PAM OTP login requirements
by Brian Topping
Hi all, I hope this is the best place to ask this, please let me know if not.
I am setting up a PAM client (libreswan, using the `pluto` service). When I log in with a non-OTP account, everything works fine, but not with an OTP account. I have tested the OTP account by logging into the node with SSH and the OTP user and it works fine, so I know both that the token works and that the client configuration are both correct. I’ve tried a few different PAM stacks to see if I could get around this, including the sshd stack to no avail. In all cases, the FreeIPA server logs state `Additional pre-authentication required` and then `Preauthentication failed`.
Preauthentication makes sense, I just don’t understand why sshd works fine with both password factors concatenated in the first factor and libreswan (and xl2tpd when I was testing it) both fail with preauth issues. What am I missing? Are there good docs on this somewhere? [1] was the best I could come up with and it seems to be out-of-date (pam_sss takes different parameters for some of the same functions in the final form).
Cheers! Brian
[1] https://docs.pagure.org/SSSD.sssd/design_pages/pam_conversation_for_otp.html
5 years, 2 months
FreeIPA not working (Segfault in Kerberos) after upgrading to Fedora 29
by Patrick Dung
Hello,
After upgrading to Fedora 29, Kerberos on the primary Free IPA is not working. Another FreeIPA replica failed to start. It is because Kerberos (GSSAPI) is not working and ns-slapd cannot start. Replication agreement cannot be established via Kerberos (GSSAPI)
I got this messages in for the kernel log.
Dec 27 02:00:05 server1 kernel: [ 2551.272984] krb5_child[25058]: segfault at 6e ip 00007f58ae29464e sp 00007fffb5047bf0 error 4 in libkrb5.so.3.3[7f58ae26b000+71000]
Dec 27 02:00:05 server1 kernel: [ 2551.273449] Code: fc bf 28 00 00 00 55 53 48 83 ec 18 64 48 8b 04 25 28 00 00 00 48 89 44 24 08 31 c0 e8 2b 9b fd ff 48 85 c0 0f 84 02 01 00 00 <f3> 41 0f 6f 07 f3 41 0f 6f 4f 10 48 89 c3 49 63 7f 20 0f 11 00 0f
Dec 27 02:00:05 server1 kernel: [ 2551.272984] krb5_child[25058]: segfault at 6e ip 00007f58ae29464e sp 00007fffb5047bf0 error 4 in libkrb5.so.3.3[7f58ae26b000+71000]
Dec 27 02:00:05 server1 kernel: [ 2551.273449] Code: fc bf 28 00 00 00 55 53 48 83 ec 18 64 48 8b 04 25 28 00 00 00 48 89 44 24 08 31 c0 e8 2b 9b fd ff 48 85 c0 0f 84 02 01 00 00 <f3> 41 0f 6f 07 f3 41 0f 6f 4f 10 48 89 c3 49 63 7f 20 0f 11 00 0f
Any ideas? FYI I had already opened a ticket in bugzilla: 1662175 – Segfault in freeipa/krb5_child after upgrading to Fedora 29
|
|
| |
1662175 – Segfault in freeipa/krb5_child after upgrading to Fedora 29
|
|
|
Thanks,Patrick
5 years, 2 months
Service named-pkcs11.service on master fails: Process 3946 (named-pkcs11) of user 25 dumped core
by 74cmonty
Hi,
starting service `named-pkcs11.service` fails with a core dump:
```
Dez 29 17:32:25 ipa-master.example.com systemd-coredump[2901]: Process 2895 (named-pkcs11) of user 25 dumped core.
