloul.files.wordpress.com/2011/07/dsc_3635.jpg" medium="image">
			<media:title type="html">Ludovic Poitou, presenting at RMLL</media:title>
		</media:content>
	</item>
		<item>
		<title>OpenDJ: Analyzing Search Filters and Indexes</title>
		<link>http://ludopoitou.wordpress.com/2011/07/28/opendj-analyzing-search-filters-and-indexes/</link>
		<comments>http://ludopoitou.wordpress.com/2011/07/28/opendj-analyzing-search-filters-and-indexes/#comments</comments>
		<pubDate>Thu, 28 Jul 2011 07:27:34 +0000</pubDate>
		<dc:creator>Ludo</dc:creator>
				<category><![CDATA[Directory Services]]></category>
		<category><![CDATA[directory]]></category>
		<category><![CDATA[directory-server]]></category>
		<category><![CDATA[index]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[ldap]]></category>
		<category><![CDATA[opendj]]></category>
		<category><![CDATA[opensource]]></category>
		<category><![CDATA[performance]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[tuning]]></category>

		<guid isPermaLink="false">http://ludopoitou.wordpress.com/?p=718</guid>
		<description><![CDATA[LDAP directory services greatly rely on indexes to provide fast and accurate search results. OpenDJ, the open source LDAP directory services for the Java platform, provides a number of tools to ensure indexes are efficiently used or to optimize them for even better performances. To start with, OpenDJ rejects by default all unindexed searches, unless [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=718&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>LDAP directory services greatly rely on indexes to provide fast and accurate search results.</p>
<p><a title="OpenDJ, the open source LDAP directory services for the Java platform" href="http://opendj.forgerock.org/">OpenDJ, the open source LDAP directory services for the Java platform</a>, provides a number of tools to ensure indexes are efficiently used or to optimize them for even better performances.</p>
<p>To start with, OpenDJ rejects by default all unindexed searches, unless the authenticated user has the privilege to perform them. Unindexed searches are rejected because they result in scanning the whole database, which consumes lots of resources and time. There are legitimate uses of unindexed search though, and OpenDJ offers a way to control who can perform them through a privilege. To learn more about privileges, how to grant them, please check the <a title="OpenDJ, Administration Guide on Privileges and ACIs" href="http://opendj.forgerock.org/doc/admin-guide/OpenDJ-Admin-Guide/chap-privileges-acis.html">Administration Guide</a> or some of my <a title="Article on OpenDJ privileges for Administrators" href="http://ludopoitou.wordpress.com/2011/01/11/directory-administrative-accounts-cont/">previous</a><a title="Article on Directory Administrative Accounts with OpenDJ" href="http://ludopoitou.wordpress.com/2011/05/03/ldap-advanced-administration-for-enterprises/"> posts</a>.</p>
<p>When unindexed searches are completed, OpenDJ (starting with revision 7148 of the OpenDJ trunk, and therefore OpenDJ 2.5) does logs the &#8220;Unindexed&#8221; keyword as part of the Search Response access log message. But the access log file can also be used to identify search operations that are not making an optimal use of indexes. Simply check for those search responses that have been returned with an etime (execution time) greater than the average.</p>
<p>The access log example below contains both an unusually high etime (expressed in ms) and the Unindexed tag.</p>
<pre>[27/Jul/2011:20:27:27 +0200] SEARCH RES conn=0 op=1 msgID=2 result=0 nentries=10001 Unindexed etime=1846</pre>
<p>The <em><a title="OpenDJ verify-index reference" href="http://opendj.forgerock.org/doc/admin-guide/OpenDJ-Admin-Guide/verify-index-1.html">verify-index</a></em> command let you check that no index is corrupted (i.e. no data is missing from indexes).</p>
<p>The <em><a title="OpenDJ rebuild-index reference" href="http://opendj.forgerock.org/doc/admin-guide/OpenDJ-Admin-Guide/rebuild-index-1.html">rebuild-index</a></em> command let you build or rebuild an index that would be corrupted or had its configuration changed.</p>
<p>One of the tuning parameter of indexes is the <em>index-entry-limit</em> (which was known in Sun DSEE as the <em>AllIDsThreshold</em>), the maximum size of entries kept in an index record, before the server stop maintaining that record and consider it&#8217;s more efficient to scan the whole database. For more information on the index entry limit, check the <a href="http://opendj.forgerock.org/doc/admin-guide/OpenDJ-Admin-Guide/chap-indexing.html#d780e2730">Section 7.2.4 Changing Index Entry Limits</a> of the <a href="http://opendj.forgerock.org/doc/admin-guide/OpenDJ-Admin-Guide/chap-indexing.html">Indexing chapter of the Administration Guide</a>.</p>
