<p dir="ltr">Hello,</p>
<p dir="ltr">After successfully adding a 'winsync' agreement and loading AD data into FreeIPA I am trying to configure the password sync software on the domain controllers.</p>
<p dir="ltr">I have installed the certificates and can successfully bind from the domain controller using ldp.exe and the 'uid=passsync,cn=sysaccounts,cn=etc,dc=my,dc=domain,dc=com' user.</p>
<p dir="ltr">I have edited the registry to increase logging, by setting 'HKEY_LOCAL_MACHINE\SOFTWARE\PasswordSync\Log Level' to '1' and I am seeing the error:</p>
<p dir="ltr"><font color="#000000">06/17/16 08:47:32: Backoff time expired. Attempting sync</font><br>
<font color="#000000">06/17/16 08:47:32: Password list has 1 entries</font><br>
<font color="#000000">06/17/16 08:47:32: Attempting to sync password for some.user</font><br>
<font color="#000000">06/17/16 08:47:32: Searching for (ntuserdomainid=some.user)</font><br>
<font color="#000000">06/17/16 08:47:32: Ldap error in QueryUsername</font><br>
<font color="#000000"> 34: Invalid DN syntax</font><br>
<font color="#000000">06/17/16 08:47:32: Deferring password change for some.user</font><br>
<font color="#000000">06/17/16 08:47:32: Backing off for 1024000ms</font><br></p>
<p dir="ltr"><font color="#000000">When I run the query from the CLI, it is successful:</font><br></p>
<p dir="ltr"><font color="#000000">$ ldapsearch -x -h ldaps://localhost -p 636 -D 'uid=passsync,cn=sysaccounts,cn=etc,dc=dc,my=domain,dc=com' -w 'password' -b 'cn=users,cn=accounts,dc=my,dc=domain,dc=com' '(ntuserdomainid=some.user)'</font></p>
<p dir="ltr"><font color="#000000">Can anyone help me resolve this?</font></p>
<p dir="ltr"><font color="#000000">Thanks.</font></p>