Stack trace of thread 2897:
#0 0x00007f2b386c753f raise (libc.so.6)
#1 0x00007f2b386b1895 abort (libc.so.6)
#2 0x00007f2b386b1769 __assert_fail_base.cold.0 (libc.so.6)
#3 0x00007f2b386bf9f6 __assert_fail (libc.so.6)
#4 0x00007f2b38fb8c95 n/a (libkrb5.so.3)
#5 0x00007f2b38fb96ef n/a (libkrb5.so.3)
#6 0x00007f2b38fc2d0c n/a (libkrb5.so.3)
#7 0x00007f2b38fbc8b3 n/a (libkrb5.so.3)
#8 0x00007f2b38fbb9dd krb5_cc_select (libkrb5.so.3)
#9 0x00007f2b3909b959 n/a (libgssapi_krb5.so.2)
#10 0x00007f2b390a4a82 n/a (libgssapi_krb5.so.2)
#11 0x00007f2b390a5b06 n/a (libgssapi_krb5.so.2)
#12 0x00007f2b3908f0bb gss_init_sec_context (libgssapi_krb5.so.2)
#13 0x00007f2b34824667 gssapi_client_mech_step (libgssapiv2.so)
#14 0x00007f2b34907471 sasl_client_step (libsasl2.so.3)
#15 0x00007f2b349075fa sasl_client_start (libsasl2.so.3)
#16 0x00007f2b3494624b ldap_int_sasl_bind (libldap-2.4.so.2)
#17 0x00007f2b349498ec ldap_sasl_interactive_bind (libldap-2.4.so.2)
#18 0x00007f2b34949b0a ldap_sasl_interactive_bind_s (libldap-2.4.so.2)
#19 0x00007f2b34992c6f ldap_connect (ldap.so)
#20 0x00007f2b3499fa90 new_ldap_instance (ldap.so)
#21 0x00007f2b34990292 dyndb_init (ldap.so)
#22 0x00007f2b3943f75a dns_dyndb_load (libdns-pkcs11.so.1102)
#23 0x00005612e6a46718 n/a (named-pkcs11)
#24 0x00005612e6a53ed3 n/a (named-pkcs11)
#25 0x00005612e6a54f47 n/a (named-pkcs11)
#26 0x00007f2b3938d899 n/a (libisc-pkcs11.so.169)
#27 0x00007f2b38bd458e start_thread (libpthread.so.0)
#28 0x00007f2b3878c6a3 __clone (libc.so.6)
Stack trace of thread 2898:
#0 0x00007f2b38bdaa8a pthread_cond_timedwait@(a)GLIBC_2.3.2 (libpthread.so.0)
#1 0x00007f2b393ad2b0 isc_condition_waituntil (libisc-pkcs11.so.169)
#2 0x00007f2b39394683 n/a (libisc-pkcs11.so.169)
#3 0x00007f2b38bd458e start_thread (libpthread.so.0)
#4 0x00007f2b3878c6a3 __clone (libc.so.6)
Stack trace of thread 2899:
#0 0x00007f2b3878c9d7 epoll_wait (libc.so.6)
#1 0x00007f2b393a501c n/a (libisc-pkcs11.so.169)
#2 0x00007f2b38bd458e start_thread (libpthread.so.0)
#3 0x00007f2b3878c6a3 __clone (libc.so.6)
Stack trace of thread 2896:
#0 0x00007f2b38bda73c pthread_cond_wait@(a)GLIBC_2.3.2 (libpthread.so.0)
#1 0x00007f2b3938d695 n/a (libisc-pkcs11.so.169)
#2 0x00007f2b38bd458e start_thread (libpthread.so.0)
#3 0x00007f2b3878c6a3 __clone (libc.so.6)
Stack trace of thread 2895:
#0 0x00007f2b386c78ee __sigsuspend (libc.so.6)
#1 0x00007f2b3939713e isc__app_ctxrun (libisc-pkcs11.so.169)
#2 0x00007f2b39397d73 isc_app_run (libisc-pkcs11.so.169)
#3 0x00005612e6a07d05 n/a (named-pkcs11)
#4 0x00007f2b386b3413 __libc_start_main (libc.so.6)
#5 0x00005612e6a0865e n/a (named-pkcs11)
Dez 29 17:32:25 ipa-master.example.com audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='unit=systemd-coredump@10-2900-0 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
```
Full log is available here: http://freetexthost.com/nx1e4xhmyi
Assuming this issue is related to file /usr/lib64/bind/ldap.so I tried to scp from replica server.
