<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-4226657536085668026</id><updated>2026-05-14T06:46:04.104-07:00</updated><title type='text'>Fedora Info</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://fedora.cattt.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default?redirect=false'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default?start-index=26&amp;max-results=25&amp;redirect=false'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>52274</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-679836041637882473</id><published>2026-05-14T06:46:04.104-07:00</published><updated>2026-05-14T06:46:04.104-07:00</updated><title type='text'>[Test-Announce] Fedora-IoT 45 RC 20260514.0 nightly compose nominated for testing</title><content type='html'>&lt;p&gt;Announcing the creation of a new nightly release validation test event
for Fedora-IoT 45 RC 20260514.0. Please help run some tests for this
nightly compose if you have time. For more information on nightly
release validation testing, see:
https://fedoraproject.org/wiki/QA:Release_validation_test_plan

Test coverage information for the current release can be seen at:
https://openqa.fedoraproject.org/testcase_stats/45iot

You can see all results, find testing instructions and image download
locations, and enter results on the Summary page:

https://fedoraproject.org/wiki/Test_Results:Fedora-IoT_45_RC_20260514.0_Summary

The individual test result pages are:

https://fedoraproject.org/wiki/Test_Results:Fedora-IoT_45_RC_20260514.0_General

Thank you for testing!
-- 
Mail generated by relvalconsumer: https://forge.fedoraproject.org/quality/relvalconsumer
-- 
_______________________________________________
test-announce mailing list -- test-announce@lists.fedoraproject.org
To unsubscribe send an email to test-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/test-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/679836041637882473/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/test-announce-fedora-iot-45-rc.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/679836041637882473'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/679836041637882473'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/test-announce-fedora-iot-45-rc.html' title='[Test-Announce] Fedora-IoT 45 RC 20260514.0 nightly compose nominated for testing'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-4776547814500551302</id><published>2026-05-13T14:17:50.922-07:00</published><updated>2026-05-13T14:17:50.922-07:00</updated><title type='text'>[389-users] Re: Cannot change nsslapd-db-max-locks</title><content type='html'>&lt;p&gt;
On 5/13/26 4:03 PM, Orion Poplawski via 389-users wrote:
&amp;gt; On 5/13/26 13:44, Mark Reynolds wrote:
&amp;gt;&amp;gt; On 5/13/26 3:32 PM, Orion Poplawski via 389-users wrote:
&amp;gt;&amp;gt;&amp;gt; So it seems that something is messed up with this particular host.
&amp;gt;&amp;gt; The &amp;quot;db locks&amp;quot; are stored under /dev/shm/slapd-INSTANCE/   Perhaps there is
&amp;gt;&amp;gt; not a lot of space allocated for /dev/shm on that host?
&amp;gt; This is what it had:
&amp;gt;
&amp;gt; Filesystem      Size  Used Avail Use% Mounted on
&amp;gt; tmpfs           1.5G  257M  1.3G  17% /dev/shm
&amp;gt;
&amp;gt; I bumped it a bit:
&amp;gt;
&amp;gt; Filesystem      Size  Used Avail Use% Mounted on
&amp;gt; tmpfs           1.8G  289M  1.5G  17% /dev/shm
&amp;gt;
&amp;gt; Now I&amp;#39;m starting to think that I&amp;#39;m looking at two different things as the
&amp;gt; nsslapd-db-max-locks is increasing after boot:
&amp;gt;
&amp;gt; nsslapd-db-current-locks: 52
&amp;gt; nsslapd-db-max-locks: 72
&amp;gt;
&amp;gt; nsslapd-db-current-locks: 99
&amp;gt; nsslapd-db-max-locks: 174
&amp;gt;
&amp;gt; nsslapd-db-current-locks: 101
&amp;gt; nsslapd-db-max-locks: 178
&amp;gt;
&amp;gt; So maybe the reason I see a large value on one machine is more indicative that
&amp;gt; something went haywire on it making it hit the configured maximum.
Not sure, I know that the monitor stats you are looking at come directly 
from libdb and not the core server - so it&amp;#39;s kind of a black box.  It 
would require debugging libdb to see why it&amp;#39;s behaving this way.
&amp;gt;
&amp;gt;
&amp;gt;
&amp;gt;
-- 
Identity Management Development Team

-- 
_______________________________________________
389-users mailing list -- 389-users@lists.fedoraproject.org
To unsubscribe send an email to 389-users-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/4776547814500551302/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-re-cannot-change-nsslapd-db_01225498551.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/4776547814500551302'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/4776547814500551302'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-re-cannot-change-nsslapd-db_01225498551.html' title='[389-users] Re: Cannot change nsslapd-db-max-locks'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-6992311287573956006</id><published>2026-05-13T13:40:51.920-07:00</published><updated>2026-05-13T13:40:51.920-07:00</updated><title type='text'>F44 election nominations now open</title><content type='html'>&lt;div dir=&quot;ltr&quot;&gt;
 &lt;div&gt;
  &lt;div&gt;
   The Fedora Project is now accepting nominations for all elected bodies until May 21, 2026. Candidates can self-nominate or be nominated by others with prior consent. Interviews are mandatory and must be completed by May 28, 2026. Elected members serve a two-release term.
  &lt;/div&gt;
  &lt;div&gt;
   &lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;
   &lt;a href=&quot;https://communityblog.fedoraproject.org/f44-election-nominations-now-open/&quot;&gt;https://communityblog.fedoraproject.org/f44-election-nominations-now-open/&lt;/a&gt;
  &lt;/div&gt;
 &lt;/div&gt;&lt;br&gt;&lt;span class=&quot;gmail_signature_prefix&quot;&gt;-- &lt;/span&gt;&lt;br&gt;
 &lt;div dir=&quot;ltr&quot; class=&quot;gmail_signature&quot; data-smartmail=&quot;gmail_signature&quot;&gt;
  &lt;div dir=&quot;ltr&quot;&gt;
   &lt;div&gt;&lt;/div&gt;
   &lt;div&gt;&lt;/div&gt;
   &lt;div&gt;
    &lt;b&gt;&lt;font size=&quot;4&quot;&gt;Justin Wheeler&lt;/font&gt;&lt;/b&gt; (&lt;span style=&quot;color:rgb(102,102,102)&quot;&gt;&lt;i&gt;he/him&lt;/i&gt;&lt;/span&gt;) || 📧 &lt;a href=&quot;mailto:jwheel@redhat.com&quot; target=&quot;_blank&quot;&gt;jwheel@redhat.com&lt;/a&gt; || 🔗 &lt;a href=&quot;https://jwheel.org&quot; target=&quot;_blank&quot;&gt;jwheel.org&lt;/a&gt;
   &lt;/div&gt;
   &lt;div&gt;&lt;/div&gt;
   &lt;div&gt;&lt;/div&gt;
   &lt;div&gt;
    &lt;i&gt;Formerly Justin W. Flory&lt;/i&gt;
   &lt;/div&gt;
   &lt;div&gt;
    &lt;b&gt;Fedora&lt;/b&gt; Community Architect&lt;br&gt;&lt;span style=&quot;font-family:monospace&quot;&gt;TZ=America/Atlanta&lt;/span&gt; (UTC-4) 🕗&lt;br&gt;
   &lt;/div&gt;
   &lt;div&gt;
    &lt;img src=&quot;https://fedoraproject.org/w/uploads/2/2d/Logo_fedoralogo.png&quot; width=&quot;96&quot; height=&quot;27&quot;&gt;
   &lt;/div&gt;
   &lt;div&gt;
    &lt;font size=&quot;1&quot;&gt;&lt;i&gt;Fedora is a &lt;a href=&quot;https://app.digitalpublicgoods.net/a/12003&quot; target=&quot;_blank&quot;&gt;registered Digital Public Good&lt;/a&gt;&lt;/i&gt;&lt;/font&gt;&lt;br&gt;
   &lt;/div&gt;
   &lt;div&gt;
    &lt;br&gt;&lt;font size=&quot;1&quot;&gt;While I may be sending this email outside my normal office hours, I have no expectation to receive a reply outside yours.&lt;/font&gt;&lt;br&gt;
   &lt;/div&gt;
  &lt;/div&gt;
 &lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;-- 
_______________________________________________
announce mailing list -- announce@lists.fedoraproject.org
To unsubscribe send an email to announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/announce@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/6992311287573956006/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/f44-election-nominations-now-open.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/6992311287573956006'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/6992311287573956006'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/f44-election-nominations-now-open.html' title='F44 election nominations now open'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-8501742979630271136</id><published>2026-05-13T13:03:42.743-07:00</published><updated>2026-05-13T13:03:42.743-07:00</updated><title type='text'>[389-users] Re: Cannot change nsslapd-db-max-locks</title><content type='html'>&lt;p&gt;On 5/13/26 13:44, Mark Reynolds wrote:
&amp;gt; 
&amp;gt; On 5/13/26 3:32 PM, Orion Poplawski via 389-users wrote:
&amp;gt;&amp;gt; So it seems that something is messed up with this particular host.
&amp;gt; The &amp;quot;db locks&amp;quot; are stored under /dev/shm/slapd-INSTANCE/   Perhaps there is
&amp;gt; not a lot of space allocated for /dev/shm on that host?

This is what it had:

Filesystem      Size  Used Avail Use% Mounted on
tmpfs           1.5G  257M  1.3G  17% /dev/shm

I bumped it a bit:

Filesystem      Size  Used Avail Use% Mounted on
tmpfs           1.8G  289M  1.5G  17% /dev/shm

Now I&amp;#39;m starting to think that I&amp;#39;m looking at two different things as the
nsslapd-db-max-locks is increasing after boot:

nsslapd-db-current-locks: 52
nsslapd-db-max-locks: 72

nsslapd-db-current-locks: 99
nsslapd-db-max-locks: 174

nsslapd-db-current-locks: 101
nsslapd-db-max-locks: 178

So maybe the reason I see a large value on one machine is more indicative that
something went haywire on it making it hit the configured maximum.



-- 
Orion Poplawski
he/him/his  - surely the least important thing about me
Manager of IT Systems                      720-772-5637
NWRA, Boulder Office                  FAX: 303-415-9702
3380 Mitchell Lane                       orion@nwra.com
Boulder, CO 80301                 https://www.nwra.com/
&lt;/p&gt;
&lt;p&gt;-- 
_______________________________________________
389-users mailing list -- 389-users@lists.fedoraproject.org
To unsubscribe send an email to 389-users-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/8501742979630271136/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-re-cannot-change-nsslapd-db_01839063887.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/8501742979630271136'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/8501742979630271136'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-re-cannot-change-nsslapd-db_01839063887.html' title='[389-users] Re: Cannot change nsslapd-db-max-locks'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-8081364984557452657</id><published>2026-05-13T12:44:32.228-07:00</published><updated>2026-05-13T12:44:32.228-07:00</updated><title type='text'>[389-users] Re: Cannot change nsslapd-db-max-locks</title><content type='html'>&lt;p&gt;
On 5/13/26 3:32 PM, Orion Poplawski via 389-users wrote:
&amp;gt; On 5/13/26 07:41, Viktor Ashirov wrote:
&amp;gt;&amp;gt; Hi,
&amp;gt;&amp;gt;
&amp;gt;&amp;gt;
&amp;gt;&amp;gt; On Tue, May 12, 2026 at 4:46 PM Orion Poplawski via 389-users &amp;lt;389-
&amp;gt;&amp;gt; users@lists.fedoraproject.org &amp;lt;mailto:389-users@lists.fedoraproject.org&amp;gt;&amp;gt; wrote:
&amp;gt;&amp;gt;
&amp;gt;&amp;gt;      On one of our EL9 IPA servers I&amp;#39;m unable to change nsslapd-db-max-locks
&amp;gt;&amp;gt;
&amp;gt;&amp;gt;   nsslapd-db-max-locks shows the peak concurrent lock count since the last
&amp;gt;&amp;gt; restart. It&amp;#39;s not meant to be changed.
&amp;gt;&amp;gt;
&amp;gt;&amp;gt;
&amp;gt;&amp;gt;      ldapsearch returns:
&amp;gt;&amp;gt;
&amp;gt;&amp;gt;      # database, monitor, ldbm database, plugins, config
&amp;gt;&amp;gt;      dn: cn=database,cn=monitor,cn=ldbm database,cn=plugins,cn=config
&amp;gt;&amp;gt;      nsslapd-db-current-locks: 96
&amp;gt;&amp;gt;      nsslapd-db-max-locks: 179
&amp;gt;&amp;gt;
&amp;gt;&amp;gt;      dsconf config get returns:
&amp;gt;&amp;gt;
&amp;gt;&amp;gt;      nsslapd-db-locks: 50018
&amp;gt;&amp;gt;
&amp;gt;&amp;gt;      I&amp;#39;ve restarted many times.  Changed the value a couple of times.  What&amp;#39;s up?
&amp;gt;&amp;gt;
&amp;gt;&amp;gt; How exactly do you change them?
&amp;gt;&amp;gt; This works for me:
&amp;gt;&amp;gt; dsconf &amp;lt;instance&amp;gt; backend config set --locks 100000
&amp;gt;&amp;gt;
&amp;gt;&amp;gt; After restart in the error logs:
&amp;gt;&amp;gt; [13/May/2026:08:11:01.395692873 -0400] - NOTICE - bdb_start - Resizing max db
&amp;gt;&amp;gt; lock count: 50000 -&amp;gt; 100000
&amp;gt; Yeah, I&amp;#39;m using dsconf backend config set to set it.  I do see that message:
&amp;gt;
&amp;gt; [11/May/2026:09:39:25.771331509 -0600] - NOTICE - bdb_start - Resizing max db
&amp;gt; lock count: 50000 -&amp;gt; 50018
&amp;gt;
&amp;gt; and dsconf config get shows:
&amp;gt;
&amp;gt; nsslapd-db-locks: 50018
&amp;gt;
&amp;gt; but the ldapsearch results stay small as above.
&amp;gt;
&amp;gt; Other machines the ldapsearch show the larger number:
&amp;gt;
&amp;gt; # database, monitor, ldbm database, plugins, config
&amp;gt; dn: cn=database,cn=monitor,cn=ldbm database,cn=plugins,cn=config
&amp;gt; nsslapd-db-current-locks: 114
&amp;gt; nsslapd-db-max-locks: 50018
&amp;gt;
&amp;gt; So it seems that something is messed up with this particular host.
The &amp;quot;db locks&amp;quot; are stored under /dev/shm/slapd-INSTANCE/   Perhaps there 
is not a lot of space allocated for /dev/shm on that host?
&amp;gt;
&amp;gt;
&amp;gt;
-- 
Identity Management Development Team

