• Skip to main content
  • Skip to primary navigation
  • Skip to primary sidebar
  • UC Berkeley
  • Berkeley Engineering
  • EECS
Header Search Widget
IRIS

Instructional & Research Information Systems

  • About Us
  • Get Started
  • Get Help
  • FAQ
    • FAQ: Accounts
    • FAQ: EECS Slack
    • FAQ: File Storage
    • FAQ: Hardware
    • FAQ: MacOS
    • FAQ: Mail
    • FAQ: Mailing Lists
    • FAQ: Network
    • FAQ: Security
    • FAQ: Unix
    • FAQ: Web
    • FAQ: Windows
  • Services
    • Accounts
    • Backups
    • E-mail
    • EECS Login Servers
    • File Storage
    • Infrastructure
    • Mailing Lists
    • Networks
    • Printing
    • Room Reservations
    • Security
    • Software
    • Unix
    • Web
  • Policies
  • Forms
    • System Registration/Update
    • Account Request Form
    • Project Storage Request
    • SSL Certificate Request
    • All Other Forms
  • Rates

LDAP

LDAP (Lightweight Directory Access Protocol) service

Changes to EECS LDAP Access from off-campus

April 1, 2014 by Rob McNicholas

On Tuesday, April 1, 2014 IRIS will begin restricting access to the EECS LDAP directory server (`ldap.eecs.berkeley.edu`) from off-campus IP addresses. This will primarily affect people who use email programs such as Thunderbird, Outlook or Apple Mail that are configured to auto-complete email addresses from our directory. This will not affect people using the bMail web interface.

At this time, anonymous queries are allowed against the EECS LDAP directory, but searches are restricted to no more than 100 results. Unfortunately this configuration still allows an anonymous query to retrieve some details about a specific person, such as their email address, phone number or advisor. To mitigate this, after April 1 only authenticated queries will be allowed when coming from an off-campus IP address. For the purposes of this change, “off-campus” means an IP not in the any of the following ranges:

  • 128.32.0.0/16
  • 169.229.0.0/16
  • 136.152.0.0/16
  • 172.16.0.0/16
  • 10.16.0.0/16

Those who need continued anonymous access to the directory from off-campus can use the [campus VPN](http://ist.berkeley.edu/node/591), which will give their off-campus machine a campus IP address. Those who need to run queries that return unlimited results can bind to the directory using their EECS credentials, or an “application” account can be created if needed.

We expect this change will affect a small number of people, but if you have any concerns or questions please contact the IRIS helpdesk at help@eecs.berkeley.edu.
[Read more…] about Changes to EECS LDAP Access from off-campus

Filed Under: Resolved Incidents Services: LDAP

filesystem problem in LDAP server may have caused temporary authentication failures

September 7, 2013 by IRIS Staff

One of the LDAP servers in our pair became unresponsive due to a filesystem problem. Some services (such as Jabber) had authentication problems during this time. The system is back online now after running fsck.

The current LDAP servers are old legacy systems slated to be replaced in the very near future. The configuration of these servers and the services that rely on it is non-optimal which results in problems with authentication to some (but not all) services that rely on LDAP.

The new LDAP system is in its final testing phases now and will completely replace the aging infrastructure we have now.

The problem with the system was detected by IT staff with one of our monitoring systems which alerted us. We are not aware of any impact to the community and have received no reports from anyone. If you experienced any authentication problems between 1-2am then please let us know by writing to help@eecs.berkeley.edu

Resolved as of 2013-09-07 01:57:00

Filed Under: Resolved Incidents Services: Jabber, LDAP

LDAP & Jabber outage this morning, May 15, 2013

May 15, 2013 by Rob McNicholas

The department’s primary LDAP server ldap.eecs stopped responding early this morning around 12:30am. This affected a few other services which rely on ldap.eecs; we had reports of problems accessing Repo, and jabber.eecs stopped accepting connections at some point.

ldap.eecs was restarted at 7:00am and this would have restored most affected services. However, the jabber server seemed to be hung and had to be restarted; this was not noticed until around 10:30am.

Our ldap servers are aging and there is a current project underway to upgrade them to more modern hardware and software. An announcement about the scope of this project will be made in the coming weeks.

We are also planning to implement better monitoring of our jabber server so that future outages will be detected much more quickly.

Resolved as of 2013-05-15 07:00:00

Filed Under: Resolved Incidents Services: LDAP

May 3, 2013 directory server malfunctioning

May 3, 2013 by Mark Kraitchman

LDAP directory service from ldap.CS.Berkeley.EDU was malfunctioning from about Friday May 3, 2013 01:56 to about 06:57.

It appears authenticated outgoing smtp service on gateway.EECS.Berkeley.EDU also malfunctioned during that time frame when gateway.EECS.Berkeley.EDU failed to use ldap.EECS.Berkeley.EDU for LDAP directory service instead of ldap.CS.Berkeley.EDU

Resolved as of 2013-05-03 06:57:00

Filed Under: Resolved Incidents Services: LDAP

no directory service from ldap.eecs Wednesday December 28th in the morning

December 28, 2011 by Mark Kraitchman

The Entrust SSL certificate that is due to expire December 31, 2011 will be removed. A new 2048 bit CSR will be generated. We will apply for a new InCommon SSL certificate. After the new SSL certificate is issued, it will be installed and ldap directory service should resume.
[Read more…] about no directory service from ldap.eecs Wednesday December 28th in the morning

Filed Under: Resolved Incidents Services: LDAP

directory service from ldap.cs down

December 23, 2011 by Mark Kraitchman

The installed SSL certificate expires December 31, 2011
[Read more…] about directory service from ldap.cs down

Filed Under: Resolved Incidents Services: LDAP

directory service from ldap.eecs

December 23, 2011 by Mark Kraitchman

The Sun Java(TM) System Directory Server Enterprise Edition software is is being updated to Patch 6.3.1.1.1 so that a new 2048 bit SSL certificate can be installed
[Read more…] about directory service from ldap.eecs

Filed Under: Resolved Incidents Services: LDAP

directory service from ldap.cs

December 23, 2011 by Mark Kraitchman

The Sun Java(TM) System Directory
Server Enterprise Edition software is
is being updated to Patch 6.3.1.1.1
so that a new 2048 bit SSL certificate
can be installed.
[Read more…] about directory service from ldap.cs

Filed Under: Resolved Incidents Services: LDAP

LDAP Outage

August 17, 2011 by Carlos Caceres

“There was a short LDAP outage between 2:50pm and 3:00pm today, that has been resolved. Impacted areas included IRIS web forms. If there are further problems with the server, please email help@eecs.berkeley.edu so we can investigate further. ”

Resolved as of 2011-08-17 15:04:00

Filed Under: Resolved Incidents Services: LDAP

cronus services are down

June 11, 2011 by Mark Kraitchman

cronus starting have some issues
Saturday June 11, 2011 at 19:58

It appears to be a hard drive problem.

cronus services went down Saturday
evening June 11, 2011. The
affected services included DNS, NIS,
time and using EECS Windows Active
Directory passwords for IRIS ldap
authentication.
[Read more…] about cronus services are down

Filed Under: Resolved Incidents Services: LDAP

  • « Go to Previous Page
  • Go to page 1
  • Go to page 2
  • Go to page 3
  • Go to Next Page »

Primary Sidebar

IRIS Service Status

Yellow
We have 0 Active Incidents, and 1 Scheduled Maintenance noted.

IST Service Status

Outages to campus services are listed at berkeley.statusdashboard.com.
  • About
  • Contact
  • Privacy
  • Accessibility
  • Nondiscrimination

© 2022–2026 UC Regents  |  Log in