<p>OpenDJ provides a static analyzer of indexes which can help to understand how well the attributes are indexed, as well as help to tune the index entry limit. This tool is a function of the <em><a title="OpenDJ dbtest reference manual" href="http://opendj.forgerock.org/doc/admin-guide/OpenDJ-Admin-Guide/dbtest-1.html">dbtest</a></em> utility and is simply used as follow:</p>
<pre>$ bin/dbtest list-index-status -n userRoot -b "dc=example,dc=com"</pre>
<p><span class="Apple-style-span" style="font-family:Consolas, Monaco, monospace;font-size:12px;line-height:18px;white-space:pre;">Index Name Index Type JE Database Name Index Valid Record Count Undefined 95% 90% 85%</span></p>
<pre>---------------------------------------------------------------------------------------------------------------------------------------
id2children                Index       dc_example_dc_com_id2children                true         2             0          0    0    0
id2subtree                 Index       dc_example_dc_com_id2subtree                 true         2             0          0    0    0
uid.equality               Index       dc_example_dc_com_uid.equality               true         2000          0          0    0    0
aci.presence               Index       dc_example_dc_com_aci.presence               true         0             0          0    0    0
ds-sync-conflict.equality  Index       dc_example_dc_com_ds-sync-conflict.equality  true         0             0          0    0    0
givenName.equality         Index       dc_example_dc_com_givenName.equality         true         2000          0          0    0    0
givenName.substring        Index       dc_example_dc_com_givenName.substring        true         5777          0          0    0    0
objectClass.equality       Index       dc_example_dc_com_objectClass.equality       true         6             0          0    0    0
member.equality            Index       dc_example_dc_com_member.equality            true         0             0          0    0    0
uniqueMember.equality      Index       dc_example_dc_com_uniqueMember.equality      true         0             0          0    0    0
cn.equality                Index       dc_example_dc_com_cn.equality                true         2000          0          0    0    0
cn.substring               Index       dc_example_dc_com_cn.substring               true         19407         0          0    0    0
sn.equality                Index       dc_example_dc_com_sn.equality                true         2000          0          0    0    0
sn.substring               Index       dc_example_dc_com_sn.substring               true         8147          0          0    0    0
telephoneNumber.equality   Index       dc_example_dc_com_telephoneNumber.equality   true         2000          0          0    0    0
telephoneNumber.substring  Index       dc_example_dc_com_telephoneNumber.substring  true         16506         0          0    0    0
ds-sync-hist.ordering      Index       dc_example_dc_com_ds-sync-hist.ordering      true         1             0          0    0    0
mail.equality              Index       dc_example_dc_com_mail.equality              true         2000          0          0    0    0
mail.substring             Index       dc_example_dc_com_mail.substring             true         7235          0          0    0    0
entryUUID.equality         Index       dc_example_dc_com_entryUUID.equality         true         2002          0          0    0    0

Total: 20</pre>
<p>If an index contains a non zero value (N) in the <em>undefined</em> column, it means N index keys have reached the index entry limit and are no longer maintained. This can be normal, for example with the ObjectClass equality index, where the vast majority of entries will have the same objectclasses (top, Person, organizationalPerson, inetOrgPerson). But, for other attributes, such as cn, it may indicate that the index entry limit is too low.</p>
<p>Finally, OpenDJ has an option to do a live analysis of search filters and how they use indexes. To enable live index analysis, simply enable it for the database backend that contains the data :</p>
<pre>dsconfig set-backend-prop --backend-name userRoot  --set index-filter-analyzer-enabled:true \
 --set max-entries:50 -h localhost -p 4444 -D cn=Directory\ Manager -w ****** -n -X</pre>
<p>The <em>max-entries</em> parameter specifies how many filter items are being analyzed and kept in memory. Only the last <em>max-entries</em> will be kept. If there is a huge variety of requests against the directory service, you might want to increase the number. However, keep in mind that the analysis is kept in memory, and the higher the number the largest the impact on the overall performances of the server.</p>