-- 
_______________________________________________
389-users mailing list -- 389-users@lists.fedoraproject.org
To unsubscribe send an email to 389-users-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/8081364984557452657/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-re-cannot-change-nsslapd-db_0168884588.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/8081364984557452657'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/8081364984557452657'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-re-cannot-change-nsslapd-db_0168884588.html' title='[389-users] Re: Cannot change nsslapd-db-max-locks'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-715835767964121483</id><published>2026-05-13T12:32:56.980-07:00</published><updated>2026-05-13T12:32:56.980-07:00</updated><title type='text'>[389-users] Re: Cannot change nsslapd-db-max-locks</title><content type='html'>&lt;p&gt;On 5/13/26 07:41, Viktor Ashirov wrote:
&amp;gt; Hi,
&amp;gt; 
&amp;gt; 
&amp;gt; On Tue, May 12, 2026 at 4:46 PM Orion Poplawski via 389-users &amp;lt;389-
&amp;gt; users@lists.fedoraproject.org &amp;lt;mailto:389-users@lists.fedoraproject.org&amp;gt;&amp;gt; wrote:
&amp;gt; 
&amp;gt;     On one of our EL9 IPA servers I&amp;#39;m unable to change nsslapd-db-max-locks
&amp;gt; 
&amp;gt;  nsslapd-db-max-locks shows the peak concurrent lock count since the last
&amp;gt; restart. It&amp;#39;s not meant to be changed.
&amp;gt; 
&amp;gt; 
&amp;gt;     ldapsearch returns:
&amp;gt; 
&amp;gt;     # database, monitor, ldbm database, plugins, config
&amp;gt;     dn: cn=database,cn=monitor,cn=ldbm database,cn=plugins,cn=config
&amp;gt;     nsslapd-db-current-locks: 96
&amp;gt;     nsslapd-db-max-locks: 179
&amp;gt; 
&amp;gt;     dsconf config get returns:
&amp;gt; 
&amp;gt;     nsslapd-db-locks: 50018
&amp;gt; 
&amp;gt;     I&amp;#39;ve restarted many times.  Changed the value a couple of times.  What&amp;#39;s up?
&amp;gt; 
&amp;gt; How exactly do you change them?
&amp;gt; This works for me:
&amp;gt; dsconf &amp;lt;instance&amp;gt; backend config set --locks 100000
&amp;gt; 
&amp;gt; After restart in the error logs:
&amp;gt; [13/May/2026:08:11:01.395692873 -0400] - NOTICE - bdb_start - Resizing max db
&amp;gt; lock count: 50000 -&amp;gt; 100000
Yeah, I&amp;#39;m using dsconf backend config set to set it.  I do see that message:

[11/May/2026:09:39:25.771331509 -0600] - NOTICE - bdb_start - Resizing max db
lock count: 50000 -&amp;gt; 50018

and dsconf config get shows:

nsslapd-db-locks: 50018

but the ldapsearch results stay small as above.

Other machines the ldapsearch show the larger number:

# database, monitor, ldbm database, plugins, config
dn: cn=database,cn=monitor,cn=ldbm database,cn=plugins,cn=config
nsslapd-db-current-locks: 114
nsslapd-db-max-locks: 50018

So it seems that something is messed up with this particular host.


-- 
Orion Poplawski
he/him/his  - surely the least important thing about me
Manager of IT Systems                      720-772-5637
NWRA, Boulder Office                  FAX: 303-415-9702
3380 Mitchell Lane                       orion@nwra.com
Boulder, CO 80301                 https://www.nwra.com/

&lt;/p&gt;
&lt;p&gt;-- 
_______________________________________________
389-users mailing list -- 389-users@lists.fedoraproject.org
To unsubscribe send an email to 389-users-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/715835767964121483/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-re-cannot-change-nsslapd-db_0609749053.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/715835767964121483'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/715835767964121483'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-re-cannot-change-nsslapd-db_0609749053.html' title='[389-users] Re: Cannot change nsslapd-db-max-locks'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-8158866301127602476</id><published>2026-05-13T06:42:01.654-07:00</published><updated>2026-05-13T06:42:01.654-07:00</updated><title type='text'>[389-users] Re: Cannot change nsslapd-db-max-locks</title><content type='html'>&lt;div dir=&quot;ltr&quot;&gt;
 &lt;div dir=&quot;ltr&quot;&gt;
  &lt;div dir=&quot;ltr&quot;&gt;
   Hi,
   &lt;div&gt;
    &lt;br&gt;
   &lt;/div&gt;
  &lt;/div&gt;&lt;br&gt;
  &lt;div class=&quot;gmail_quote&quot;&gt;
   &lt;div dir=&quot;ltr&quot; class=&quot;gmail_attr&quot;&gt;
    On Tue, May 12, 2026 at 4:46 PM Orion Poplawski via 389-users &amp;lt;&lt;a href=&quot;mailto:389-users@lists.fedoraproject.org&quot; target=&quot;_blank&quot;&gt;389-users@lists.fedoraproject.org&lt;/a&gt;&amp;gt; wrote:&lt;br&gt;
   &lt;/div&gt;
   &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex&quot;&gt;
    On one of our EL9 IPA servers I&#39;m unable to change nsslapd-db-max-locks&lt;br&gt;
   &lt;/blockquote&gt;
   &lt;div&gt;
    &amp;nbsp;nsslapd-db-max-locks shows the peak concurrent lock count since the last restart. It&#39;s not meant to be changed.
   &lt;/div&gt;
   &lt;div&gt;
    &lt;br&gt;
   &lt;/div&gt;
   &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex&quot;&gt;&lt;br&gt;
     ldapsearch returns:&lt;br&gt;&lt;br&gt;
     # database, monitor, ldbm database, plugins, config&lt;br&gt;
     dn: cn=database,cn=monitor,cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
     nsslapd-db-current-locks: 96&lt;br&gt;
     nsslapd-db-max-locks: 179&lt;br&gt;&lt;br&gt;
     dsconf config get returns:&lt;br&gt;&lt;br&gt;
     nsslapd-db-locks: 50018&lt;br&gt;&lt;br&gt;
     I&#39;ve restarted many times.&amp;nbsp; Changed the value a couple of times.&amp;nbsp; What&#39;s up?&lt;br&gt;
   &lt;/blockquote&gt;
   &lt;div&gt;
    How exactly do you change them?
   &lt;/div&gt;
   &lt;div&gt;
    This works for me:
   &lt;/div&gt;
   &lt;div&gt;
    dsconf &amp;lt;instance&amp;gt; backend config set --locks 100000
   &lt;/div&gt;
   &lt;div&gt;
    &lt;br&gt;
   &lt;/div&gt;
   &lt;div&gt;
    After restart in the error logs:&lt;br&gt;
    [13/May/2026:08:11:01.395692873 -0400] - NOTICE - bdb_start - Resizing max db lock count: 50000 -&amp;gt; 100000
   &lt;/div&gt;
   &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex&quot;&gt;&lt;br&gt;
     389-ds-base-2.7.0-12.el9_7.x86_64&lt;br&gt;&lt;br&gt;
     -- &lt;br&gt;
     Orion Poplawski&lt;br&gt;
     he/him/his&amp;nbsp; - surely the least important thing about me&lt;br&gt;
     Manager of IT Systems&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 720-772-5637&lt;br&gt;
     NWRA, Boulder Office&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FAX: 303-415-9702&lt;br&gt;
     3380 Mitchell Lane&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;mailto:orion@nwra.com&quot; target=&quot;_blank&quot;&gt;orion@nwra.com&lt;/a&gt;&lt;br&gt;
     Boulder, CO 80301&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;https://www.nwra.com/&quot; rel=&quot;noreferrer&quot; target=&quot;_blank&quot;&gt;https://www.nwra.com/&lt;/a&gt;&lt;br&gt;&lt;br&gt;
     -- &lt;br&gt;
     _______________________________________________&lt;br&gt;
     389-users mailing list -- &lt;a href=&quot;mailto:389-users@lists.fedoraproject.org&quot; target=&quot;_blank&quot;&gt;389-users@lists.fedoraproject.org&lt;/a&gt;&lt;br&gt;
     To unsubscribe send an email to &lt;a href=&quot;mailto:389-users-leave@lists.fedoraproject.org&quot; target=&quot;_blank&quot;&gt;389-users-leave@lists.fedoraproject.org&lt;/a&gt;&lt;br&gt;
     Fedora Code of Conduct: &lt;a href=&quot;https://docs.fedoraproject.org/en-US/project/code-of-conduct/&quot; rel=&quot;noreferrer&quot; target=&quot;_blank&quot;&gt;https://docs.fedoraproject.org/en-US/project/code-of-conduct/&lt;/a&gt;&lt;br&gt;
     List Guidelines: &lt;a href=&quot;https://fedoraproject.org/wiki/Mailing_list_guidelines&quot; rel=&quot;noreferrer&quot; target=&quot;_blank&quot;&gt;https://fedoraproject.org/wiki/Mailing_list_guidelines&lt;/a&gt;&lt;br&gt;
     List Archives: &lt;a href=&quot;https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org&quot; rel=&quot;noreferrer&quot; target=&quot;_blank&quot;&gt;https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org&lt;/a&gt;&lt;br&gt;
     Do not reply to spam, report it: &lt;a href=&quot;https://forge.fedoraproject.org/infra/tickets/issues/new&quot; rel=&quot;noreferrer&quot; target=&quot;_blank&quot;&gt;https://forge.fedoraproject.org/infra/tickets/issues/new&lt;/a&gt;&lt;br&gt;
   &lt;/blockquote&gt;
  &lt;/div&gt;
  &lt;div&gt;
   &lt;br clear=&quot;all&quot;&gt;
  &lt;/div&gt;
  &lt;div&gt;
   &lt;br&gt;
  &lt;/div&gt;&lt;span class=&quot;gmail_signature_prefix&quot;&gt;-- &lt;/span&gt;&lt;br&gt;
  &lt;div dir=&quot;ltr&quot; class=&quot;gmail_signature&quot;&gt;
   &lt;div dir=&quot;ltr&quot;&gt;
    Viktor
   &lt;/div&gt;
  &lt;/div&gt;
 &lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;-- 
_______________________________________________
389-users mailing list -- 389-users@lists.fedoraproject.org
To unsubscribe send an email to 389-users-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/8158866301127602476/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-re-cannot-change-nsslapd-db.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/8158866301127602476'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/8158866301127602476'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-re-cannot-change-nsslapd-db.html' title='[389-users] Re: Cannot change nsslapd-db-max-locks'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-3673160983948829846</id><published>2026-05-12T07:46:55.224-07:00</published><updated>2026-05-12T07:46:55.224-07:00</updated><title type='text'>[389-users] Cannot change nsslapd-db-max-locks</title><content type='html'>&lt;p&gt;On one of our EL9 IPA servers I&amp;#39;m unable to change nsslapd-db-max-locks

ldapsearch returns:

# database, monitor, ldbm database, plugins, config
dn: cn=database,cn=monitor,cn=ldbm database,cn=plugins,cn=config
nsslapd-db-current-locks: 96
nsslapd-db-max-locks: 179

dsconf config get returns:

nsslapd-db-locks: 50018

I&amp;#39;ve restarted many times.  Changed the value a couple of times.  What&amp;#39;s up?

389-ds-base-2.7.0-12.el9_7.x86_64

-- 
Orion Poplawski
he/him/his  - surely the least important thing about me
Manager of IT Systems                      720-772-5637
NWRA, Boulder Office                  FAX: 303-415-9702
3380 Mitchell Lane                       orion@nwra.com
Boulder, CO 80301                 https://www.nwra.com/

