04.06.2013 Views

UCS 2.4 - Univention

UCS 2.4 - Univention

UCS 2.4 - Univention

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

7 <strong>UCS</strong> Directory service<br />

Logging of the LDAP changes is effected by a <strong>Univention</strong> directory listener module. The univention-<br />

directory-listener service should be restarted if changes are made to the <strong>Univention</strong> Configuration Reg-<br />

istry.<br />

7.2.2 Format of the log file<br />

Changes to the directory service are documented in the /var/log/univention/directory-logger.log<br />

file as a series of data records in the following format:<br />

START<br />

Old hash: <br />

DN: <br />

ID: <br />

Modifier: <br />

Time stamp: <br />

Action: <br />

Old values:<br />

<br />

New values:<br />

<br />

END<br />

There are three types of changes:<br />

• For added entries (add), only the New Values section appears.<br />

• For changed entries (modify), both the New Values section and the Old Values section appear.<br />

• For deleted entries (delete), only the Old Values section appears.<br />

A hash sum is calculated for each logged data record and documented as a line in the daemon.info<br />

section of the Syslog service in the following format:<br />

directory_logger:<br />

DN=<br />

ID=<br />

Modifier=<br />

Timestamp=<br />

New Hash=<br />

The new hash sum is also saved in the /var/lib/univention-directory-logger/cache file to<br />

allow further rotation of the directory-logger.log via Logrotate. Both files are saved in such a way<br />

that read access is limited to the root Posix user and the adm Posix group.<br />

As each data record contains the hash value of the old data record, manipulations of the log file - such as<br />

deleted entries - can be uncovered.<br />

7.3 Timeout for inactive LDAP connections<br />

The LDAP server accepts 1024 connections as standard. When many clients create connections which<br />

they only use sporadically, the point may come when the LDAP server cannot accept any more connec-<br />

182

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!