However this fails with this weird error:
```[root@ipa-master ~]# ssh -p 22202 ipa-replica.example.com
ssh_exchange_identification: Connection closed by remote host
[root@ipa-master ~]# scp -P 22201 ipa-replica.example.com:/usr/lib64/bind/ldap.so /home/
Password:
\033[0m\033[1;34m /:-------------:\ \033[0m\033[1;34m root\033[0m\033[1m(a)\033[0m\033[0m\033[1;34mipa-replica.example.com\033[0m
````
5 years, 2 months
Help to install a replica on Fedora 28
by ARNAL Laurent
Hello,
I try to install a replica on a fedora 28 server using the command
ipa-replica-install --principal admin --admin-password password --force-join
Command failed on step [26/41]: creating DS keytab with error :
===================================================
2018-12-26T11:00:02Z DEBUG Process finished, return code=9
2018-12-26T11:00:02Z DEBUG stdout=uid=0(root) gid=0(root) groupes=0(root),39(video)
2018-12-26T11:00:02Z DEBUG stderr=Impossible d'analyser le résultat : Insufficient access rights
Nouvelle tentative de récupération avec la méthode pre-4.0...
Impossible d'analyser le résultat : Insufficient access rights
Échec d'obtention du tableau de clés !
Échec à l'obtention du tableau de clés
2018-12-26T11:00:02Z DEBUG Traceback (most recent call last):
File "/usr/lib/python3.6/site-packages/ipaserver/install/service.py", line 605, in start_creation
run_step(full_msg, method)
File "/usr/lib/python3.6/site-packages/ipaserver/install/service.py", line 591, in run_step
method()
File "/usr/lib/python3.6/site-packages/ipaserver/install/dsinstance.py", line 1315, in request_service_keytab
super(DsInstance, self).request_service_keytab()
File "/usr/lib/python3.6/site-packages/ipaserver/install/service.py", line 782, in request_service_keytab
self.run_getkeytab(self.api.env.ldap_uri, self.keytab, self.principal)
File "/usr/lib/python3.6/site-packages/ipaserver/install/service.py", line 772, in run_getkeytab
ipautil.run(args, nolog=nolog)
File "/usr/lib/python3.6/site-packages/ipapython/ipautil.py", line 574, in run
p.returncode, arg_string, output_log, error_log
Error(Command ['/usr/sbin/ipa-getkeytab', '-k', '/etc/dirsrv/ds.keytab', '-p', 'ldap/kerclaei.mydomain.com(a)MYDOMAIN.COM', '-H', 'ldaps://stellai.mydomain.com'] returned non-zero exit status 9: "Impossible d'analyser le résultat\xa0: Insufficient access rights\n\nNouvelle tentative de récupération avec la méthode pre-4.0...\nImpossible d'analyser le résultat\xa0: Insufficient access rights\n\nÉchec d'obtention du tableau de clés\xa0!\nÉchec à l'obtention du tableau de clés\n")
2018-12-26T11:00:02Z DEBUG [error] CalledProcessError: CalledProcessError(Command ['/usr/sbin/ipa-getkeytab', '-k', '/etc/dirsrv/ds.keytab', '-p', 'ldap/kerclaei.mydomain.com(a)MYDOMAIN.COM', '-H', 'ldaps://stellai.mydomain.com'] returned non-zero exit status 9: "Impossible d'analyser le résultat\xa0: Insufficient access rights\n\nNouvelle tentative de récupération avec la méthode pre-4.0...\nImpossible d'analyser le résultat\xa0: Insufficient access rights\n\nÉchec d'obtention du tableau de clés\xa0!\nÉchec à l'obtention du tableau de clés\n")
2018-12-26T11:00:02Z DEBUG Destroyed connection context.ldap2_140109927205352
===================================================
If I try to launch the ipa-getkeytab command from shell, the command succed.
Can someone help me to solve this issue ?
The permissions on /etc/dirsrv directory look like this:
[root@kerclaei 2]# dir /etc/dirsrv -la
total 0
drwxrwxr-x 1 root dirsrv 124 26 déc. 12:30 .
drwxr-xr-x 1 root root 10828 26 déc. 12:27 ..
drwx------ 1 dirsrv dirsrv 188 7 févr. 2018 admin-serv
drwxr-xr-x 1 dirsrv dirsrv 104 23 déc. 13:07 config
drwxr-xr-x 1 dirsrv dirsrv 30 7 févr. 2018 dsgw
drwxr-xr-x 1 dirsrv dirsrv 22 24 août 23:12 schema
drwxrwx--- 1 dirsrv dirsrv 234 26 déc. 12:30 slapd-DOMAIN-COM
drwxrwx--- 1 dirsrv dirsrv 30 26 déc. 09:44 slapd-DOMAIN-COM.removed
Regards,
Laurent
5 years, 3 months
Freeipa replica server issue
by Azim Siddiqui
Hello,
Hope you are doing good.