<p>We do not recommend that you leave the index analysis enabled all the time, especially in production. The index analyzer should be used to gather statistics over a flow of requests for a short period of time, and should be disabled afterwards to free the resources.</p>
<p>The result of the index analyzer can be retrieved under the <em>cn=monitor</em> suffix, more specifically as part of the <em>database environment</em> of the backend.</p>
<pre>$ bin/ldapsearch -p 1389 -D cn=directory\ manager -w secret12  \
-b "cn=userRoot Database Environment,cn=monitor" '(objectclass=*)' filter-use

dn: cn=userRoot Database Environment,cn=monitor
filter-use: (uid=user.*) hits:1 maxmatches:20 message:
filter-use: (tel=*) hits:1 maxmatches:-1 message:presence index type is disabled
  for the tel attribute
filter-use: (objectClass=groupOfURLs) hits:1 maxmatches:0 message:
filter-use: (objectClass=groupOfEntries) hits:1 maxmatches:0 message:
filter-use: (objectClass=person) hits:1 maxmatches:20 message:
filter-use: (objectClass=ds-virtual-static-group) hits:1 maxmatches:0 message:
filter-use: (aci=*) hits:1 maxmatches:0 message:
filter-use: (objectClass=groupOfNames) hits:1 maxmatches:0 message:
filter-use: (objectClass=groupOfUniqueNames) hits:1 maxmatches:0 message:
filter-use: (objectClass=ldapSubentry) hits:1 maxmatches:0 message:
filter-use: (objectClass=subentry) hits:1 maxmatches:0 message:</pre>
<p><em>hits</em> represents the number of time this filter was used. the <em>maxmatches</em> represents the maximum number of entries that were returned for that filter.</p>
<p>Index analysis and tuning is not a simple task, and I recommend to play with these tools  a lot on a test environment to understand how to get the best out of them. But, as you can see, OpenDJ provides you with all the tools you need to get the best performances out of your LDAP directory.</p>
<br />Filed under: <a href='http://ludopoitou.wordpress.com/category/directory-services/'>Directory Services</a> Tagged: <a href='http://ludopoitou.wordpress.com/tag/directory/'>directory</a>, <a href='http://ludopoitou.wordpress.com/tag/directory-server/'>directory-server</a>, <a href='http://ludopoitou.wordpress.com/tag/index/'>index</a>, <a href='http://ludopoitou.wordpress.com/tag/java-2/'>java</a>, <a href='http://ludopoitou.wordpress.com/tag/ldap/'>ldap</a>, <a href='http://ludopoitou.wordpress.com/tag/opendj/'>opendj</a>, <a href='http://ludopoitou.wordpress.com/tag/opensource/'>opensource</a>, <a href='http://ludopoitou.wordpress.com/tag/performance/'>performance</a>, <a href='http://ludopoitou.wordpress.com/tag/tips/'>Tips</a>, <a href='http://ludopoitou.wordpress.com/tag/tuning/'>tuning</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ludopoitou.wordpress.com/718/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ludopoitou.wordpress.com/718/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ludopoitou.wordpress.com/718/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ludopoitou.wordpress.com/718/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ludopoitou.wordpress.com/718/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ludopoitou.wordpress.com/718/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ludopoitou.wordpress.com/718/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ludopoitou.wordpress.com/718/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ludopoitou.wordpress.com/718/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ludopoitou.wordpress.com/718/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ludopoitou.wordpress.com/718/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ludopoitou.wordpress.com/718/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ludopoitou.wordpress.com/718/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ludopoitou.wordpress.com/718/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=718&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ludopoitou.wordpress.com/2011/07/28/opendj-analyzing-search-filters-and-indexes/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4c7d0f23ff8919a2720a7845ba1d4e5a?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=R" medium="image">
			<media:title type="html">Ludo</media:title>
		</media:content>
	</item>
		<item>
		<title>Newbie help : How to reset the Directory Manager&#8217;s password ?</title>
		<link>http://ludopoitou.wordpress.com/2011/06/30/newbie-help-how-to-reset-the-directory-managers-password/</link>
		<comments>http://ludopoitou.wordpress.com/2011/06/30/newbie-help-how-to-reset-the-directory-managers-password/#comments</comments>
		<pubDate>Thu, 30 Jun 2011 07:31:57 +0000</pubDate>
		<dc:creator>Ludo</dc:creator>
				<category><![CDATA[Directory Services]]></category>
		<category><![CDATA[directory-server]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[ldap]]></category>
