Hello

On Thu, Mar 15, 2012 at 6:55 AM, Michael R. Gettes <gettes@gmail.com> wrote:
EL 5.6 and ds-389 1.2.9.9

I have a question of curiosity…

I have a number of replication agreements.  They were initially configured as TLS on port 389. I need them to be moved to SSL on 636.  I could re-create the agreements and delete the old ones.  OR, what about going into the cn=config, using Console and into the mapping tree and for each agreement I change nsdsReplicaPort and nsdsReplicaTransportInfo to 636 and SSL respectively.  Will this work?  Or will it screw replication into the floor?  Would I need to restart nssldapd?

Thoughts appreciated and MANY thanks in advance.

After creating a replication agreement, the connection type (SSL or non-SSL) cannot be change because LDAP and LDAPS connections use different ports. To change the connection type, re-create the replication agreement.

Refer http://docs.redhat.com/docs/en-US/Red_Hat_Directory_Server/8.2/html/Administration_Guide/Managing_Replication-Configuring_Cascading_Replication.html

Regards
Arpit Tolani