&lt;/p&gt;
&lt;p&gt;-- 
_______________________________________________
389-users mailing list -- 389-users@lists.fedoraproject.org
To unsubscribe send an email to 389-users-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/3673160983948829846/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-cannot-change-nsslapd-db-max.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/3673160983948829846'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/3673160983948829846'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-cannot-change-nsslapd-db-max.html' title='[389-users] Cannot change nsslapd-db-max-locks'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-8664316633998467357</id><published>2026-05-11T08:20:53.645-07:00</published><updated>2026-05-11T08:20:53.645-07:00</updated><title type='text'>[389-users] Re: [EXTERNAL\EXTERNE:] Re: version 3.1 : ERR - attrcrypt_ciphe</title><content type='html'>&lt;div id=&quot;divtagdefaultwrapper&quot; style=&quot;font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif;&quot; dir=&quot;ltr&quot;&gt;
 &lt;p&gt;I see I am missing the entries for&lt;/p&gt;
 &lt;div&gt;
  nsSSL3Ciphers in my exisitng cfg please&amp;nbsp; how to resolve this now ?
 &lt;/div&gt;
 &lt;div&gt;
  Initail the server was cfg withour TLS Certs in place for testing only next we put the Certs&amp;nbsp; but seeing&amp;nbsp; the errors&amp;nbsp; after ldap restart.&lt;br&gt;
 &lt;/div&gt;
 &lt;div&gt;
  &lt;br&gt;
 &lt;/div&gt;
 &lt;div&gt;
  &lt;br&gt;
 &lt;/div&gt;
 &lt;div&gt;
  dn: cn=encryption,cn=config&lt;br&gt;
   bjectClass: top&lt;br&gt;
   objectClass: nsEncryptionConfig&lt;br&gt;
   cn: encryption&lt;br&gt;
   nsSSLSessionTimeout: 0&lt;br&gt;
   nsSSLClientAuth: allowed&lt;br&gt;
   CACertExtractFile: /tmp/slapd-testldap/Self-Signed-CA.pem&lt;br&gt;
   modifiersName: cn=server,cn=plugins,cn=config&lt;br&gt;
   modifyTimestamp: 20260128211815Z&lt;br&gt;
   numSubordinates: 1&lt;br&gt;&lt;br&gt;
 &lt;/div&gt;&lt;br&gt;
 &lt;p&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;hr style=&quot;display:inline-block;width:98%&quot; tabindex=&quot;-1&quot;&gt;
&lt;div id=&quot;divRplyFwdMsg&quot; dir=&quot;ltr&quot;&gt;
 &lt;font face=&quot;Calibri, sans-serif&quot; style=&quot;font-size:11pt&quot; color=&quot;#000000&quot;&gt;&lt;b&gt;From:&lt;/b&gt; Ghiurea, Isabella&lt;br&gt;&lt;b&gt;Sent:&lt;/b&gt; Monday, May 11, 2026 8:12:13 AM&lt;br&gt;&lt;b&gt;To:&lt;/b&gt; Mark Reynolds; General discussion list for the 389 Directory server project.&lt;br&gt;&lt;b&gt;Subject:&lt;/b&gt; Re: [EXTERNAL\EXTERNE:] Re: [389-users] version 3.1 : ERR - attrcrypt_ciphe&lt;/font&gt;
 &lt;div&gt;
  &amp;nbsp;
 &lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
 &lt;style type=&quot;text/css&quot; style=&quot;display:none;&quot;&gt;&lt;!-- P {margin-top:0;margin-bottom:0;} --&gt;&lt;/style&gt;
 &lt;div id=&quot;divtagdefaultwrapper&quot; style=&quot;font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif;&quot; dir=&quot;ltr&quot;&gt;
  &lt;p&gt;This is my full log after restart and the OS and 389-DS version:: &lt;br&gt;&lt;/p&gt;
  &lt;p&gt;&lt;/p&gt;
  &lt;div&gt;
   &amp;nbsp;5.14.0-611.49.2.el9_7.x86_64 #1 SMP PREEMPT_DYNAMIC Thu Apr 30 09:05:08 EDT 2026 x86_64 GNU/Linux&lt;br&gt;
    389-ds-base-libs-3.1.3-7.el10_1.x86_64&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;
   &lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;
   &lt;div&gt;
    1/May/2026:08:08:06.489703415 -0700] - INFO - slapd_extract_cert - CA CERT NAME: Entrust OV TLS Issuing RSA CA 1 - SSL Corporation&lt;br&gt;
     [11/May/2026:08:08:06.491682937 -0700] - INFO - slapd_extract_cert - CA CERT NAME: Self-Signed-CA&lt;br&gt;
     [11/May/2026:08:08:06.492152194 -0700] - WARN - Security Initialization - SSL alert: Sending pin request to SVRCore. You may need to run systemd-tty-ask-password-agent to provide the password if pin.txt does not exist.&lt;br&gt;
     [11/May/2026:08:08:06.518750646 -0700] - INFO - slapd_extract_cert - SERVER CERT NAME: Server-Cert&lt;br&gt;
     [11/May/2026:08:08:06.553993372 -0700] - INFO - Security Initialization - SSL info: Enabling default cipher set.&lt;br&gt;
     [11/May/2026:08:08:06.554338296 -0700] - INFO - Security Initialization - SSL info: Configured NSS Ciphers&lt;br&gt;
     [11/May/2026:08:08:06.554580339 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_AES_128_GCM_SHA256: enabled&lt;br&gt;
     [11/May/2026:08:08:06.554917810 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_CHACHA20_POLY1305_SHA256: enabled&lt;br&gt;
     [11/May/2026:08:08:06.555192333 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_AES_256_GCM_SHA384: enabled&lt;br&gt;
     [11/May/2026:08:08:06.555360588 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256: enabled&lt;br&gt;
     [11/May/2026:08:08:06.555512802 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256: enabled&lt;br&gt;
     [11/May/2026:08:08:06.555660128 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256: enabled&lt;br&gt;
     [11/May/2026:08:08:06.555820939 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256: enabled&lt;br&gt;
     [11/May/2026:08:08:06.555971791 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384: enabled&lt;br&gt;
     [11/May/2026:08:08:06.556116070 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384: enabled&lt;br&gt;
     [11/May/2026:08:08:06.556262604 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA: enabled&lt;br&gt;
     [11/May/2026:08:08:06.556408537 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA: enabled&lt;br&gt;
     [11/May/2026:08:08:06.556551104 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA: enabled&lt;br&gt;
     [11/May/2026:08:08:06.556695374 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256: enabled&lt;br&gt;
     [11/May/2026:08:08:06.556846817 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256: enabled&lt;br&gt;
     [11/May/2026:08:08:06.556994573 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA: enabled&lt;br&gt;
     [11/May/2026:08:08:06.557139865 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_AES_128_GCM_SHA256: enabled&lt;br&gt;
     [11/May/2026:08:08:06.557287401 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256: enabled&lt;br&gt;
     [11/May/2026:08:08:06.557431420 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_AES_256_GCM_SHA384: enabled&lt;br&gt;
     [11/May/2026:08:08:06.557573065 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_AES_128_CBC_SHA: enabled&lt;br&gt;
     [11/May/2026:08:08:06.557726221 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_AES_128_CBC_SHA256: enabled&lt;br&gt;
     [11/May/2026:08:08:06.557886871 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_AES_256_CBC_SHA: enabled&lt;br&gt;
     [11/May/2026:08:08:06.558041370 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_AES_256_CBC_SHA256: enabled&lt;br&gt;
     [11/May/2026:08:08:06.563964174 -0700] - INFO - Security Initialization - slapd_ssl_init2 - Configured SSL version range: min: TLS1.2, max: TLS1.3&lt;br&gt;
     [11/May/2026:08:08:06.564487373 -0700] - INFO - Security Initialization - slapd_ssl_init2 - NSS adjusted SSL version range: min: TLS1.2, max: TLS1.3&lt;br&gt;
     [11/May/2026:08:08:06.564835995 -0700] - INFO - main - 389-Directory/3.1.3 B2026.051.0000 starting up&lt;br&gt;
     [11/May/2026:08:08:06.565071755 -0700] - INFO - main - Setting the maximum file descriptor limit to: 1048576&lt;br&gt;
     [11/May/2026:08:08:06.571042469 -0700] - INFO - PBKDF2-SHA1 - Number of iterations set to 100000 from default&lt;br&gt;
     [11/May/2026:08:08:06.571406910 -0700] - INFO - PBKDF2-SHA1 - Number of iterations set to 100000 from default&lt;br&gt;
     [11/May/2026:08:08:06.571637361 -0700] - INFO - PBKDF2-SHA256 - Number of iterations set to 100000 from default&lt;br&gt;
     [11/May/2026:08:08:06.571870307 -0700] - INFO - PBKDF2-SHA512 - Number of iterations set to 100000 from default&lt;br&gt;
     [11/May/2026:08:08:06.692829541 -0700] - INFO - PBKDF2_SHA256 - Based on CPU performance, chose 3000 rounds&lt;br&gt;
     [11/May/2026:08:08:06.697571186 -0700] - INFO - ldbm_instance_config_cachememsize_set - force a minimal value 512000&lt;br&gt;
     [11/May/2026:08:08:06.703451140 -0700] - INFO - dbmdb_make_env - MDB environment created with maxsize=6442450944.&lt;br&gt;
     [11/May/2026:08:08:06.703753165 -0700] - INFO - dbmdb_make_env - MDB environment created with max readers=126.&lt;br&gt;
     [11/May/2026:08:08:06.703942058 -0700] - INFO - dbmdb_make_env - MDB environment created with max database instances=512.&lt;br&gt;
     [11/May/2026:08:08:06.704770127 -0700] - ERR - attrcrypt_cipher_init - Failed to retrieve key for cipher AES (2)&lt;br&gt;
     [11/May/2026:08:08:06.704994095 -0700] - ERR - attrcrypt_cipher_init - Failed to retrieve key for cipher 3DES (2)&lt;br&gt;
     [11/May/2026:08:08:06.705155447 -0700] - ERR - attrcrypt_init - All prepared ciphers are not available. Please disable attribute encryption.&lt;br&gt;
     [11/May/2026:08:08:06.750376700 -0700] - INFO - connection_table_new - Number of connection sub-tables 1, each containing 63937 slots.&lt;br&gt;
     [11/May/2026:08:08:06.777423200 -0700] - INFO - slapd_daemon - slapd started.&amp;nbsp; Listening on All Interfaces port 389 for LDAP requests&lt;br&gt;
     [11/May/2026:08:08:06.777828878 -0700] - INFO - slapd_daemon - Listening on All Interfaces port 636 for LDAPS requests&lt;br&gt;&lt;br&gt;
   &lt;/div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;
   &lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;
   &lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;
   &lt;br&gt;&lt;br&gt;
  &lt;/div&gt;&lt;br&gt;
  &lt;p&gt;&lt;/p&gt;
 &lt;/div&gt;
 &lt;hr style=&quot;display:inline-block;width:98%&quot; tabindex=&quot;-1&quot;&gt;
 &lt;div id=&quot;divRplyFwdMsg&quot; dir=&quot;ltr&quot;&gt;
  &lt;font face=&quot;Calibri, sans-serif&quot; style=&quot;font-size:11pt&quot; color=&quot;#000000&quot;&gt;&lt;b&gt;From:&lt;/b&gt; Mark Reynolds &amp;lt;mareynol@redhat.com&amp;gt;&lt;br&gt;&lt;b&gt;Sent:&lt;/b&gt; Friday, May 8, 2026 2:14:23 PM&lt;br&gt;&lt;b&gt;To:&lt;/b&gt; General discussion list for the 389 Directory server project.&lt;br&gt;&lt;b&gt;Cc:&lt;/b&gt; Ghiurea, Isabella&lt;br&gt;&lt;b&gt;Subject:&lt;/b&gt; [EXTERNAL\EXTERNE:] Re: [389-users] version 3.1 : ERR - attrcrypt_ciphe&lt;/font&gt;
  &lt;div&gt;
   &amp;nbsp;
  &lt;/div&gt;
 &lt;/div&gt;
 &lt;div&gt;
  &lt;p style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: #000000;&quot;&gt;&lt;strong&gt;***Attention*** This email originated from outside of the NRC. ***Attention*** Ce courriel provient de l&#39;extérieur du CNRC.&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
  &lt;div&gt;
   &lt;p&gt;I haven&#39;t seen this particular error before.&amp;nbsp; Here is my error log at startup. Does your log look similar to this (besides the error)?&lt;/p&gt;
   &lt;p&gt;&lt;br&gt;&lt;/p&gt;
   &lt;p&gt;[05/May/2026:10:38:38.570345263 -0400] - INFO - slapd_extract_cert - CA CERT NAME: Self-Signed-CA&lt;br&gt;
     [05/May/2026:10:38:38.575013995 -0400] - WARN - Security Initialization - SSL alert: Sending pin request to SVRCore. You may need to run systemd-tty-ask-password-agent to provide the password if pin.txt does not exist.&lt;br&gt;
     [05/May/2026:10:38:38.596977165 -0400] - INFO - slapd_extract_cert - SERVER CERT NAME: Server-Cert&lt;br&gt;
     [05/May/2026:10:38:38.628070445 -0400] - INFO - Security Initialization - SSL info: Enabling default cipher set.&lt;br&gt;
     [05/May/2026:10:38:38.629070043 -0400] - INFO - Security Initialization - SSL info: Configured NSS Ciphers&lt;br&gt;
     [05/May/2026:10:38:38.629758473 -0400] - INFO - Security Initialization - SSL info: TLS_AES_128_GCM_SHA256: enabled&lt;br&gt;
     [05/May/2026:10:38:38.630223912 -0400] - INFO - Security Initialization - SSL info: TLS_CHACHA20_POLY1305_SHA256: enabled&lt;br&gt;
     [05/May/2026:10:38:38.630729097 -0400] - INFO - Security Initialization - SSL info: TLS_AES_256_GCM_SHA384: enabled&lt;br&gt;
     ...&lt;/p&gt;
   &lt;p&gt;...&lt;/p&gt;
   &lt;p&gt;[05/May/2026:10:38:38.646869597 -0400] - INFO - Security Initialization - slapd_ssl_init2 - Configured SSL version range: min: TLS1.2, max: TLS1.3&lt;br&gt;
     [05/May/2026:10:38:38.647319500 -0400] - INFO - Security Initialization - slapd_ssl_init2 - NSS adjusted SSL version range: min: TLS1.2, max: TLS1.3&lt;br&gt;
     [05/May/2026:10:38:38.647903706 -0400] - INFO - main - 389-Directory/3.2.0 DEVELOPER BUILD B0000.000.0000 starting up&lt;br&gt;
     ...&lt;/p&gt;
   &lt;p&gt;...&lt;br&gt;
     [05/May/2026:10:38:38.758475494 -0400] - INFO - dbmdb_make_env - MDB environment created with maxsize=21474836480 (20.0 GB)&lt;br&gt;
     [05/May/2026:10:38:38.759509913 -0400] - INFO - dbmdb_make_env - MDB environment created with max readers=126&lt;br&gt;
     [05/May/2026:10:38:38.760668867 -0400] - INFO - dbmdb_make_env - MDB environment created with max database instances=512&lt;br&gt;
     [05/May/2026:10:38:38.763059652 -0400] - NOTICE - attrcrypt_cipher_init - No symmetric key found for cipher AES in backend userroot, attempting to create one...&lt;br&gt;
     [05/May/2026:10:38:38.765674326 -0400] - INFO - attrcrypt_cipher_init - Key for cipher AES successfully generated and stored&lt;br&gt;
     [05/May/2026:10:38:38.766149695 -0400] - NOTICE - attrcrypt_cipher_init - No symmetric key found for cipher 3DES in backend userroot, attempting to create one...&lt;br&gt;
     [05/May/2026:10:38:38.768561634 -0400] - INFO - attrcrypt_cipher_init - Key for cipher 3DES successfully generated and stored&lt;/p&gt;
   &lt;p&gt;&lt;br&gt;&lt;/p&gt;
   &lt;p&gt;&lt;br&gt;&lt;/p&gt;
   &lt;p&gt;Are you running the server with security enabled?&amp;nbsp;&amp;nbsp;&lt;/p&gt;
   &lt;p&gt;&lt;br&gt;&lt;/p&gt;
   &lt;p&gt;Have you explicitly enabled/disable specific ciphers under cn=encryption,cn=config ?&lt;/p&gt;
   &lt;p&gt;&lt;br&gt;&lt;/p&gt;
   &lt;p&gt;dn: cn=encryption,cn=config&lt;br&gt;
     objectClass: top&lt;br&gt;
     objectClass: nsEncryptionConfig&lt;br&gt;
     cn: encryption&lt;br&gt;
     nsSSLSessionTimeout: 0&lt;br&gt;
     nsSSLClientAuth: allowed&lt;br&gt;
     CACertExtractFile: /tmp/slapd-localhost/Self-Signed-CA.pem&lt;br&gt;
     nsSSL3Ciphers:&amp;nbsp; +all,-TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384&lt;/p&gt;
   &lt;p&gt;&lt;br&gt;&lt;/p&gt;
   &lt;p&gt;&lt;br&gt;&lt;/p&gt;
   &lt;p&gt;Also what platform are you running this on?&amp;nbsp; What rpm version of &quot;nss&quot; is installed?&amp;nbsp; This could also be related to your system&#39;s crypto policy.&lt;/p&gt;
   &lt;p&gt;&lt;br&gt;&lt;/p&gt;
   &lt;p&gt;Thanks,&lt;/p&gt;
   &lt;p&gt;Mark&lt;/p&gt;
   &lt;p&gt;&lt;br&gt;&lt;/p&gt;
   &lt;p&gt;&lt;br&gt;&lt;/p&gt;
   &lt;div class=&quot;moz-cite-prefix&quot;&gt;
    On 5/8/26 4:11 PM, Ghiurea, Isabella via 389-users wrote:&lt;br&gt;
   &lt;/div&gt;
   &lt;blockquote type=&quot;cite&quot; cite=&quot;mid:9582397c732741668b300ac34d807bbb@nrc-cnrc.gc.ca&quot;&gt;
    &lt;style type=&quot;text/css&quot; style=&quot;display:none;&quot;&gt;P {margin-top:0;margin-bottom:0;}&lt;/style&gt;
    &lt;div id=&quot;divtagdefaultwrapper&quot; style=&quot;font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif;&quot; dir=&quot;ltr&quot;&gt;
     &lt;p&gt;&lt;br&gt;&lt;/p&gt;
     &lt;p&gt;&lt;br&gt;&lt;/p&gt;
     &lt;p&gt;After installing new Certs on version&amp;nbsp;&lt;span&gt;389-ds-base-libs-3.1.3-7.el10_1.x86_64&lt;/span&gt; ,&lt;/p&gt;
     &lt;p&gt;I am seeing the following&amp;nbsp; ERR in errolog when restarting the ldap.&lt;/p&gt;
     &lt;p&gt;&lt;br&gt;&lt;/p&gt;
     &lt;div&gt;
      [08/May/2026:12:47:19.286692556 -0700] - INFO - dbmdb_make_env - MDB environment created with max database instances=512.&lt;br&gt;
       [08/May/2026:12:47:19.287568735 -0700] - ERR - attrcrypt_cipher_init - Failed to retrieve key for cipher AES (2)&lt;br&gt;
       [08/May/2026:12:47:19.287866902 -0700] - ERR - attrcrypt_cipher_init - Failed to retrieve key for cipher 3DES (2)&lt;br&gt;
       [08/May/2026:12:47:19.288083818 -0700] - ERR - attrcrypt_init - All prepared ciphers are not available. Please disable attribute encryption.&lt;br&gt;&lt;br&gt;
     &lt;/div&gt; And here are my entries for encryption in dse.ldif :&lt;br&gt;
     &lt;div&gt;
      dn: cn=encrypted attribute keys,cn=userroot,cn=ldbm database,cn=plugins,cn=con&lt;br&gt;
       &amp;nbsp;fig&lt;br&gt;
       objectClass: top&lt;br&gt;
       objectClass: extensibleObject&lt;br&gt;
       cn: encrypted attribute keys&lt;br&gt;
       creatorsName: cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
       modifiersName: cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
       createTimestamp: 20260128,........&lt;br&gt;
       modifyTimestamp: 20260128........&lt;br&gt;
       numSubordinates: 2&lt;br&gt;&lt;br&gt;
       dn: cn=encrypted attributes,cn=userroot,cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
       objectClass: top &lt;br&gt;
       objectClass: extensibleObject&lt;br&gt;
       cn: encrypted attributes&lt;br&gt;
       creatorsName: cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
       modifiersName: cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
       createTimestamp: 202601282....&lt;br&gt;
       modifyTimestamp: 20260128....&lt;br&gt;
     &lt;/div&gt;
     &lt;div&gt;
      &lt;br&gt;
     &lt;/div&gt;
     &lt;div&gt;
      What else must be change to eliminate the errors.
     &lt;/div&gt;