		<category><![CDATA[opendj]]></category>
		<category><![CDATA[opensource]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://ludopoitou.wordpress.com/?p=876</guid>
		<description><![CDATA[We get this question quite often on IRC or mailling lists, from newbies who&#8217;ve installed OpenDJ (or OpenDS) for evaluation and forgot the Directory Manager&#8217;s password. So here are the steps : Make sure OpenDJ is stopped. bin/stop-ds Generate an encoded password for Directory Manager : bin/encode-password -s SSHA512 -c AS3cur3PassW0rd Encoded Password:  "{SSHA512}G/knE0xkyW2Af3+1MFy+yPYxchGgLuqog71R4njPJcs9t5NDAadqLxU7pxZjZkrDquQeb5aq7tum1ZFC3uE+r4Nmuil4S46A" Copy [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=876&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>We get this question quite often on <a title="OpenDJ on IRC.freenode.net" href="irc://irc.freenode.net/#opendj">IRC</a> or <a title="OpenDJ Mailing lists information" href="http://opendj.forgerock.org/mail-lists.html">mailling lists</a>, from newbies who&#8217;ve installed <a title="OpenDJ, the open source LDAP directory services in Java" href="http://opendj.org">OpenDJ</a> (or OpenDS) for evaluation and forgot the Directory Manager&#8217;s password.</p>
<p>So here are the steps :</p>
<p>Make sure OpenDJ is stopped.</p>
<pre>bin/stop-ds</pre>
<p>Generate an encoded password for Directory Manager :</p>
<pre>bin/encode-password -s SSHA512 -c <em>AS3cur3PassW0rd</em>
Encoded Password:  "{SSHA512}G/knE0xkyW2Af3+1MFy+yPYxchGgLuqog71R4njPJcs9t5NDAadqLxU7pxZjZkrDquQeb5aq7tum1ZFC3uE+r4Nmuil4S46A"</pre>
<p>Copy the string within quotes (without the quotes), and edit the <em>config/config.ldif</em> file.</p>
<p>Go down to the following entry</p>
<pre>dn: cn=Directory Manager,cn=Root DNs,cn=config</pre>
<p>Replace the value of userPassword with the newly generated one.</p>
<pre>dn: cn=Directory Manager,cn=Root DNs,cn=config
objectClass: person
objectClass: organizationalPerson
objectClass: inetOrgPerson
objectClass: top
objectClass: ds-cfg-root-dn-user
userpassword: {SSHA512}G/knE0xkyW2Af3+1MFy+yPYxchGgLuqog71R4njPJcs9t5NDAadqLxU7pxZjZkrDquQeb5aq7tum1ZFC3uE+r4Nmuil4S46A
...</pre>
<p>You can now restart the server and administer it.</p>
<br />Filed under: <a href='http://ludopoitou.wordpress.com/category/directory-services/'>Directory Services</a> Tagged: <a href='http://ludopoitou.wordpress.com/tag/directory-server/'>directory-server</a>, <a href='http://ludopoitou.wordpress.com/tag/java-2/'>java</a>, <a href='http://ludopoitou.wordpress.com/tag/ldap/'>ldap</a>, <a href='http://ludopoitou.wordpress.com/tag/opendj/'>opendj</a>, <a href='http://ludopoitou.wordpress.com/tag/opensource/'>opensource</a>, <a href='http://ludopoitou.wordpress.com/tag/password/'>password</a>, <a href='http://ludopoitou.wordpress.com/tag/security/'>security</a>, <a href='http://ludopoitou.wordpress.com/tag/tips/'>Tips</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ludopoitou.wordpress.com/876/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ludopoitou.wordpress.com/876/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ludopoitou.wordpress.com/876/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ludopoitou.wordpress.com/876/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ludopoitou.wordpress.com/876/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ludopoitou.wordpress.com/876/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ludopoitou.wordpress.com/876/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ludopoitou.wordpress.com/876/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ludopoitou.wordpress.com/876/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ludopoitou.wordpress.com/876/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ludopoitou.wordpress.com/876/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ludopoitou.wordpress.com/876/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ludopoitou.wordpress.com/876/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ludopoitou.wordpress.com/876/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=876&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ludopoitou.wordpress.com/2011/06/30/newbie-help-how-to-reset-the-directory-managers-password/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4c7d0f23ff8919a2720a7845ba1d4e5a?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=R" medium="image">
			<media:title type="html">Ludo</media:title>
		</media:content>
	</item>
		<item>
		<title>OpenDJ: Troubleshooting LDAP SSL connections</title>
		<link>http://ludopoitou.wordpress.com/2011/06/29/opendj-troubleshooting-ldap-ssl-connections/</link>
		<comments>http://ludopoitou.wordpress.com/2011/06/29/opendj-troubleshooting-ldap-ssl-connections/#comments</comments>
		<pubDate>Wed, 29 Jun 2011 15:20:20 +0000</pubDate>
		<dc:creator>Ludo</dc:creator>