Hello All,
We have a master freeipa server through which we created more two replica
freeipa servers. When we create a user in master server, the user was
automatically created into the two replica servers. Everything was working
fine, But now I am seeing this error for one of the replica server, when
running this command
ipa-replica-manage -v list local-host
last update status: -1 Incremental update has failed and requires
administrator actionLDAP error: Can't contact LDAP server
When i am checking the logs for /var/log/dirsrv/localhost, I can see this
:-
[24/Dec/2018:21:27:55 +0000] slapi_ldap_bind - Error: could not perform
interactive bind for id [] authentication mechanism [GSSAPI]: error -1
(Can't contact LDAP server)
[24/Dec/2018:21:32:20 +0000] slapi_ldap_bind - Error: could not send
startTLS request: error -1 (Can't contact LDAP server) errno 2 (No such
file or directory)
[24/Dec/2018:21:32:55 +0000] slapd_ldap_sasl_interactive_bind - Error:
could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -1
(Can't contact LDAP server) ((null)) errno 107 (Transport endpoint is not
connected)
[24/Dec/2018:21:32:55 +0000] slapi_ldap_bind - Error: could not perform
interactive bind for id [] authentication mechanism [GSSAPI]: error -1
(Can't contact LDAP server)
Can you please tell me how to resolve this issue ?
Thanks & Regards,
Azeem
5 years, 3 months
FreeIPA UID vs. Linux UID - what's the difference
by 74cmonty
Hi,
could you please explain the difference of FreeIPA UID vs. Linux UID?
When I create a user in FreeIPA the UID is this: 1227200001
But in any Linux the first user created has UID: 1000
Should I align UIDs in FreeIPA to the Linux UID?
If yes, does the same apply to GID?
Or should I keep the UID / GID created by FreeIPA?
If yes, how does this work when a client is registered with FreeIPA?
THX
5 years, 3 months
FreeIPA containerization status
by Jan Pazdziora
Hello,
in the past couple of week I've pushed multiple changes to the
https://github.com/freeipa/freeipa-container
repository, fixing and enabling Fedora 28 and Fedora 29 Dockerfiles,
adding Travis CI configuration where we currently test IPA master and
replica setups in images of Fedoras from 23 to rawhide and on CentOS 7:
https://travis-ci.org/freeipa/freeipa-container/branches
Testing on Travis' Ubuntus allowed me to reproduce and fix some issues
that people have observed on non-RHEL/CentOS/Fedora docker hosts. One
of the results is that docker run's --privileged or --cap-add
SYS_ADMIN options should not be needed anymore, making things more
confined and more secure. In fact, it's quite likely that running the
FreeIPA server containers as privileged will result in
https://github.com/freeipa/freeipa-container/issues/254
... so just don't do it.
Another focus of the effort was to make it possible to run the
containers as read-only (docker run --read-only), making all the
changes that are done during the initial ipa-server-install or during
runtime properly confined to the /data volume, or pointed to
discardable /tmp. While things pass in my local read-only tests, in
Travis CI the initial ipa-server-install phase runs fine but starting
the read-only container afterwars seems to hang:
https://travis-ci.org/adelton/freeipa-container/builds/459418370
Any help with investigating why this is happening would be
appreciated.
--
Jan Pazdziora
Senior Principal Software Engineer, Security Engineering, Red Hat
5 years, 3 months
Insufficient access: SASL(-1): generic failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Ticket expired)
by lune voo
Hello !
I contact you because I have a random problem with my 3.0.0.47 FreeIPA
server.
Sometimes, suddenly, I cannot use anymore the REST API and I got the
following errors when I try things like ipa user-show <myuser> :
Insufficient access: SASL(-1): generic failure: GSSAPI Error: Unspecified
GSS failure. Minor code may provide more information (Ticket expired)]
traceback : <traceback object at 0x3b917a0>
The kinit works fine, klist also.
My ticket is valid until the day after so no problem from there.
The datetime is the same between the IPA server and the IPA client.
When I check the httpd logs on the IPA server, as long as this error lasts,
I don't see any logs at all.