     &lt;div&gt;
      thank you !&lt;br&gt;
     &lt;/div&gt;&lt;br&gt;
    &lt;/div&gt;&lt;br&gt;
    &lt;fieldset class=&quot;moz-mime-attachment-header&quot;&gt;&lt;/fieldset&gt;
   &lt;/blockquote&gt;
   &lt;pre class=&quot;moz-signature&quot; cols=&quot;72&quot;&gt;-- 
Identity Management Development Team&lt;/pre&gt;
  &lt;/div&gt;
 &lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;-- 
_______________________________________________
389-users mailing list -- 389-users@lists.fedoraproject.org
To unsubscribe send an email to 389-users-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/8664316633998467357/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-re-externalexterne-re-version_01814864600.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/8664316633998467357'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/8664316633998467357'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-re-externalexterne-re-version_01814864600.html' title='[389-users] Re: [EXTERNAL\EXTERNE:] Re: version 3.1 : ERR - attrcrypt_ciphe'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-4950769347067888201</id><published>2026-05-11T08:15:53.022-07:00</published><updated>2026-05-11T08:15:53.022-07:00</updated><title type='text'>[389-users] Re: [EXTERNAL\EXTERNE:] Re: version 3.1 : ERR - attrcrypt_ciphe</title><content type='html'>&lt;div id=&quot;divtagdefaultwrapper&quot; style=&quot;font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif;&quot; dir=&quot;ltr&quot;&gt;
 &lt;p&gt;This is my full log after restart and the OS and 389-DS version:: &lt;br&gt;&lt;/p&gt;
 &lt;p&gt;&lt;/p&gt;
 &lt;div&gt;
  &amp;nbsp;5.14.0-611.49.2.el9_7.x86_64 #1 SMP PREEMPT_DYNAMIC Thu Apr 30 09:05:08 EDT 2026 x86_64 GNU/Linux&lt;br&gt;
   389-ds-base-libs-3.1.3-7.el10_1.x86_64&lt;br&gt;
 &lt;/div&gt;
 &lt;div&gt;
  &lt;br&gt;
 &lt;/div&gt;
 &lt;div&gt;
  &lt;div&gt;
   1/May/2026:08:08:06.489703415 -0700] - INFO - slapd_extract_cert - CA CERT NAME: Entrust OV TLS Issuing RSA CA 1 - SSL Corporation&lt;br&gt;
    [11/May/2026:08:08:06.491682937 -0700] - INFO - slapd_extract_cert - CA CERT NAME: Self-Signed-CA&lt;br&gt;
    [11/May/2026:08:08:06.492152194 -0700] - WARN - Security Initialization - SSL alert: Sending pin request to SVRCore. You may need to run systemd-tty-ask-password-agent to provide the password if pin.txt does not exist.&lt;br&gt;
    [11/May/2026:08:08:06.518750646 -0700] - INFO - slapd_extract_cert - SERVER CERT NAME: Server-Cert&lt;br&gt;
    [11/May/2026:08:08:06.553993372 -0700] - INFO - Security Initialization - SSL info: Enabling default cipher set.&lt;br&gt;
    [11/May/2026:08:08:06.554338296 -0700] - INFO - Security Initialization - SSL info: Configured NSS Ciphers&lt;br&gt;
    [11/May/2026:08:08:06.554580339 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_AES_128_GCM_SHA256: enabled&lt;br&gt;
    [11/May/2026:08:08:06.554917810 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_CHACHA20_POLY1305_SHA256: enabled&lt;br&gt;
    [11/May/2026:08:08:06.555192333 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_AES_256_GCM_SHA384: enabled&lt;br&gt;
    [11/May/2026:08:08:06.555360588 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256: enabled&lt;br&gt;
    [11/May/2026:08:08:06.555512802 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256: enabled&lt;br&gt;
    [11/May/2026:08:08:06.555660128 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256: enabled&lt;br&gt;
    [11/May/2026:08:08:06.555820939 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256: enabled&lt;br&gt;
    [11/May/2026:08:08:06.555971791 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384: enabled&lt;br&gt;
    [11/May/2026:08:08:06.556116070 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384: enabled&lt;br&gt;
    [11/May/2026:08:08:06.556262604 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA: enabled&lt;br&gt;
    [11/May/2026:08:08:06.556408537 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA: enabled&lt;br&gt;
    [11/May/2026:08:08:06.556551104 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA: enabled&lt;br&gt;
    [11/May/2026:08:08:06.556695374 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256: enabled&lt;br&gt;
    [11/May/2026:08:08:06.556846817 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256: enabled&lt;br&gt;
    [11/May/2026:08:08:06.556994573 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA: enabled&lt;br&gt;
    [11/May/2026:08:08:06.557139865 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_AES_128_GCM_SHA256: enabled&lt;br&gt;
    [11/May/2026:08:08:06.557287401 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256: enabled&lt;br&gt;
    [11/May/2026:08:08:06.557431420 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_AES_256_GCM_SHA384: enabled&lt;br&gt;
    [11/May/2026:08:08:06.557573065 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_AES_128_CBC_SHA: enabled&lt;br&gt;
    [11/May/2026:08:08:06.557726221 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_AES_128_CBC_SHA256: enabled&lt;br&gt;
    [11/May/2026:08:08:06.557886871 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_AES_256_CBC_SHA: enabled&lt;br&gt;
    [11/May/2026:08:08:06.558041370 -0700] - INFO - Security Initialization - SSL info:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TLS_DHE_RSA_WITH_AES_256_CBC_SHA256: enabled&lt;br&gt;
    [11/May/2026:08:08:06.563964174 -0700] - INFO - Security Initialization - slapd_ssl_init2 - Configured SSL version range: min: TLS1.2, max: TLS1.3&lt;br&gt;
    [11/May/2026:08:08:06.564487373 -0700] - INFO - Security Initialization - slapd_ssl_init2 - NSS adjusted SSL version range: min: TLS1.2, max: TLS1.3&lt;br&gt;
    [11/May/2026:08:08:06.564835995 -0700] - INFO - main - 389-Directory/3.1.3 B2026.051.0000 starting up&lt;br&gt;
    [11/May/2026:08:08:06.565071755 -0700] - INFO - main - Setting the maximum file descriptor limit to: 1048576&lt;br&gt;
    [11/May/2026:08:08:06.571042469 -0700] - INFO - PBKDF2-SHA1 - Number of iterations set to 100000 from default&lt;br&gt;
    [11/May/2026:08:08:06.571406910 -0700] - INFO - PBKDF2-SHA1 - Number of iterations set to 100000 from default&lt;br&gt;
    [11/May/2026:08:08:06.571637361 -0700] - INFO - PBKDF2-SHA256 - Number of iterations set to 100000 from default&lt;br&gt;
    [11/May/2026:08:08:06.571870307 -0700] - INFO - PBKDF2-SHA512 - Number of iterations set to 100000 from default&lt;br&gt;
    [11/May/2026:08:08:06.692829541 -0700] - INFO - PBKDF2_SHA256 - Based on CPU performance, chose 3000 rounds&lt;br&gt;
    [11/May/2026:08:08:06.697571186 -0700] - INFO - ldbm_instance_config_cachememsize_set - force a minimal value 512000&lt;br&gt;
    [11/May/2026:08:08:06.703451140 -0700] - INFO - dbmdb_make_env - MDB environment created with maxsize=6442450944.&lt;br&gt;
    [11/May/2026:08:08:06.703753165 -0700] - INFO - dbmdb_make_env - MDB environment created with max readers=126.&lt;br&gt;
    [11/May/2026:08:08:06.703942058 -0700] - INFO - dbmdb_make_env - MDB environment created with max database instances=512.&lt;br&gt;
    [11/May/2026:08:08:06.704770127 -0700] - ERR - attrcrypt_cipher_init - Failed to retrieve key for cipher AES (2)&lt;br&gt;
    [11/May/2026:08:08:06.704994095 -0700] - ERR - attrcrypt_cipher_init - Failed to retrieve key for cipher 3DES (2)&lt;br&gt;
    [11/May/2026:08:08:06.705155447 -0700] - ERR - attrcrypt_init - All prepared ciphers are not available. Please disable attribute encryption.&lt;br&gt;
    [11/May/2026:08:08:06.750376700 -0700] - INFO - connection_table_new - Number of connection sub-tables 1, each containing 63937 slots.&lt;br&gt;
    [11/May/2026:08:08:06.777423200 -0700] - INFO - slapd_daemon - slapd started.&amp;nbsp; Listening on All Interfaces port 389 for LDAP requests&lt;br&gt;
    [11/May/2026:08:08:06.777828878 -0700] - INFO - slapd_daemon - Listening on All Interfaces port 636 for LDAPS requests&lt;br&gt;&lt;br&gt;
  &lt;/div&gt;&lt;br&gt;
 &lt;/div&gt;
 &lt;div&gt;
  &lt;br&gt;
 &lt;/div&gt;
 &lt;div&gt;
  &lt;br&gt;
 &lt;/div&gt;
 &lt;div&gt;
  &lt;br&gt;&lt;br&gt;
 &lt;/div&gt;&lt;br&gt;
 &lt;p&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;hr style=&quot;display:inline-block;width:98%&quot; tabindex=&quot;-1&quot;&gt;
&lt;div id=&quot;divRplyFwdMsg&quot; dir=&quot;ltr&quot;&gt;
 &lt;font face=&quot;Calibri, sans-serif&quot; style=&quot;font-size:11pt&quot; color=&quot;#000000&quot;&gt;&lt;b&gt;From:&lt;/b&gt; Mark Reynolds &amp;lt;mareynol@redhat.com&amp;gt;&lt;br&gt;&lt;b&gt;Sent:&lt;/b&gt; Friday, May 8, 2026 2:14:23 PM&lt;br&gt;&lt;b&gt;To:&lt;/b&gt; General discussion list for the 389 Directory server project.&lt;br&gt;&lt;b&gt;Cc:&lt;/b&gt; Ghiurea, Isabella&lt;br&gt;&lt;b&gt;Subject:&lt;/b&gt; [EXTERNAL\EXTERNE:] Re: [389-users] version 3.1 : ERR - attrcrypt_ciphe&lt;/font&gt;
 &lt;div&gt;
  &amp;nbsp;
 &lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
 &lt;p style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: #000000;&quot;&gt;&lt;strong&gt;***Attention*** This email originated from outside of the NRC. ***Attention*** Ce courriel provient de l&#39;extérieur du CNRC.&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
 &lt;div&gt;
  &lt;p&gt;I haven&#39;t seen this particular error before.&amp;nbsp; Here is my error log at startup. Does your log look similar to this (besides the error)?&lt;/p&gt;
  &lt;p&gt;&lt;br&gt;&lt;/p&gt;
  &lt;p&gt;[05/May/2026:10:38:38.570345263 -0400] - INFO - slapd_extract_cert - CA CERT NAME: Self-Signed-CA&lt;br&gt;
    [05/May/2026:10:38:38.575013995 -0400] - WARN - Security Initialization - SSL alert: Sending pin request to SVRCore. You may need to run systemd-tty-ask-password-agent to provide the password if pin.txt does not exist.&lt;br&gt;
    [05/May/2026:10:38:38.596977165 -0400] - INFO - slapd_extract_cert - SERVER CERT NAME: Server-Cert&lt;br&gt;
    [05/May/2026:10:38:38.628070445 -0400] - INFO - Security Initialization - SSL info: Enabling default cipher set.&lt;br&gt;
    [05/May/2026:10:38:38.629070043 -0400] - INFO - Security Initialization - SSL info: Configured NSS Ciphers&lt;br&gt;
    [05/May/2026:10:38:38.629758473 -0400] - INFO - Security Initialization - SSL info: TLS_AES_128_GCM_SHA256: enabled&lt;br&gt;
    [05/May/2026:10:38:38.630223912 -0400] - INFO - Security Initialization - SSL info: TLS_CHACHA20_POLY1305_SHA256: enabled&lt;br&gt;
    [05/May/2026:10:38:38.630729097 -0400] - INFO - Security Initialization - SSL info: TLS_AES_256_GCM_SHA384: enabled&lt;br&gt;
    ...&lt;/p&gt;
  &lt;p&gt;...&lt;/p&gt;
  &lt;p&gt;[05/May/2026:10:38:38.646869597 -0400] - INFO - Security Initialization - slapd_ssl_init2 - Configured SSL version range: min: TLS1.2, max: TLS1.3&lt;br&gt;
    [05/May/2026:10:38:38.647319500 -0400] - INFO - Security Initialization - slapd_ssl_init2 - NSS adjusted SSL version range: min: TLS1.2, max: TLS1.3&lt;br&gt;
    [05/May/2026:10:38:38.647903706 -0400] - INFO - main - 389-Directory/3.2.0 DEVELOPER BUILD B0000.000.0000 starting up&lt;br&gt;
    ...&lt;/p&gt;
  &lt;p&gt;...&lt;br&gt;
    [05/May/2026:10:38:38.758475494 -0400] - INFO - dbmdb_make_env - MDB environment created with maxsize=21474836480 (20.0 GB)&lt;br&gt;
    [05/May/2026:10:38:38.759509913 -0400] - INFO - dbmdb_make_env - MDB environment created with max readers=126&lt;br&gt;
    [05/May/2026:10:38:38.760668867 -0400] - INFO - dbmdb_make_env - MDB environment created with max database instances=512&lt;br&gt;
    [05/May/2026:10:38:38.763059652 -0400] - NOTICE - attrcrypt_cipher_init - No symmetric key found for cipher AES in backend userroot, attempting to create one...&lt;br&gt;
    [05/May/2026:10:38:38.765674326 -0400] - INFO - attrcrypt_cipher_init - Key for cipher AES successfully generated and stored&lt;br&gt;
    [05/May/2026:10:38:38.766149695 -0400] - NOTICE - attrcrypt_cipher_init - No symmetric key found for cipher 3DES in backend userroot, attempting to create one...&lt;br&gt;
    [05/May/2026:10:38:38.768561634 -0400] - INFO - attrcrypt_cipher_init - Key for cipher 3DES successfully generated and stored&lt;/p&gt;
  &lt;p&gt;&lt;br&gt;&lt;/p&gt;
  &lt;p&gt;&lt;br&gt;&lt;/p&gt;
  &lt;p&gt;Are you running the server with security enabled?&amp;nbsp;&amp;nbsp;&lt;/p&gt;
  &lt;p&gt;&lt;br&gt;&lt;/p&gt;
  &lt;p&gt;Have you explicitly enabled/disable specific ciphers under cn=encryption,cn=config ?&lt;/p&gt;
  &lt;p&gt;&lt;br&gt;&lt;/p&gt;
  &lt;p&gt;dn: cn=encryption,cn=config&lt;br&gt;
    objectClass: top&lt;br&gt;
    objectClass: nsEncryptionConfig&lt;br&gt;
    cn: encryption&lt;br&gt;
    nsSSLSessionTimeout: 0&lt;br&gt;
    nsSSLClientAuth: allowed&lt;br&gt;
    CACertExtractFile: /tmp/slapd-localhost/Self-Signed-CA.pem&lt;br&gt;
    nsSSL3Ciphers:&amp;nbsp; +all,-TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384&lt;/p&gt;
  &lt;p&gt;&lt;br&gt;&lt;/p&gt;
  &lt;p&gt;&lt;br&gt;&lt;/p&gt;
  &lt;p&gt;Also what platform are you running this on?&amp;nbsp; What rpm version of &quot;nss&quot; is installed?&amp;nbsp; This could also be related to your system&#39;s crypto policy.&lt;/p&gt;
  &lt;p&gt;&lt;br&gt;&lt;/p&gt;
  &lt;p&gt;Thanks,&lt;/p&gt;
  &lt;p&gt;Mark&lt;/p&gt;
  &lt;p&gt;&lt;br&gt;&lt;/p&gt;
  &lt;p&gt;&lt;br&gt;&lt;/p&gt;
  &lt;div class=&quot;moz-cite-prefix&quot;&gt;
   On 5/8/26 4:11 PM, Ghiurea, Isabella via 389-users wrote:&lt;br&gt;
  &lt;/div&gt;
  &lt;blockquote type=&quot;cite&quot; cite=&quot;mid:9582397c732741668b300ac34d807bbb@nrc-cnrc.gc.ca&quot;&gt;
   &lt;style type=&quot;text/css&quot; style=&quot;display:none;&quot;&gt;P {margin-top:0;margin-bottom:0;}&lt;/style&gt;
   &lt;div id=&quot;divtagdefaultwrapper&quot; style=&quot;font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif;&quot; dir=&quot;ltr&quot;&gt;
    &lt;p&gt;&lt;br&gt;&lt;/p&gt;
    &lt;p&gt;&lt;br&gt;&lt;/p&gt;
    &lt;p&gt;After installing new Certs on version&amp;nbsp;&lt;span&gt;389-ds-base-libs-3.1.3-7.el10_1.x86_64&lt;/span&gt; ,&lt;/p&gt;
    &lt;p&gt;I am seeing the following&amp;nbsp; ERR in errolog when restarting the ldap.&lt;/p&gt;
    &lt;p&gt;&lt;br&gt;&lt;/p&gt;
    &lt;div&gt;
     [08/May/2026:12:47:19.286692556 -0700] - INFO - dbmdb_make_env - MDB environment created with max database instances=512.&lt;br&gt;
      [08/May/2026:12:47:19.287568735 -0700] - ERR - attrcrypt_cipher_init - Failed to retrieve key for cipher AES (2)&lt;br&gt;
      [08/May/2026:12:47:19.287866902 -0700] - ERR - attrcrypt_cipher_init - Failed to retrieve key for cipher 3DES (2)&lt;br&gt;
      [08/May/2026:12:47:19.288083818 -0700] - ERR - attrcrypt_init - All prepared ciphers are not available. Please disable attribute encryption.&lt;br&gt;&lt;br&gt;
    &lt;/div&gt; And here are my entries for encryption in dse.ldif :&lt;br&gt;
    &lt;div&gt;
     dn: cn=encrypted attribute keys,cn=userroot,cn=ldbm database,cn=plugins,cn=con&lt;br&gt;
      &amp;nbsp;fig&lt;br&gt;
      objectClass: top&lt;br&gt;
      objectClass: extensibleObject&lt;br&gt;
      cn: encrypted attribute keys&lt;br&gt;
      creatorsName: cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
      modifiersName: cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
      createTimestamp: 20260128,........&lt;br&gt;
      modifyTimestamp: 20260128........&lt;br&gt;
      numSubordinates: 2&lt;br&gt;&lt;br&gt;
      dn: cn=encrypted attributes,cn=userroot,cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
      objectClass: top &lt;br&gt;
      objectClass: extensibleObject&lt;br&gt;
      cn: encrypted attributes&lt;br&gt;
      creatorsName: cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
      modifiersName: cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
      createTimestamp: 202601282....&lt;br&gt;
      modifyTimestamp: 20260128....&lt;br&gt;
    &lt;/div&gt;
    &lt;div&gt;
     &lt;br&gt;
    &lt;/div&gt;
    &lt;div&gt;
     What else must be change to eliminate the errors.
    &lt;/div&gt;
    &lt;div&gt;
     thank you !&lt;br&gt;
    &lt;/div&gt;&lt;br&gt;
   &lt;/div&gt;&lt;br&gt;
   &lt;fieldset class=&quot;moz-mime-attachment-header&quot;&gt;&lt;/fieldset&gt;
  &lt;/blockquote&gt;
  &lt;pre class=&quot;moz-signature&quot; cols=&quot;72&quot;&gt;-- 
Identity Management Development Team&lt;/pre&gt;
 &lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;-- 
_______________________________________________
389-users mailing list -- 389-users@lists.fedoraproject.org
To unsubscribe send an email to 389-users-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/4950769347067888201/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-re-externalexterne-re-version.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/4950769347067888201'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/4950769347067888201'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-re-externalexterne-re-version.html' title='[389-users] Re: [EXTERNAL\EXTERNE:] Re: version 3.1 : ERR - attrcrypt_ciphe'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-1726791086734194287</id><published>2026-05-10T23:45:49.544-07:00</published><updated>2026-05-10T23:45:49.544-07:00</updated><title type='text'>[Test-Announce] Fedora 45 Rawhide 20260511.n.0 nightly compose nominated for testing</title><content type='html'>&lt;p&gt;Announcing the creation of a new nightly release validation test event
for Fedora 45 Rawhide 20260511.n.0. Please help run some tests for this
nightly compose if you have time. For more information on nightly
release validation testing, see:
https://fedoraproject.org/wiki/QA:Release_validation_test_plan