				<category><![CDATA[Directory Services]]></category>
		<category><![CDATA[directory]]></category>
		<category><![CDATA[directory-server]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[ldap]]></category>
		<category><![CDATA[opendj]]></category>
		<category><![CDATA[opensource]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[troubleshooting]]></category>

		<guid isPermaLink="false">http://ludopoitou.wordpress.com/?p=831</guid>
		<description><![CDATA[Troubleshooting Secure Socket Layer (SSL, also now standardized as TLS) issues is not trivial and there is no secret sauce specific to OpenDJ. Should an LDAP SSL connection fails due to the server, you should find a descriptive error message in the server&#8217;s errors log (in logs/errors). But sometime the connection is aborted by the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=831&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Troubleshooting Secure Socket Layer (SSL, also now standardized as <a title="RFC5246 The Transport Layer Security (TLS) Protocol" href="http://tools.ietf.org/rfc/rfc5246.txt">TLS</a>) issues is not trivial and there is no secret sauce specific to <a title="OpenDJ, the open source LDAP directory services in Java" href="http://opendj.org">OpenDJ</a>.</p>
<p>Should an LDAP SSL connection fails due to the server, you should find a descriptive error message in the server&#8217;s errors log (in <em>logs/errors</em>). But sometime the connection is aborted by the client with some obscure message. Often we see a message ending with &#8220; <em>javax.net.ssl.SSLHandshakeException: no cipher suites in common</em>&#8220;.</p>
<p>Java has some debugging capabilities embedded and they are pretty easy to use with the <a title="OpenDJ, the open source LDAP directory services in Java" href="http://opendj.forgerock.org">OpenDJ LDAP directory server</a>, which just need to be restarted with some additional arguments: <em><strong>-Djavax.net.debug=all</strong></em> or <em><strong>-Djavax.net.debug=ssl</strong></em>.</p>
<p>There are two ways to add extra arguments to the OpenDJ server startup command, using an environment variable, or using the <em>java.properties</em> file.</p>
<p><strong>Using env variable</strong></p>
<p>- you define the OPENDS_JAVA_ARGS environment variable. And you restart the server. If you do so, make sure you include all previous arguments.</p>
<pre>OPENDS_JAVA_ARGS='-server -Xms1G -Xmx1G -Djavax.net.debug=ssl,handshake,trustmanager' bin/start-ds</pre>
<p><strong>Using the java.properties file</strong></p>
<p>Edit the <em>java.properties</em> file in the config directory.<br />
Since you probably only want to track the OpenDS directory server SSL access, you should append the <em>-Djavax.net.debug=ssl,handshake,trustmanager</em> args to the <em>start-ds</em> line (rather than applying it to all commands).</p>
<pre>start-ds.java-args=-Xms1G -Xmx1G -server -Djavax.net.debug=ssl,handshake,trustmanager</pre>
<p>Save the file and run the dsjavaproperties command:</p>
<pre>bin/dsjavaproperties</pre>
<p>Now restart the server, using the <em>start-ds</em> command</p>
<p><strong>Where is the output ?</strong></p>
<p><strong></strong>All SSL related logs are output in the <em>logs/server.out</em> file.<br />
To test, you can use ldapsearch :</p>
<pre>bin/ldapsearch -Z -X -p 1636 -b "" -s base '(objectclass=*)'</pre>
<p>And if you look into the <em>logs/server.out</em> file, you will see something similar to this:</p>
<pre>Using SSLEngineImpl.
 Allow unsafe renegotiation: false
 Allow legacy hello messages: true
 Is initial handshake: true
 Is secure renegotiation: false
 LDAP Request Handler 0 for connection handler LDAP Connection Handler 0.0.0.0 port 1636, READ: SSL v2, contentType = Handshake, translated length = 81
 *** ClientHello, TLSv1
 RandomCookie: GMT: 1287771875 bytes = { 68, 231, 5, 253, 105, 26, 137, 36, 38, 238, 12, 141, 110, 12, 59, 10, 192, 135, 113, 119, 108, 153, 10, 31, 127, 120, 110, 61 }
 Session ID: {}
 Cipher Suites: [SSL_RSA_WITH_RC4_128_MD5, SSL_RSA_WITH_RC4_128_SHA, TLS_RSA_WITH_AES_128_CBC_SHA, TLS_RSA_WITH_AES_256_CBC_SHA, TLS_DHE_RSA_WITH_AES_128_CBC_SHA, TLS_DHE_RSA_WITH_AES_256_CBC_SHA, TLS_DHE_DSS_WITH_AES_128_CBC_SHA, TLS_DHE_DSS_WITH_AES_256_CBC_SHA, SSL_RSA_WITH_3DES_EDE_CBC_SHA, SSL_DHE_RSA_WITH_3DES_EDE_CBC_SHA, SSL_DHE_DSS_WITH_3DES_EDE_CBC_SHA, SSL_RSA_WITH_DES_CBC_SHA, SSL_DHE_RSA_WITH_DES_CBC_SHA, SSL_DHE_DSS_WITH_DES_CBC_SHA, SSL_RSA_EXPORT_WITH_RC4_40_MD5, SSL_RSA_EXPORT_WITH_DES40_CBC_SHA, SSL_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA, SSL_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA, TLS_EMPTY_RENEGOTIATION_INFO_SCSV]
 ...</pre>
<p>This will help you to identify what part of the secure connection is failing and fix it.</p>