For example, today, the problem occured at 12:06:39 and in the HTTPD error
logs :
[Wed Oct 31 12:05:23 2018] [error] ipa: INFO: aPrincipal@MYREALM:
user_show(u'anotherPincipal', rights=False, all=True, raw=False,
version=u'2.49', no_members=False): SUCCESS
[Wed Oct 31 12:07:23 2018] [error] ipa: INFO: aPrincipal@MYREALM:
user_find(u'PrincipalPattern_', sizelimit=1000, whoami=False, all=False,
raw=False, version=u'2.49', no_members=False, pkey_only=False): SUCCESS
There is nothing in the dirsrv error logs at this time and around this time.
Nothing neither in the PKI CA logs.
When I check the logs in cli.log, I find this kind of lines :
2018-10-31T12:06:39Z 1933 MainThread ipa.ipalib.rpc.xmlclient
INFO trying https://<IPA-MASTER>/ipa/xml
2018-10-31T12:06:39Z 1933 MainThread ipa.ipalib.rpc.xmlclient
INFO Forwarding 'user_show' to server u'https://<IPA-MASTER>/ipa/xml'
2018-10-31T12:06:39Z 1947 MainThread ipa.ipalib.rpc.xmlclient
INFO trying https://<IPA-MASTER>/ipa/xml
2018-10-31T12:06:39Z 1947 MainThread ipa.ipalib.rpc.xmlclient
INFO Forwarding 'user_show' to server u'https://<IPA-MASTER>/ipa/xml'
2018-10-31T12:06:40Z 1961 MainThread ipa.ipalib.rpc.xmlclient
INFO trying https://<IPA-MASTER>/ipa/xml
2018-10-31T12:06:40Z 1961 MainThread ipa.ipalib.rpc.xmlclient
INFO Forwarding 'user_show' to server u'https://<IPA-MASTER>/ipa/xml'
2018-10-31T12:06:40Z 1975 MainThread ipa.ipalib.rpc.xmlclient
INFO trying https://<IPA-MASTER>/ipa/xml
2018-10-31T12:06:40Z 1975 MainThread ipa.ipalib.rpc.xmlclient
INFO Forwarding 'user_show' to server u'https://<IPA-MASTER>/ipa/xml'
2018-10-31T12:07:27Z 2159 MainThread ipa INFO The ipactl
command was successful
2018-10-31T12:07:27Z 2160 MainThread ipa INFO The ipactl
command was successful
I cannot see anything special in the krb5kdc.log neither for this time. The
only line corresponding to the IP of the client are the followings :
Oct 31 12:06:24 <IPA-MASTER> krb5kdc[137188](info): AS_REQ (4 etypes {18 17
16 23}) <IP CLIENT>: NEEDED_PREAUTH: <MYUSER>@<MYREALM> for
krbtgt/<MYREALM>@<MYREALM>, Additional pre-authentication required
Oct 31 12:06:24 <IPA-MASTER> krb5kdc[137188](info): AS_REQ (4 etypes {18 17
16 23}) <IP CLIENT>: NEEDED_PREAUTH: <MYUSER>@<MYREALM> for
krbtgt/<MYREALM>@<MYREALM>, Additional pre-authentication required
Oct 31 12:06:24 <IPA-MASTER> krb5kdc[137188](info): closing down fd 10
Oct 31 12:06:24 <IPA-MASTER> krb5kdc[137188](info): closing down fd 10
Oct 31 12:06:24 <IPA-MASTER> krb5kdc[137181](info): AS_REQ (4 etypes {18 17
16 23}) <IP CLIENT>: ISSUE: authtime 1540983984, etypes {rep=18 tkt=18
ses=18}, <MYUSER>@<MYREALM> for krbtgt/<MYREALM>@<MYREALM>
Oct 31 12:06:24 <IPA-MASTER> krb5kdc[137181](info): AS_REQ (4 etypes {18 17
16 23}) <IP CLIENT>: ISSUE: authtime 1540983984, etypes {rep=18 tkt=18
ses=18}, <MYUSER>@<MYREALM> for krbtgt/<MYREALM>@<MYREALM>
Oct 31 12:06:24 <IPA-MASTER> krb5kdc[137181](info): closing down fd 10
Oct 31 12:06:24 <IPA-MASTER> krb5kdc[137181](info): closing down fd 10
We are multiple users connecting to the same server with SSH and using root.