Notable package version changes:
anaconda - 20260508.n.0: anaconda-45.1-1.fc45.src, 20260511.n.0: anaconda-45.2-1.fc45.src

Test coverage information for the current release can be seen at:
https://openqa.fedoraproject.org/testcase_stats/45

You can see all results, find testing instructions and image download
locations, and enter results on the Summary page:

https://fedoraproject.org/wiki/Test_Results:Fedora_45_Rawhide_20260511.n.0_Summary

The individual test result pages are:

https://fedoraproject.org/wiki/Test_Results:Fedora_45_Rawhide_20260511.n.0_Installation
https://fedoraproject.org/wiki/Test_Results:Fedora_45_Rawhide_20260511.n.0_Base
https://fedoraproject.org/wiki/Test_Results:Fedora_45_Rawhide_20260511.n.0_Server
https://fedoraproject.org/wiki/Test_Results:Fedora_45_Rawhide_20260511.n.0_Cloud
https://fedoraproject.org/wiki/Test_Results:Fedora_45_Rawhide_20260511.n.0_Desktop
https://fedoraproject.org/wiki/Test_Results:Fedora_45_Rawhide_20260511.n.0_Security_Lab

Thank you for testing!
-- 
Mail generated by relvalconsumer: https://forge.fedoraproject.org/quality/relvalconsumer
-- 
_______________________________________________
test-announce mailing list -- test-announce@lists.fedoraproject.org
To unsubscribe send an email to test-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/test-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/1726791086734194287/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/test-announce-fedora-45-rawhide_0302168259.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/1726791086734194287'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/1726791086734194287'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/test-announce-fedora-45-rawhide_0302168259.html' title='[Test-Announce] Fedora 45 Rawhide 20260511.n.0 nightly compose nominated for testing'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-553846309477273423</id><published>2026-05-10T23:31:27.655-07:00</published><updated>2026-05-10T23:31:27.655-07:00</updated><title type='text'>[Test-Announce] Test Days: Podman 6.0</title><content type='html'>&lt;p&gt;Greetings testers!

Please join us for upcoming Test Days [1] and help us improve Fedora&amp;#39;s
quality and stability.
Your participation helps us find and fix bugs before the next release,
ensuring a smoother experience for all users.

This time we&amp;#39;ll focus on testing the Podman.

Test period: 2026-05-11 to 2026-05-15
Test instructions: https://fedoraproject.org/wiki/Test_Day:2026-05-11_Podman_6.0


Thank you.

Petr Sklenar
Fedora Quality

-- 
_______________________________________________
test-announce mailing list -- test-announce@lists.fedoraproject.org
To unsubscribe send an email to test-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/test-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/553846309477273423/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/test-announce-test-days-podman-60.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/553846309477273423'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/553846309477273423'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/test-announce-test-days-podman-60.html' title='[Test-Announce] Test Days: Podman 6.0'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-4038485855753030050</id><published>2026-05-10T12:14:15.206-07:00</published><updated>2026-05-10T12:14:15.206-07:00</updated><title type='text'>Self-Introduction: Alberto García Fernández (Spanish)</title><content type='html'>&lt;div dir=&quot;ltr&quot;&gt;
 &lt;font face=&quot;monospace&quot;&gt;Name: Alberto García Fernández (Alberto)&lt;br&gt;
  Location: Gijón, Spain&lt;br&gt;
  &lt;div style=&quot;text-align:left&quot;&gt;
   Login: algarcia
  &lt;/div&gt;
  &lt;div style=&quot;text-align:left&quot;&gt;
   Language: Spanish
  &lt;/div&gt;
  &lt;div style=&quot;text-align:left&quot;&gt;
   &lt;br&gt;
  &lt;/div&gt;
  &lt;div style=&quot;text-align:left&quot;&gt;
   About me: I&#39;m a Linux end user (not a programmer or web developer) and free software enthusiast. I&#39;d like to contribute with Spanish L10N team as a form of gratitude for this software. I&#39;d like to practice my English too.
  &lt;/div&gt;
  &lt;div style=&quot;text-align:left&quot;&gt;
   &lt;br&gt;
  &lt;/div&gt;
  &lt;div style=&quot;text-align:left&quot;&gt;
   About Fedora Project and me: In the past, I used Fedora, but I haven&#39;t used Linux in many years. I use GNOME desktop, another project that I like a lot. Finally I&#39;d like to contribute with Fedora&#39;s marketing team in Spanish.
  &lt;/div&gt;
  &lt;div style=&quot;text-align:left&quot;&gt;
   &lt;br&gt;
  &lt;/div&gt;
  &lt;div style=&quot;text-align:left&quot;&gt;
   GPG KEYID and fingerprint: gpg --fingerprint 0379658C
  &lt;/div&gt;
  &lt;div style=&quot;text-align:left&quot;&gt;
   pub &amp;nbsp; ed25519 2026-05-08 [SC] [caduca: 2029-05-07]
  &lt;/div&gt;
  &lt;div style=&quot;text-align:left&quot;&gt;
   &amp;nbsp; &amp;nbsp; &amp;nbsp; 1DA6 61E2 BFF5 CEFC A71D &amp;nbsp;09A2 EEFE E8D6 0379 658C
  &lt;/div&gt;
  &lt;div style=&quot;text-align:left&quot;&gt;
   uid &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;[ &amp;nbsp;absoluta ] Alberto García Fernández &amp;lt;algarcia (at) &lt;a href=&quot;http://fedoraproject.org&quot;&gt;fedoraproject.org&lt;/a&gt;&amp;gt;
  &lt;/div&gt;
  &lt;div style=&quot;text-align:left&quot;&gt;
   sub &amp;nbsp; cv25519 2026-05-08 [E] [caduca: 2029-05-07]
  &lt;/div&gt;&lt;/font&gt;
&lt;/div&gt;
&lt;p&gt;-- 
_______________________________________________
trans mailing list -- trans@lists.fedoraproject.org
To unsubscribe send an email to trans-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/trans@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/4038485855753030050/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/self-introduction-alberto-garcia.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/4038485855753030050'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/4038485855753030050'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/self-introduction-alberto-garcia.html' title='Self-Introduction: Alberto García Fernández (Spanish)'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-11210534863992556</id><published>2026-05-10T05:04:06.790-07:00</published><updated>2026-05-10T05:04:06.790-07:00</updated><title type='text'>[Test-Announce] 2026-05-11 @ 15:00 UTC - Fedora Quality Meeting?</title><content type='html'>&lt;p&gt;# Fedora Quality Assurance Meeting
# Date: 2026-05-11
# Time: 15:00 UTC
(https://fedoraproject.org/wiki/Infrastructure/UTCHowto)
# Location:
https://matrix.to/#/#meeting:fedoraproject.org?web-instance[element.io]=chat.fedoraproject.org

Greetings testers! It&amp;#39;s meeting time again. I may not be around to run
it, though. If I don&amp;#39;t make it and anyone else wants to run it, please
go ahead, it&amp;#39;s easy! The SOP is at
https://fedoraproject.org/wiki/QA:SOP_Matrix_meeting_process . I didn&amp;#39;t
have anything particular to discuss, just a quick status check-in as
usual.

