Using dynlist overlay like dynlist and dyngroup (extend dyngroup schema?)

2010-12-15 Thread c0re
Hello openldap users! slapd.conf: overlay dynlist dynlist-attrset groupOfUrls labeledURI member ldif: dn: cn=testgroup,ou=servers,dc=domain,dc=local objectclass: groupOfNames cn: testgroup member: cn=test,ou=users,dc=domain,dc=local dn: cn=maingroup,ou=servers,dc=domain,dc=local objectclass:

Debugging syncrepl

2010-12-15 Thread Angel L. Mateo
Hello, I've configured 2 ldap servers (2.4.21, from ubuntu 10.04 package) in a master-master configuration. The configuration I have is: {0}rid=004 provider=ldap://ldap1.mydomain.com binddn=replicauser bindmethod=simple credentials=replicapass searchbase=dc=mydomain type=refreshOnly

PAM Filtering Not working with CRYPT Passwds

2010-12-15 Thread Anton Chu
I have installed the ldapns.schema in my ubuntu 10.04 ldap server to enable host based authentication/filtering. I have some ubuntu 10.10 ldap clients that requires filtering. All my ldap users have passwords in crypt format that I have converted to an ldif file using the PADL migration.pl

Re: openldap and kerberos integration

2010-12-15 Thread Howard Chu
Thierry Lacoste wrote: On 10 déc. 10, at 20:57, Howard Chu wrote: Thierry Lacoste wrote: BTW I'd appreciate any recommandations about providing kerberos and LDAP authentication (with the same password) in a production setting. Should I use Heimdal or MIT kerberos ? If Heimdal, is it better

Re: openldap and kerberos integration

2010-12-15 Thread Hugo Monteiro
On 12/15/2010 07:19 PM, Howard Chu wrote: Thierry Lacoste wrote: On 10 déc. 10, at 20:57, Howard Chu wrote: Thierry Lacoste wrote: BTW I'd appreciate any recommandations about providing kerberos and LDAP authentication (with the same password) in a production setting. Should I use Heimdal

Re: openldap and kerberos integration

2010-12-15 Thread Howard Chu
Hugo Monteiro wrote: On 12/15/2010 07:19 PM, Howard Chu wrote: Thierry Lacoste wrote: I noticed some differences. In particular ldappasswd updates sambaLMPassword while kpasswd does not. I suppose we can delete sambaLMPassword support by now, certainly no one should be using it any more.