<p>Note that <em>-Djavax.net.debug=ssl</em> enables debug of the SSL connections, while <em>-Djavax.net.debug=all</em> enables full debugging including use of certificates, and more. You can also find more debug options by using <em>-Djavax.net.debug=help</em>.</p>
<p>&nbsp;</p>
<br />Filed under: <a href='http://ludopoitou.wordpress.com/category/directory-services/'>Directory Services</a> Tagged: <a href='http://ludopoitou.wordpress.com/tag/directory/'>directory</a>, <a href='http://ludopoitou.wordpress.com/tag/directory-server/'>directory-server</a>, <a href='http://ludopoitou.wordpress.com/tag/java-2/'>java</a>, <a href='http://ludopoitou.wordpress.com/tag/ldap/'>ldap</a>, <a href='http://ludopoitou.wordpress.com/tag/opendj/'>opendj</a>, <a href='http://ludopoitou.wordpress.com/tag/opensource/'>opensource</a>, <a href='http://ludopoitou.wordpress.com/tag/security/'>security</a>, <a href='http://ludopoitou.wordpress.com/tag/tips/'>Tips</a>, <a href='http://ludopoitou.wordpress.com/tag/troubleshooting/'>troubleshooting</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ludopoitou.wordpress.com/831/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ludopoitou.wordpress.com/831/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ludopoitou.wordpress.com/831/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ludopoitou.wordpress.com/831/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ludopoitou.wordpress.com/831/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ludopoitou.wordpress.com/831/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ludopoitou.wordpress.com/831/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ludopoitou.wordpress.com/831/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ludopoitou.wordpress.com/831/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ludopoitou.wordpress.com/831/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ludopoitou.wordpress.com/831/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ludopoitou.wordpress.com/831/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ludopoitou.wordpress.com/831/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ludopoitou.wordpress.com/831/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=831&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ludopoitou.wordpress.com/2011/06/29/opendj-troubleshooting-ldap-ssl-connections/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4c7d0f23ff8919a2720a7845ba1d4e5a?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=R" medium="image">
			<media:title type="html">Ludo</media:title>
		</media:content>
	</item>
		<item>
		<title>OpenDJ Tip: Auto-completion of dsconfig command</title>
		<link>http://ludopoitou.wordpress.com/2011/06/20/opendj-tip-auto-completion-of-dsconfig-command/</link>
		<comments>http://ludopoitou.wordpress.com/2011/06/20/opendj-tip-auto-completion-of-dsconfig-command/#comments</comments>
		<pubDate>Mon, 20 Jun 2011 07:05:49 +0000</pubDate>
		<dc:creator>Ludo</dc:creator>
				<category><![CDATA[Directory Services]]></category>
		<category><![CDATA[directory-server]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[ldap]]></category>
		<category><![CDATA[opendj]]></category>
		<category><![CDATA[opensource]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://ludopoitou.wordpress.com/?p=860</guid>
		<description><![CDATA[With OpenDJ LDAP directory services, a single command-line tool, dsconfig, is used to manage every configuration parameter of the server. The dsconfig command has several modes and useful options, some of them are not well known. So let me repeat them. interactive mode: if started with no parameter or no command, the tool goes in [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=860&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>With <a title="OpenDJ opensource LDAP directory services" href="http://opendj.org/">OpenDJ LDAP directory services</a>, a single command-line tool, <em>dsconfig</em>, is used to manage every configuration parameter of the server.</p>
<p>The <em>dsconfig</em> command has several modes and useful options, some of them are not well known. So let me repeat them.</p>
<ul>
<li>interactive mode: if started with no parameter or no command, the tool goes in interactive mode. This is a nice way to discover the various parts of OpenDJ configuration.</li>
<li>advanced mode: There are really a lot of configuration parameters in OpenDJ, so not all of them can be read or set by default. An advanced mode allows to view and edit the hidden ones.</li>
<li>scripted mode: dsconfig can be used with a file containing several commands, and will call them one after the other.</li>
<li>teaching mode: if the option &#8211;displayCommand is used in interactive mode, it will display the complete command to use for non interactive mode, or for scripted mode.</li>
</ul>