Here is a handy link which should show you the meeting time
in your local time:
https://www.timeanddate.com/worldclock/fixedtime.html?msg=Fedora+quality+meeting&amp;amp;iso=20260511T15&amp;amp;p1=1440&amp;amp;ah=1

If anyone has any other items for the agenda, please reply to this
email and suggest them! Thanks.

== Proposed Agenda Topics ==

1. Previous meeting follow-up
2. Fedora 44 and 45 status
3. Test Day / community event status
4. Open floor
-- 
Adam Williamson (he/him/his)
Fedora QA
Fedora Chat: @adamwill:fedora.im | Mastodon: @adamw@fosstodon.org
https://www.happyassassin.net

-- 
Adam Williamson (he/him/his)
Fedora QA
Fedora Chat: @adamwill:fedora.im | Mastodon: @adamw@fosstodon.org
https://www.happyassassin.net



-- 
_______________________________________________
test-announce mailing list -- test-announce@lists.fedoraproject.org
To unsubscribe send an email to test-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/test-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/11210534863992556/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/test-announce-2026-05-11-1500-utc.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/11210534863992556'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/11210534863992556'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/test-announce-2026-05-11-1500-utc.html' title='[Test-Announce] 2026-05-11 @ 15:00 UTC - Fedora Quality Meeting?'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-423004410335248969</id><published>2026-05-08T21:36:45.656-07:00</published><updated>2026-05-08T21:36:45.656-07:00</updated><title type='text'>[Test-Announce] Fedora 45 Rawhide 20260508.n.0 nightly compose nominated for testing</title><content type='html'>&lt;p&gt;Announcing the creation of a new nightly release validation test event
for Fedora 45 Rawhide 20260508.n.0. Please help run some tests for this
nightly compose if you have time. For more information on nightly
release validation testing, see:
https://fedoraproject.org/wiki/QA:Release_validation_test_plan

Notable package version changes:
anaconda - 20260505.n.0: anaconda-44.35-1.fc45.src, 20260508.n.0: anaconda-45.1-1.fc45.src
pungi - 20260505.n.0: pungi-4.10.1-6.fc45.src, 20260508.n.0: pungi-4.13.0-1.fc45.src

Test coverage information for the current release can be seen at:
https://openqa.fedoraproject.org/testcase_stats/45

You can see all results, find testing instructions and image download
locations, and enter results on the Summary page:

https://fedoraproject.org/wiki/Test_Results:Fedora_45_Rawhide_20260508.n.0_Summary

The individual test result pages are:

https://fedoraproject.org/wiki/Test_Results:Fedora_45_Rawhide_20260508.n.0_Installation
https://fedoraproject.org/wiki/Test_Results:Fedora_45_Rawhide_20260508.n.0_Base
https://fedoraproject.org/wiki/Test_Results:Fedora_45_Rawhide_20260508.n.0_Server
https://fedoraproject.org/wiki/Test_Results:Fedora_45_Rawhide_20260508.n.0_Cloud
https://fedoraproject.org/wiki/Test_Results:Fedora_45_Rawhide_20260508.n.0_Desktop
https://fedoraproject.org/wiki/Test_Results:Fedora_45_Rawhide_20260508.n.0_Security_Lab