But each one of us use a different KRB5CCNAME to take a kerberos ticket.
(we take different ticket, me for example I take an admin ticket, a
colleague takes another principal ticket).
I tried using the ipa user-show with the -d flag : ipa -d user-show
<myuser> and I compared the result between one which failed and one which
was successfull.
The difference came at this step :
When it failed :
ipa: DEBUG: approved_usage = SSL Server intended_usage = SSL Server
ipa: DEBUG: cert valid True for "CN=<IPA-MASTER>,O=<MYREALM>"
ipa: DEBUG: handshake complete, peer = <IP>:443
ipa: DEBUG: Protocol: TLS1.2
ipa: DEBUG: Cipher: TLS_RSA_WITH_AES_128_CBC_SHA
ipa: DEBUG: Caught fault 2100 from server
https://<IPA-MASTER>/ipa/session/xml: Insufficient access: SASL(-1):
generic failure: GSSAPI Error: Unspecified GSS failure. Minor code may
provide more information (Ticket expired)
ipa: DEBUG: Destroyed connection context.xmlclient
ipa: ERROR: Insufficient access: SASL(-1): generic failure: GSSAPI
Error: Unspecified GSS failure. Minor code may provide more information
(Ticket expired)
When it succeeds :
ipa: DEBUG: approved_usage = SSL Server intended_usage = SSL Server
ipa: DEBUG: cert valid True for "CN=<IPA-MASTER>,O=<MYREALM>"
ipa: DEBUG: handshake complete, peer = <IP>:<PORT>
ipa: DEBUG: Protocol: TLS1.2
ipa: DEBUG: Cipher: TLS_RSA_WITH_AES_128_CBC_SHA
ipa: DEBUG: received Set-Cookie
'ipa_session=385454761d74afed915a24124ba5ef25; Domain=<IPA-MASTER>;
Path=/ipa; Expires=Wed, 31 Oct 2018 15:57:45 GMT; Secure; HttpOnly'
ipa: DEBUG: storing cookie 'ipa_session=385454761d74afed915a24124ba5ef25;
Domain=<IPA-MASTER>; Path=/ipa; Expires=Wed, 31 Oct 2018 15:57:45 GMT;
Secure; HttpOnly' for principal <myPrincipal>@<MYREALM>
ipa: DEBUG: args=keyctl search @s user
ipa_session_cookie:<myPrincipal>@<MYREALM>
ipa: DEBUG: stdout=485338998
ipa: DEBUG: stderr=
ipa: DEBUG: args=keyctl search @s user
ipa_session_cookie:<myPrincipal>@<MYREALM>
ipa: DEBUG: stdout=485338998
ipa: DEBUG: stderr=
ipa: DEBUG: args=keyctl pupdate 485338998
ipa: DEBUG: stdout=
ipa: DEBUG: stderr=
ipa: DEBUG: Destroyed connection context.xmlclient
So when it works, it sets a session cookie ?
Some information about FreeIPA and cookies :
https://vda.li/en/posts/2015/05/28/talking-to-freeipa-api-with-sessions/
May you help me please ?
As a note, I found a workaround for that. I need to destroy my ticket with
kdestroy and then to disconnect from the server.
Then when I connect back to the server, I take a kerberos ticket and I can
use the rest api.
This problem is really strange, thank you in advance for your help guys.
Lune
5 years, 3 months
FreeIPA/Dogtag - Slow host deletion due to certificate pagination
by Jared Ledvina
Hi folks,
I recently posted a thread to pki-users, https://www.redhat.com/archives/pki-users/2018-December/msg00003.html . Working with 'cipherboy' on IRC in #dogtag-pki, we narrowed the issue down to the searches that Dogtag performs against a VLV index/search. These are being paginated to 2,000 entries. I've since, opened up: https://bugzilla.redhat.com/show_bug.cgi?id=1658280 but, haven't been able to figure out a solution. I'm hoping that someone on this list might be able to troubleshoot further with me on this.
Has anyone looked at this before? So far, I'm unable to determine where the 2,000 paging size is getting set.
The linked bugzilla issue should have a bunch of necessary details but, I'm happy to provide any additional details that might help.
Thanks,
Jared
--
Jared Ledvina
jared(a)techsmix.net
5 years, 3 months