<div>But regardless of the different modes, there are really too many commands and options to remember. So shell completion can come to the rescue.</div>
<div>Just insert the following lines in your .bashrc or .cshrc file.</div>
<p>Bash:</p>
<pre>complete -W "`bin/dsconfig --help-all|grep '^[a-z].*'`" dsconfig</pre>
<p>csh:</p>
<pre>set DSC = `&lt;OpenDJPath&gt;/bin/dsconfig --help-all|grep '^[a-z].*'`
complete dsconfig "p/1/($DSC)/"</pre>
<p>And now type bin/dsconfig set[TAB] and the list of commands appears magically&#8230;</p>
<pre>$ dsconfig set-password-[TAB][TAB]
set-password-generator-prop       set-password-storage-scheme-prop
set-password-policy-prop          set-password-validator-prop
$ dsconfig set-password-</pre>
<br />Filed under: <a href='http://ludopoitou.wordpress.com/category/directory-services/'>Directory Services</a> Tagged: <a href='http://ludopoitou.wordpress.com/tag/directory-server/'>directory-server</a>, <a href='http://ludopoitou.wordpress.com/tag/java-2/'>java</a>, <a href='http://ludopoitou.wordpress.com/tag/ldap/'>ldap</a>, <a href='http://ludopoitou.wordpress.com/tag/opendj/'>opendj</a>, <a href='http://ludopoitou.wordpress.com/tag/opensource/'>opensource</a>, <a href='http://ludopoitou.wordpress.com/tag/tips/'>Tips</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ludopoitou.wordpress.com/860/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ludopoitou.wordpress.com/860/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ludopoitou.wordpress.com/860/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ludopoitou.wordpress.com/860/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ludopoitou.wordpress.com/860/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ludopoitou.wordpress.com/860/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ludopoitou.wordpress.com/860/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ludopoitou.wordpress.com/860/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ludopoitou.wordpress.com/860/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ludopoitou.wordpress.com/860/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ludopoitou.wordpress.com/860/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ludopoitou.wordpress.com/860/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ludopoitou.wordpress.com/860/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ludopoitou.wordpress.com/860/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=860&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ludopoitou.wordpress.com/2011/06/20/opendj-tip-auto-completion-of-dsconfig-command/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4c7d0f23ff8919a2720a7845ba1d4e5a?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=R" medium="image">
			<media:title type="html">Ludo</media:title>
		</media:content>
	</item>
		<item>
		<title>OpenDJ 2.4.3 is now available</title>
		<link>http://ludopoitou.wordpress.com/2011/06/17/opendj-2-4-3-is-now-available/</link>
		<comments>http://ludopoitou.wordpress.com/2011/06/17/opendj-2-4-3-is-now-available/#comments</comments>
		<pubDate>Fri, 17 Jun 2011 10:59:50 +0000</pubDate>
		<dc:creator>Ludo</dc:creator>
				<category><![CDATA[Directory Services]]></category>
		<category><![CDATA[directory]]></category>
		<category><![CDATA[directory-server]]></category>
		<category><![CDATA[documentation]]></category>
		<category><![CDATA[ForgeRock]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[ldap]]></category>
		<category><![CDATA[opendj]]></category>
		<category><![CDATA[opensource]]></category>
		<category><![CDATA[release]]></category>

		<guid isPermaLink="false">http://ludopoitou.wordpress.com/?p=862</guid>
		<description><![CDATA[Another revision of OpenDJ has just been released. OpenDJ 2.4.3 is an update release of the OpenDJ project and resolves several issues found around the External Change Log and the bundled database version. The version is built out of revision 7007 of the b2.4 branch of the code repository. The full details about the release [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=862&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://ludopoitou.files.wordpress.com/2010/12/opendj-300x100.png"><img class="size-thumbnail wp-image-667 alignleft" title="OpenDJ-300x100" src="http://ludopoitou.files.wordpress.com/2010/12/opendj-300x100.png?w=150&#038;h=50" alt="" width="150" height="50" /></a>Another revision of <a title="OpenDJ, the open source LDAP directory services in Java" href="http://opendj.org/">OpenDJ</a> has just been released. OpenDJ 2.4.3 is an update release of the OpenDJ project and resolves several issues found around the External Change Log and the bundled database version. The version is built out of revision 7007 of the <a title="See activity on the b2.4 branch of the OpenDJ code repository with FishEye" href="http://sources.forgerock.org/changelog/opendj/branches/b2.4">b2.4 branch</a> of the code repository.</p>