Thank you for testing!
-- 
Mail generated by relvalconsumer: https://forge.fedoraproject.org/quality/relvalconsumer
-- 
_______________________________________________
test-announce mailing list -- test-announce@lists.fedoraproject.org
To unsubscribe send an email to test-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/test-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/423004410335248969/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/test-announce-fedora-45-rawhide_01476822183.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/423004410335248969'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/423004410335248969'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/test-announce-fedora-45-rawhide_01476822183.html' title='[Test-Announce] Fedora 45 Rawhide 20260508.n.0 nightly compose nominated for testing'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-3552128080848084532</id><published>2026-05-08T14:53:01.867-07:00</published><updated>2026-05-08T14:53:01.867-07:00</updated><title type='text'>[389-users] Re: version 3.1 : ERR - attrcrypt_ciphe</title><content type='html'>&lt;div dir=&quot;ltr&quot;&gt;
 Some more notes:
 &lt;div&gt;
  &lt;br&gt;
 &lt;/div&gt;
 &lt;div&gt;
  is it possible the LDAP SSL server certificate was changed or renewed?
  &lt;div&gt;
   &lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;
   I believe newer instances use AES for attribute encryption, not 3DES anymore
  &lt;/div&gt;
  &lt;div&gt;
   &lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;
   It seems the entries cn=AES and cn=3DES exist, so&amp;nbsp;the nsSymmetricKey attribute might be absent or empty ( like if an instance was created without a SSL server cert) , or there was some &quot;incomplete&quot; configuration at some point
  &lt;/div&gt;
 &lt;/div&gt;
 &lt;div&gt;
  &lt;br&gt;
 &lt;/div&gt;
 &lt;div&gt;
  No subordinates value for:
 &lt;/div&gt;
 &lt;div&gt;
  dn: cn=encrypted attributes,cn=userroot,cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
 &lt;/div&gt;
 &lt;div&gt;
  ?
 &lt;/div&gt;
 &lt;div&gt;
  &lt;br&gt;
 &lt;/div&gt;
 &lt;div&gt;
  if attribute encryption&amp;nbsp;is not used, an option may be to remove the 2 entries cn=AES and cn=3DES under
 &lt;/div&gt;
 &lt;div&gt;
  &amp;nbsp; dn: cn=encrypted attribute keys,cn=userroot,cn=ldbm database,cn=plugins,cn=config
 &lt;/div&gt;
 &lt;div&gt;
  and restart the LDAP service
 &lt;/div&gt;
 &lt;div&gt;
  if NSS is configured with a SSL server certificate, those 2 entries should then be created and initialized with a key
 &lt;/div&gt;
 &lt;div&gt;
  &lt;br&gt;
 &lt;/div&gt;
 &lt;div&gt;
  Thanks,
 &lt;/div&gt;
 &lt;div&gt;
  Marc S.
 &lt;/div&gt;
&lt;/div&gt;&lt;br&gt;
&lt;div class=&quot;gmail_quote gmail_quote_container&quot;&gt;
 &lt;div dir=&quot;ltr&quot; class=&quot;gmail_attr&quot;&gt;
  On Fri, May 8, 2026 at 9:14 PM Mark Reynolds via 389-users &amp;lt;&lt;a href=&quot;mailto:389-users@lists.fedoraproject.org&quot;&gt;389-users@lists.fedoraproject.org&lt;/a&gt;&amp;gt; wrote:&lt;br&gt;
 &lt;/div&gt;
 &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex&quot;&gt;
  &lt;u&gt;&lt;/u&gt;
  &lt;div&gt;
   &lt;p&gt;I haven&#39;t seen this particular error before.&amp;nbsp; Here is my error log at startup. Does your log look similar to this (besides the error)?&lt;/p&gt;
   &lt;p&gt;&lt;br&gt;&lt;/p&gt;
   &lt;p&gt;[05/May/2026:10:38:38.570345263 -0400] - INFO - slapd_extract_cert - CA CERT NAME: Self-Signed-CA&lt;br&gt;
     [05/May/2026:10:38:38.575013995 -0400] - WARN - Security Initialization - SSL alert: Sending pin request to SVRCore. You may need to run systemd-tty-ask-password-agent to provide the password if pin.txt does not exist.&lt;br&gt;
     [05/May/2026:10:38:38.596977165 -0400] - INFO - slapd_extract_cert - SERVER CERT NAME: Server-Cert&lt;br&gt;
     [05/May/2026:10:38:38.628070445 -0400] - INFO - Security Initialization - SSL info: Enabling default cipher set.&lt;br&gt;
     [05/May/2026:10:38:38.629070043 -0400] - INFO - Security Initialization - SSL info: Configured NSS Ciphers&lt;br&gt;
     [05/May/2026:10:38:38.629758473 -0400] - INFO - Security Initialization - SSL info: TLS_AES_128_GCM_SHA256: enabled&lt;br&gt;
     [05/May/2026:10:38:38.630223912 -0400] - INFO - Security Initialization - SSL info: TLS_CHACHA20_POLY1305_SHA256: enabled&lt;br&gt;
     [05/May/2026:10:38:38.630729097 -0400] - INFO - Security Initialization - SSL info: TLS_AES_256_GCM_SHA384: enabled&lt;br&gt;
     ...&lt;/p&gt;
   &lt;p&gt;...&lt;/p&gt;
   &lt;p&gt;[05/May/2026:10:38:38.646869597 -0400] - INFO - Security Initialization - slapd_ssl_init2 - Configured SSL version range: min: TLS1.2, max: TLS1.3&lt;br&gt;
     [05/May/2026:10:38:38.647319500 -0400] - INFO - Security Initialization - slapd_ssl_init2 - NSS adjusted SSL version range: min: TLS1.2, max: TLS1.3&lt;br&gt;
     [05/May/2026:10:38:38.647903706 -0400] - INFO - main - 389-Directory/3.2.0 DEVELOPER BUILD B0000.000.0000 starting up&lt;br&gt;
     ...&lt;/p&gt;
   &lt;p&gt;...&lt;br&gt;
     [05/May/2026:10:38:38.758475494 -0400] - INFO - dbmdb_make_env - MDB environment created with maxsize=21474836480 (20.0 GB)&lt;br&gt;
     [05/May/2026:10:38:38.759509913 -0400] - INFO - dbmdb_make_env - MDB environment created with max readers=126&lt;br&gt;
     [05/May/2026:10:38:38.760668867 -0400] - INFO - dbmdb_make_env - MDB environment created with max database instances=512&lt;br&gt;
     [05/May/2026:10:38:38.763059652 -0400] - NOTICE - attrcrypt_cipher_init - No symmetric key found for cipher AES in backend userroot, attempting to create one...&lt;br&gt;
     [05/May/2026:10:38:38.765674326 -0400] - INFO - attrcrypt_cipher_init - Key for cipher AES successfully generated and stored&lt;br&gt;
     [05/May/2026:10:38:38.766149695 -0400] - NOTICE - attrcrypt_cipher_init - No symmetric key found for cipher 3DES in backend userroot, attempting to create one...&lt;br&gt;
     [05/May/2026:10:38:38.768561634 -0400] - INFO - attrcrypt_cipher_init - Key for cipher 3DES successfully generated and stored&lt;/p&gt;
   &lt;p&gt;&lt;br&gt;&lt;/p&gt;
   &lt;p&gt;&lt;br&gt;&lt;/p&gt;
   &lt;p&gt;Are you running the server with security enabled?&amp;nbsp;&amp;nbsp;&lt;/p&gt;
   &lt;p&gt;&lt;br&gt;&lt;/p&gt;
   &lt;p&gt;Have you explicitly enabled/disable specific ciphers under cn=encryption,cn=config ?&lt;/p&gt;
   &lt;p&gt;&lt;br&gt;&lt;/p&gt;
   &lt;p&gt;dn: cn=encryption,cn=config&lt;br&gt;
     objectClass: top&lt;br&gt;
     objectClass: nsEncryptionConfig&lt;br&gt;
     cn: encryption&lt;br&gt;
     nsSSLSessionTimeout: 0&lt;br&gt;
     nsSSLClientAuth: allowed&lt;br&gt;
     CACertExtractFile: /tmp/slapd-localhost/Self-Signed-CA.pem&lt;br&gt;
     nsSSL3Ciphers:&amp;nbsp; +all,-TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384&lt;/p&gt;
   &lt;p&gt;&lt;br&gt;&lt;/p&gt;
   &lt;p&gt;&lt;br&gt;&lt;/p&gt;
   &lt;p&gt;Also what platform are you running this on?&amp;nbsp; What rpm version of &quot;nss&quot; is installed?&amp;nbsp; This could also be related to your system&#39;s crypto policy.&lt;/p&gt;
   &lt;p&gt;&lt;br&gt;&lt;/p&gt;
   &lt;p&gt;Thanks,&lt;/p&gt;
   &lt;p&gt;Mark&lt;/p&gt;
   &lt;p&gt;&lt;br&gt;&lt;/p&gt;
   &lt;p&gt;&lt;br&gt;&lt;/p&gt;
   &lt;div&gt;
    On 5/8/26 4:11 PM, Ghiurea, Isabella via 389-users wrote:&lt;br&gt;
   &lt;/div&gt;
   &lt;blockquote type=&quot;cite&quot;&gt;
    &lt;div id=&quot;m_5183667384703017693divtagdefaultwrapper&quot; style=&quot;font-size:12pt;color:rgb(0,0,0);font-family:Calibri,Helvetica,sans-serif&quot; dir=&quot;ltr&quot;&gt;
     &lt;p&gt;&lt;br&gt;&lt;/p&gt;
     &lt;p&gt;&lt;br&gt;&lt;/p&gt;
     &lt;p&gt;After installing new Certs on version&amp;nbsp;&lt;span&gt;389-ds-base-libs-3.1.3-7.el10_1.x86_64&lt;/span&gt; ,&lt;/p&gt;
     &lt;p&gt;I am seeing the following&amp;nbsp; ERR in errolog when restarting the ldap.&lt;/p&gt;
     &lt;p&gt;&lt;br&gt;&lt;/p&gt;
     &lt;div&gt;
      [08/May/2026:12:47:19.286692556 -0700] - INFO - dbmdb_make_env - MDB environment created with max database instances=512.&lt;br&gt;
       [08/May/2026:12:47:19.287568735 -0700] - ERR - attrcrypt_cipher_init - Failed to retrieve key for cipher AES (2)&lt;br&gt;
       [08/May/2026:12:47:19.287866902 -0700] - ERR - attrcrypt_cipher_init - Failed to retrieve key for cipher 3DES (2)&lt;br&gt;
       [08/May/2026:12:47:19.288083818 -0700] - ERR - attrcrypt_init - All prepared ciphers are not available. Please disable attribute encryption.&lt;br&gt;&lt;br&gt;
     &lt;/div&gt; And here are my entries for encryption in dse.ldif :&lt;br&gt;
     &lt;div&gt;
      dn: cn=encrypted attribute keys,cn=userroot,cn=ldbm database,cn=plugins,cn=con&lt;br&gt;
       &amp;nbsp;fig&lt;br&gt;
       objectClass: top&lt;br&gt;
       objectClass: extensibleObject&lt;br&gt;
       cn: encrypted attribute keys&lt;br&gt;
       creatorsName: cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
       modifiersName: cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
       createTimestamp: 20260128,........&lt;br&gt;
       modifyTimestamp: 20260128........&lt;br&gt;
       numSubordinates: 2&lt;br&gt;&lt;br&gt;
       dn: cn=encrypted attributes,cn=userroot,cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
       objectClass: top &lt;br&gt;
       objectClass: extensibleObject&lt;br&gt;
       cn: encrypted attributes&lt;br&gt;
       creatorsName: cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
       modifiersName: cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
       createTimestamp: 202601282....&lt;br&gt;
       modifyTimestamp: 20260128....&lt;br&gt;
     &lt;/div&gt;
     &lt;div&gt;
      &lt;br&gt;
     &lt;/div&gt;
     &lt;div&gt;
      What else must be change to eliminate the errors.
     &lt;/div&gt;
     &lt;div&gt;
      thank you !&lt;br&gt;
     &lt;/div&gt;&lt;br&gt;
    &lt;/div&gt;&lt;br&gt;
    &lt;fieldset&gt;&lt;/fieldset&gt;
   &lt;/blockquote&gt;
   &lt;pre cols=&quot;72&quot;&gt;-- 
Identity Management Development Team&lt;/pre&gt;
  &lt;/div&gt; -- &lt;br&gt;
   _______________________________________________&lt;br&gt;
   389-users mailing list -- &lt;a href=&quot;mailto:389-users@lists.fedoraproject.org&quot; target=&quot;_blank&quot;&gt;389-users@lists.fedoraproject.org&lt;/a&gt;&lt;br&gt;
   To unsubscribe send an email to &lt;a href=&quot;mailto:389-users-leave@lists.fedoraproject.org&quot; target=&quot;_blank&quot;&gt;389-users-leave@lists.fedoraproject.org&lt;/a&gt;&lt;br&gt;
   Fedora Code of Conduct: &lt;a href=&quot;https://docs.fedoraproject.org/en-US/project/code-of-conduct/&quot; rel=&quot;noreferrer&quot; target=&quot;_blank&quot;&gt;https://docs.fedoraproject.org/en-US/project/code-of-conduct/&lt;/a&gt;&lt;br&gt;
   List Guidelines: &lt;a href=&quot;https://fedoraproject.org/wiki/Mailing_list_guidelines&quot; rel=&quot;noreferrer&quot; target=&quot;_blank&quot;&gt;https://fedoraproject.org/wiki/Mailing_list_guidelines&lt;/a&gt;&lt;br&gt;
   List Archives: &lt;a href=&quot;https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org&quot; rel=&quot;noreferrer&quot; target=&quot;_blank&quot;&gt;https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org&lt;/a&gt;&lt;br&gt;
   Do not reply to spam, report it: &lt;a href=&quot;https://forge.fedoraproject.org/infra/tickets/issues/new&quot; rel=&quot;noreferrer&quot; target=&quot;_blank&quot;&gt;https://forge.fedoraproject.org/infra/tickets/issues/new&lt;/a&gt;&lt;br&gt;
 &lt;/blockquote&gt;
&lt;/div&gt;
&lt;p&gt;-- 
_______________________________________________
389-users mailing list -- 389-users@lists.fedoraproject.org
To unsubscribe send an email to 389-users-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/3552128080848084532/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-re-version-31-err_063948291.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/3552128080848084532'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/3552128080848084532'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-re-version-31-err_063948291.html' title='[389-users] Re: version 3.1 : ERR - attrcrypt_ciphe'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-6866256923222415441</id><published>2026-05-08T14:14:33.906-07:00</published><updated>2026-05-08T14:14:33.906-07:00</updated><title type='text'>[389-users] Re: version 3.1 : ERR - attrcrypt_ciphe</title><content type='html'>&lt;p&gt;I haven&#39;t seen this particular error before.&amp;nbsp; Here is my error log at startup. Does your log look similar to this (besides the error)?&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;[05/May/2026:10:38:38.570345263 -0400] - INFO - slapd_extract_cert - CA CERT NAME: Self-Signed-CA&lt;br&gt;
  [05/May/2026:10:38:38.575013995 -0400] - WARN - Security Initialization - SSL alert: Sending pin request to SVRCore. You may need to run systemd-tty-ask-password-agent to provide the password if pin.txt does not exist.&lt;br&gt;
  [05/May/2026:10:38:38.596977165 -0400] - INFO - slapd_extract_cert - SERVER CERT NAME: Server-Cert&lt;br&gt;
  [05/May/2026:10:38:38.628070445 -0400] - INFO - Security Initialization - SSL info: Enabling default cipher set.&lt;br&gt;
  [05/May/2026:10:38:38.629070043 -0400] - INFO - Security Initialization - SSL info: Configured NSS Ciphers&lt;br&gt;
  [05/May/2026:10:38:38.629758473 -0400] - INFO - Security Initialization - SSL info: TLS_AES_128_GCM_SHA256: enabled&lt;br&gt;
  [05/May/2026:10:38:38.630223912 -0400] - INFO - Security Initialization - SSL info: TLS_CHACHA20_POLY1305_SHA256: enabled&lt;br&gt;
  [05/May/2026:10:38:38.630729097 -0400] - INFO - Security Initialization - SSL info: TLS_AES_256_GCM_SHA384: enabled&lt;br&gt;
  ...&lt;/p&gt;
&lt;p&gt;...&lt;/p&gt;
&lt;p&gt;[05/May/2026:10:38:38.646869597 -0400] - INFO - Security Initialization - slapd_ssl_init2 - Configured SSL version range: min: TLS1.2, max: TLS1.3&lt;br&gt;
  [05/May/2026:10:38:38.647319500 -0400] - INFO - Security Initialization - slapd_ssl_init2 - NSS adjusted SSL version range: min: TLS1.2, max: TLS1.3&lt;br&gt;
  [05/May/2026:10:38:38.647903706 -0400] - INFO - main - 389-Directory/3.2.0 DEVELOPER BUILD B0000.000.0000 starting up&lt;br&gt;
  ...&lt;/p&gt;
&lt;p&gt;...&lt;br&gt;
  [05/May/2026:10:38:38.758475494 -0400] - INFO - dbmdb_make_env - MDB environment created with maxsize=21474836480 (20.0 GB)&lt;br&gt;
  [05/May/2026:10:38:38.759509913 -0400] - INFO - dbmdb_make_env - MDB environment created with max readers=126&lt;br&gt;
  [05/May/2026:10:38:38.760668867 -0400] - INFO - dbmdb_make_env - MDB environment created with max database instances=512&lt;br&gt;
  [05/May/2026:10:38:38.763059652 -0400] - NOTICE - attrcrypt_cipher_init - No symmetric key found for cipher AES in backend userroot, attempting to create one...&lt;br&gt;
  [05/May/2026:10:38:38.765674326 -0400] - INFO - attrcrypt_cipher_init - Key for cipher AES successfully generated and stored&lt;br&gt;
  [05/May/2026:10:38:38.766149695 -0400] - NOTICE - attrcrypt_cipher_init - No symmetric key found for cipher 3DES in backend userroot, attempting to create one...&lt;br&gt;
  [05/May/2026:10:38:38.768561634 -0400] - INFO - attrcrypt_cipher_init - Key for cipher 3DES successfully generated and stored&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Are you running the server with security enabled?&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Have you explicitly enabled/disable specific ciphers under cn=encryption,cn=config ?&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;dn: cn=encryption,cn=config&lt;br&gt;
  objectClass: top&lt;br&gt;
  objectClass: nsEncryptionConfig&lt;br&gt;
  cn: encryption&lt;br&gt;
  nsSSLSessionTimeout: 0&lt;br&gt;
  nsSSLClientAuth: allowed&lt;br&gt;
  CACertExtractFile: /tmp/slapd-localhost/Self-Signed-CA.pem&lt;br&gt;
  nsSSL3Ciphers:&amp;nbsp; +all,-TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Also what platform are you running this on?&amp;nbsp; What rpm version of &quot;nss&quot; is installed?&amp;nbsp; This could also be related to your system&#39;s crypto policy.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Mark&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;div class=&quot;moz-cite-prefix&quot;&gt;
 On 5/8/26 4:11 PM, Ghiurea, Isabella via 389-users wrote:&lt;br&gt;
&lt;/div&gt;
&lt;blockquote type=&quot;cite&quot; cite=&quot;mid:9582397c732741668b300ac34d807bbb@nrc-cnrc.gc.ca&quot;&gt;
 &lt;meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=UTF-8&quot;&gt;
 &lt;style type=&quot;text/css&quot; style=&quot;display:none;&quot;&gt;P {margin-top:0;margin-bottom:0;}&lt;/style&gt;
 &lt;div id=&quot;divtagdefaultwrapper&quot; style=&quot;font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif;&quot; dir=&quot;ltr&quot;&gt;
  &lt;p&gt;&lt;br&gt;&lt;/p&gt;
  &lt;p&gt;&lt;br&gt;&lt;/p&gt;
  &lt;p&gt;After installing new Certs on version&amp;nbsp;&lt;span&gt;389-ds-base-libs-3.1.3-7.el10_1.x86_64&lt;/span&gt; ,&lt;/p&gt;
  &lt;p&gt;I am seeing the following&amp;nbsp; ERR in errolog when restarting the ldap.&lt;/p&gt;
  &lt;p&gt;&lt;br&gt;&lt;/p&gt;
  &lt;div&gt;
   [08/May/2026:12:47:19.286692556 -0700] - INFO - dbmdb_make_env - MDB environment created with max database instances=512.&lt;br&gt;
    [08/May/2026:12:47:19.287568735 -0700] - ERR - attrcrypt_cipher_init - Failed to retrieve key for cipher AES (2)&lt;br&gt;
    [08/May/2026:12:47:19.287866902 -0700] - ERR - attrcrypt_cipher_init - Failed to retrieve key for cipher 3DES (2)&lt;br&gt;
    [08/May/2026:12:47:19.288083818 -0700] - ERR - attrcrypt_init - All prepared ciphers are not available. Please disable attribute encryption.&lt;br&gt;&lt;br&gt;
  &lt;/div&gt; And here are my entries for encryption in dse.ldif :&lt;br&gt;
  &lt;div&gt;
   dn: cn=encrypted attribute keys,cn=userroot,cn=ldbm database,cn=plugins,cn=con&lt;br&gt;
    &amp;nbsp;fig&lt;br&gt;
    objectClass: top&lt;br&gt;
    objectClass: extensibleObject&lt;br&gt;
    cn: encrypted attribute keys&lt;br&gt;
    creatorsName: cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
    modifiersName: cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
    createTimestamp: 20260128,........&lt;br&gt;
    modifyTimestamp: 20260128........&lt;br&gt;
    numSubordinates: 2&lt;br&gt;&lt;br&gt;
    dn: cn=encrypted attributes,cn=userroot,cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
    objectClass: top &lt;br&gt;
    objectClass: extensibleObject&lt;br&gt;
    cn: encrypted attributes&lt;br&gt;
    creatorsName: cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
    modifiersName: cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
    createTimestamp: 202601282....&lt;br&gt;
    modifyTimestamp: 20260128....&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;
   &lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;
   What else must be change to eliminate the errors.
  &lt;/div&gt;
  &lt;div&gt;
   thank you !&lt;br&gt;
  &lt;/div&gt;&lt;br&gt;
 &lt;/div&gt;&lt;br&gt;
 &lt;fieldset class=&quot;moz-mime-attachment-header&quot;&gt;&lt;/fieldset&gt;
&lt;/blockquote&gt;
&lt;pre class=&quot;moz-signature&quot; cols=&quot;72&quot;&gt;-- 
Identity Management Development Team&lt;/pre&gt;
&lt;p&gt;-- 
_______________________________________________
389-users mailing list -- 389-users@lists.fedoraproject.org
To unsubscribe send an email to 389-users-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/6866256923222415441/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-re-version-31-err.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/6866256923222415441'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/6866256923222415441'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-re-version-31-err.html' title='[389-users] Re: version 3.1 : ERR - attrcrypt_ciphe'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-4796443522017420236</id><published>2026-05-08T14:03:37.272-07:00</published><updated>2026-05-08T14:03:37.272-07:00</updated><title type='text'>[389-users] Re: Backend Database(s)</title><content type='html'>&lt;p&gt;Currently with LMDB all databases/indexes are all stored in that single 
file.  There is no way to change this.  I&amp;#39;m not sure if separating each 
database into a separate file would have any performance benefit, but it 
might be worth investigating.  Feel free to open a github issue for us 
look into it.

Mark

On 5/7/26 3:16 PM, Sean Weldon via 389-users wrote:
&amp;gt; Hello All,
&amp;gt; I&amp;#39;m in the process of building a 389 instance on RHEL that has 
&amp;gt; multiple backend suffixes (15+). When building a new 3.0.x instance, 
&amp;gt; 389 no longer creates a separate backend database (on file system), 
&amp;gt; and puts them all in one database (1 data.mdb file). Is there a way to 
&amp;gt; keep this separate per backend suffix (C=US, C=CA)? Documentation 
&amp;gt; makes it seem like --be-name would have this effect, but it doesn&amp;#39;t 
&amp;gt; (still 1 data.mdb file), at least not that I can get to work.
&amp;gt;
&amp;gt; Best
&amp;gt;
-- 
Identity Management Development Team

-- 
_______________________________________________
389-users mailing list -- 389-users@lists.fedoraproject.org
To unsubscribe send an email to 389-users-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/4796443522017420236/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-re-backend-databases.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/4796443522017420236'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/4796443522017420236'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-re-backend-databases.html' title='[389-users] Re: Backend Database(s)'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-5926571841355646320</id><published>2026-05-08T13:11:35.151-07:00</published><updated>2026-05-08T13:11:35.151-07:00</updated><title type='text'>[389-users] version 3.1 :  ERR - attrcrypt_ciphe</title><content type='html'>&lt;div id=&quot;divtagdefaultwrapper&quot; style=&quot;font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif;&quot; dir=&quot;ltr&quot;&gt;
 &lt;p&gt;&lt;br&gt;&lt;/p&gt;
 &lt;p&gt;&lt;br&gt;&lt;/p&gt;
 &lt;p&gt;After installing new Certs on version&amp;nbsp;&lt;span&gt;389-ds-base-libs-3.1.3-7.el10_1.x86_64&lt;/span&gt; ,&lt;/p&gt;
 &lt;p&gt;I am seeing the following&amp;nbsp; ERR in errolog when restarting the ldap.&lt;/p&gt;
 &lt;p&gt;&lt;br&gt;&lt;/p&gt;
 &lt;div&gt;
  [08/May/2026:12:47:19.286692556 -0700] - INFO - dbmdb_make_env - MDB environment created with max database instances=512.&lt;br&gt;
   [08/May/2026:12:47:19.287568735 -0700] - ERR - attrcrypt_cipher_init - Failed to retrieve key for cipher AES (2)&lt;br&gt;
   [08/May/2026:12:47:19.287866902 -0700] - ERR - attrcrypt_cipher_init - Failed to retrieve key for cipher 3DES (2)&lt;br&gt;
   [08/May/2026:12:47:19.288083818 -0700] - ERR - attrcrypt_init - All prepared ciphers are not available. Please disable attribute encryption.&lt;br&gt;&lt;br&gt;
 &lt;/div&gt; And here are my entries for encryption in dse.ldif :&lt;br&gt;
 &lt;p&gt;&lt;/p&gt;
 &lt;p&gt;&lt;/p&gt;
 &lt;div&gt;
  dn: cn=encrypted attribute keys,cn=userroot,cn=ldbm database,cn=plugins,cn=con&lt;br&gt;
   &amp;nbsp;fig&lt;br&gt;
   objectClass: top&lt;br&gt;
   objectClass: extensibleObject&lt;br&gt;
   cn: encrypted attribute keys&lt;br&gt;
   creatorsName: cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
   modifiersName: cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
   createTimestamp: 20260128,........&lt;br&gt;
   modifyTimestamp: 20260128........&lt;br&gt;
   numSubordinates: 2&lt;br&gt;&lt;br&gt;
   dn: cn=encrypted attributes,cn=userroot,cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
   objectClass: top &lt;br&gt;
   objectClass: extensibleObject&lt;br&gt;
   cn: encrypted attributes&lt;br&gt;
   creatorsName: cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
   modifiersName: cn=ldbm database,cn=plugins,cn=config&lt;br&gt;
   createTimestamp: 202601282....&lt;br&gt;
   modifyTimestamp: 20260128....&lt;br&gt;
 &lt;/div&gt;
 &lt;div&gt;
  &lt;br&gt;
 &lt;/div&gt;
 &lt;div&gt;
  What else must be change to eliminate the errors.
 &lt;/div&gt;
 &lt;div&gt;
  thank you !&lt;br&gt;
 &lt;/div&gt;&lt;br&gt;
 &lt;p&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;-- 
_______________________________________________
389-users mailing list -- 389-users@lists.fedoraproject.org
To unsubscribe send an email to 389-users-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/5926571841355646320/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-version-31-err-attrcryptciphe.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/5926571841355646320'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/5926571841355646320'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-version-31-err-attrcryptciphe.html' title='[389-users] version 3.1 :  ERR - attrcrypt_ciphe'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-5984298385406907358</id><published>2026-05-07T12:17:13.989-07:00</published><updated>2026-05-07T12:17:13.989-07:00</updated><title type='text'>[389-users] Backend Database(s)</title><content type='html'>&lt;div dir=&quot;ltr&quot;&gt;
 Hello All,
 &lt;div&gt;
  I&#39;m in the process of building a 389 instance on RHEL that has multiple backend suffixes (15+). When building a new 3.0.x instance, 389 no longer creates a separate backend database (on file system), and puts them all in one database (1 data.mdb file). Is there a way to keep this separate per backend suffix (C=US, C=CA)? Documentation makes it seem like --be-name would have this effect, but it doesn&#39;t (still 1 data.mdb file), at least not that I can get to work.
 &lt;/div&gt;
 &lt;div&gt;
  &lt;br&gt;
 &lt;/div&gt;
 &lt;div&gt;
  Best
 &lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;-- 
_______________________________________________
389-users mailing list -- 389-users@lists.fedoraproject.org
To unsubscribe send an email to 389-users-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/5984298385406907358/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-backend-databases.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/5984298385406907358'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/5984298385406907358'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/389-users-backend-databases.html' title='[389-users] Backend Database(s)'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-6064682387332963890</id><published>2026-05-07T07:48:43.525-07:00</published><updated>2026-05-07T07:48:43.525-07:00</updated><title type='text'>Re: Fedora Linux 42 will be End of Life next week</title><content type='html'>&lt;p&gt;Hi all,

Please accept my apologies for the confusion caused by my previous
announcement. The End of Life (EOL) date originally provided for
Fedora Linux 42 was incorrect, as the message was pre-scheduled with
our release calendar as source, and amidst things, I don&amp;#39;t think the
schedule was updated with the most recent information.

The correct EOL date is five weeks following the release of the latest
version. Given that Fedora Linux 44 was officially released on April
28th, 2026, the actual EOL for Fedora Linux 42 will be May 27, 2026.
We are currently working to ensure this date is updated across all
relevant systems, including Bodhi and Bugzilla.

Thank you for catching this discrepancy, and I apologize for the oversight.

Regards,
Samyak Jain
Fedora Release Engineering

On Wed, May 6, 2026 at 8:10 PM Samyak Jain &amp;lt;samyak.jn11@gmail.com&amp;gt; wrote:
&amp;gt;
&amp;gt; Hello all,
&amp;gt;
&amp;gt; Fedora Linux 42 will go end-of-life for updates and support on
&amp;gt; 2026-05-13.
&amp;gt; No more updates of any kind, including security updates or security
&amp;gt; announcements, will be available for Fedora Linux 42 after this
&amp;gt; date. No pending updates for Fedora Linux 42 will be pushed to stable.
&amp;gt;
&amp;gt; Fedora Linux 43 will continue to receive updates until approximately
&amp;gt; one month after the release of Fedora Linux 45. The maintenance
&amp;gt; schedule of Fedora Linux releases is documented here[1]. The docs also
&amp;gt; contain instructions[2] on how to upgrade from a previous release of
&amp;gt; Fedora Linux to a version receiving updates.
&amp;gt;
&amp;gt; Regards,
&amp;gt; Samyak Jain
&amp;gt; Fedora Release Engineering
&amp;gt;
&amp;gt; [1] https://docs.fedoraproject.org/en-US/releases/lifecycle/#_maintenance_schedule
&amp;gt; [2] https://docs.fedoraproject.org/en-US/quick-docs/upgrading-fedora-new-release/
-- 
_______________________________________________
announce mailing list -- announce@lists.fedoraproject.org
To unsubscribe send an email to announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/announce@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/6064682387332963890/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/re-fedora-linux-42-will-be-end-of-life.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/6064682387332963890'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/6064682387332963890'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/re-fedora-linux-42-will-be-end-of-life.html' title='Re: Fedora Linux 42 will be End of Life next week'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-7902274109893883967</id><published>2026-05-07T01:25:28.009-07:00</published><updated>2026-05-07T01:25:28.009-07:00</updated><title type='text'>[Test-Announce] Re: Fedora Linux 42 will be End of Life next week</title><content type='html'>&lt;p&gt;Hi all,

Please accept my apologies for the confusion caused by my previous
announcement. The End of Life (EOL) date originally provided for
Fedora Linux 42 was incorrect, as the message was pre-scheduled with
our release calendar as source, and amidst things, I don&amp;#39;t think the
schedule was updated with the most recent information.

The correct EOL date is five weeks following the release of the latest
version. Given that Fedora Linux 44 was officially released on April
28th, 2026, the actual EOL for Fedora Linux 42 will be May 27, 2026.
We are currently working to ensure this date is updated across all
relevant systems, including Bodhi and Bugzilla.

Thank you for catching this discrepancy, and I apologize for the oversight.

Regards,
Samyak Jain
Fedora Release Engineering

On Wed, May 6, 2026 at 8:10 PM Samyak Jain &amp;lt;samyak.jn11@gmail.com&amp;gt; wrote:
&amp;gt;
&amp;gt; Hello all,
&amp;gt;
&amp;gt; Fedora Linux 42 will go end-of-life for updates and support on
&amp;gt; 2026-05-13.
&amp;gt; No more updates of any kind, including security updates or security
&amp;gt; announcements, will be available for Fedora Linux 42 after this
&amp;gt; date. No pending updates for Fedora Linux 42 will be pushed to stable.
&amp;gt;
&amp;gt; Fedora Linux 43 will continue to receive updates until approximately
&amp;gt; one month after the release of Fedora Linux 45. The maintenance
&amp;gt; schedule of Fedora Linux releases is documented here[1]. The docs also
&amp;gt; contain instructions[2] on how to upgrade from a previous release of
&amp;gt; Fedora Linux to a version receiving updates.
&amp;gt;
&amp;gt; Regards,
&amp;gt; Samyak Jain
&amp;gt; Fedora Release Engineering
&amp;gt;
&amp;gt; [1] https://docs.fedoraproject.org/en-US/releases/lifecycle/#_maintenance_schedule
&amp;gt; [2] https://docs.fedoraproject.org/en-US/quick-docs/upgrading-fedora-new-release/
-- 
_______________________________________________
test-announce mailing list -- test-announce@lists.fedoraproject.org
To unsubscribe send an email to test-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/test-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/7902274109893883967/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/test-announce-re-fedora-linux-42-will.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/7902274109893883967'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/7902274109893883967'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/test-announce-re-fedora-linux-42-will.html' title='[Test-Announce] Re: Fedora Linux 42 will be End of Life next week'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-255617470628744816</id><published>2026-05-06T12:02:02.583-07:00</published><updated>2026-05-06T12:02:02.583-07:00</updated><title type='text'>[Bug 2336875] kbd lacks workable Georgian console layout and font, contains unworkable xkb-translated layout</title><content type='html'>&lt;p&gt;https://bugzilla.redhat.com/show_bug.cgi?id=2336875

Adam Williamson &amp;lt;awilliam@redhat.com&amp;gt; changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
         Resolution|---                         |ERRATA
             Status|POST                        |CLOSED
        Last Closed|                            |2026-05-06 19:01:29



--- Comment #57 from Adam Williamson &amp;lt;awilliam@redhat.com&amp;gt; ---
It looks like all of this worked, we just forgot to close the ticket. I checked
current Rawhide and Georgian install works great out of the box, the correct
config is used, the font is correct, you can switch layout with shift+ctrl and
input Georgian characters and they look fine (AFAICT). Thanks again for all the
help on this, Temuri.


-- 
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2336875

Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&amp;amp;format=report-spam&amp;amp;short_desc=Report%20of%20Bug%202336875%23c57

-- 
_______________________________________________
trans mailing list -- trans@lists.fedoraproject.org
To unsubscribe send an email to trans-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/trans@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/255617470628744816/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/bug-2336875-kbd-lacks-workable-georgian.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/255617470628744816'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/255617470628744816'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/bug-2336875-kbd-lacks-workable-georgian.html' title='[Bug 2336875] kbd lacks workable Georgian console layout and font, contains unworkable xkb-translated layout'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-4219189883407905671</id><published>2026-05-06T09:14:54.580-07:00</published><updated>2026-05-06T09:14:54.580-07:00</updated><title type='text'>Fedora Linux 42 will be End of Life next week</title><content type='html'>&lt;p&gt;Hello all,

Fedora Linux 42 will go end-of-life for updates and support on
2026-05-13.
No more updates of any kind, including security updates or security
announcements, will be available for Fedora Linux 42 after this
date. No pending updates for Fedora Linux 42 will be pushed to stable.

Fedora Linux 43 will continue to receive updates until approximately
one month after the release of Fedora Linux 45. The maintenance
schedule of Fedora Linux releases is documented here[1]. The docs also
contain instructions[2] on how to upgrade from a previous release of
Fedora Linux to a version receiving updates.

Regards,
Samyak Jain
Fedora Release Engineering

[1] https://docs.fedoraproject.org/en-US/releases/lifecycle/#_maintenance_schedule
[2] https://docs.fedoraproject.org/en-US/quick-docs/upgrading-fedora-new-release/
-- 
_______________________________________________
announce mailing list -- announce@lists.fedoraproject.org
To unsubscribe send an email to announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/announce@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/4219189883407905671/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/fedora-linux-42-will-be-end-of-life.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/4219189883407905671'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/4219189883407905671'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/fedora-linux-42-will-be-end-of-life.html' title='Fedora Linux 42 will be End of Life next week'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4226657536085668026.post-154290849357325027</id><published>2026-05-06T08:10:56.122-07:00</published><updated>2026-05-06T08:10:56.122-07:00</updated><title type='text'>[Test-Announce] Fedora Linux 42 will be End of Life next week</title><content type='html'>&lt;p&gt;Hello all,

Fedora Linux 42 will go end-of-life for updates and support on
2026-05-13.
No more updates of any kind, including security updates or security
announcements, will be available for Fedora Linux 42 after this
date. No pending updates for Fedora Linux 42 will be pushed to stable.

Fedora Linux 43 will continue to receive updates until approximately
one month after the release of Fedora Linux 45. The maintenance
schedule of Fedora Linux releases is documented here[1]. The docs also
contain instructions[2] on how to upgrade from a previous release of
Fedora Linux to a version receiving updates.

Regards,
Samyak Jain
Fedora Release Engineering

[1] https://docs.fedoraproject.org/en-US/releases/lifecycle/#_maintenance_schedule
[2] https://docs.fedoraproject.org/en-US/quick-docs/upgrading-fedora-new-release/
-- 
_______________________________________________
test-announce mailing list -- test-announce@lists.fedoraproject.org
To unsubscribe send an email to test-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/test-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='http://fedora.cattt.com/feeds/154290849357325027/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://fedora.cattt.com/2026/05/test-announce-fedora-linux-42-will-be.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/154290849357325027'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4226657536085668026/posts/default/154290849357325027'/><link rel='alternate' type='text/html' href='http://fedora.cattt.com/2026/05/test-announce-fedora-linux-42-will-be.html' title='[Test-Announce] Fedora Linux 42 will be End of Life next week'/><author><name>xCat</name><uri>http://www.blogger.com/profile/17959601547768870164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>