<p>The full details about the release have been posted in the <a title="OpenDJ 2.4.3 LDAP Directory Server Release Notes" href="https://wikis.forgerock.org/confluence/display/OPENDJ/OpenDJ+2.4.3+Release+Notes">OpenDJ 2.4.3 Release Notes</a>.</p>
<p>As usual, you can find every thing on the <a title="OpenDJ LDAP directory services Download page" href="http://www.forgerock.org/opendj.html">OpenDJ Downloads</a> page:</p>
<ul>
<li>The <a title="Install or Upgrade to OpenDJ 2.4.3 with the Java WebStart installer" href="http://www.forgerock.org/downloads/opendj/2.4.3/install/QuickSetup.jnlp">Java WebStart Installer</a></li>
<li>The <a title="OpenDJ 2.4.3 Zip package" href="http://www.forgerock.org/downloads/opendj/2.4.3/OpenDJ-2.4.3.zip">Zip package</a>.</li>
<li>The <a title="OpenDJ 2.4.3 SVR4 package" href="http://www.forgerock.org/downloads/opendj/2.4.3/opendj.zip">SVR4 package for Solaris users</a>.</li>
<li>The <a title="OpenDJ 2.4.3 DSML Gateway" href="http://www.forgerock.org/downloads/opendj/2.4.3/OpenDJ-2.4.3-DSML.war">DSML gateway</a> for those who want to provide a web service access to their LDAP directory server.</li>
</ul>
<p>In addition, some draft documentation for OpenDJ, and more specifically the <a title="OpenDJ LDAP directory services Administration Guide" href="http://opendj.forgerock.org/doc/admin-guide/OpenDJ-Admin-Guide.html">Administration Guide</a>, are now published (and regularly updated) on the <a title="Projet site for OpenDJ, the open source LDAP directory services in Java" href="http://opendj.forgerock.org/">OpenDJ project site</a>.</p>
<p>Feedback is important to us and you can participate on the <a title="#OpenDJ IRC channel, the chat about OpenDJ LDAP directory services in Java" href="irc://irc.freenode.net/#opendj">IRC channel</a>, the <a title="ForgeRock.org mailing list information, regarding OpenDJ LDAP directory server, OpenAM Web SSO project, OpenIDM ..." href="http://lists.forgerock.org/mailman/listinfo/">mailing lists</a> or <a title="Register to ForgeRock.Org community site" href="http://idp.forgerock.org/openam/UI/Login?service=register">join our community</a>.</p>
<p>Enjoy !</p>
<br />Filed under: <a href='http://ludopoitou.wordpress.com/category/directory-services/'>Directory Services</a> Tagged: <a href='http://ludopoitou.wordpress.com/tag/directory/'>directory</a>, <a href='http://ludopoitou.wordpress.com/tag/directory-server/'>directory-server</a>, <a href='http://ludopoitou.wordpress.com/tag/documentation/'>documentation</a>, <a href='http://ludopoitou.wordpress.com/tag/forgerock/'>ForgeRock</a>, <a href='http://ludopoitou.wordpress.com/tag/java-2/'>java</a>, <a href='http://ludopoitou.wordpress.com/tag/ldap/'>ldap</a>, <a href='http://ludopoitou.wordpress.com/tag/opendj/'>opendj</a>, <a href='http://ludopoitou.wordpress.com/tag/opensource/'>opensource</a>, <a href='http://ludopoitou.wordpress.com/tag/release/'>release</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ludopoitou.wordpress.com/862/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ludopoitou.wordpress.com/862/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ludopoitou.wordpress.com/862/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ludopoitou.wordpress.com/862/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ludopoitou.wordpress.com/862/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ludopoitou.wordpress.com/862/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ludopoitou.wordpress.com/862/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ludopoitou.wordpress.com/862/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ludopoitou.wordpress.com/862/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ludopoitou.wordpress.com/862/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ludopoitou.wordpress.com/862/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ludopoitou.wordpress.com/862/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ludopoitou.wordpress.com/862/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ludopoitou.wordpress.com/862/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ludopoitou.wordpress.com&amp;blog=9290851&amp;post=862&amp;subd=ludopoitou&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ludopoitou.wordpress.com/2011/06/17/opendj-2-4-3-is-now-available/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4c7d0f23ff8919a2720a7845ba1d4e5a?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=R" medium="image">
			<media:title type="html">Ludo</media:title>
		</media:content>

		<media:content url="http://ludopoitou.files.wordpress.com/2010/12/opendj-300x100.png?w=150" medium="image">
			<media:title type="html">OpenDJ-300x100</media:title>
		</media:content>
	</item>
	</channel>
</rss>
