RE: How to use LDAP_OPT_CONNECT_ASYNC?

2011-02-12 Thread Ian Puleston
Hi Howard, -Original Message- From: Howard Chu [mailto:h...@symas.com] Ian Puleston wrote: I'm working on a fix now, and I think what is needed is: 1. A call to ldap_int_poll in ldap_int_tls_start if async. Then it should abort without calling ldap_int_tls_connect if not ready

Re: How to use LDAP_OPT_CONNECT_ASYNC?

2011-02-12 Thread Howard Chu
Ian Puleston wrote: Hi Howard, -Original Message- From: Howard Chu [mailto:h...@symas.com] Ian Puleston wrote: I'm working on a fix now, and I think what is needed is: 1. A call to ldap_int_poll in ldap_int_tls_start if async. Then it should abort without calling

Re: question about cn=config replication and security.

2011-02-12 Thread Jonathan Clarke
Le 11/02/2011 18:26, Mailing Lists a écrit : Hello. I'm running a pair of openldap 2.4 servers which replicate cn=config DB in mirror mode. Is there a way to configure a RO user (like user from BDB) for cn=config DB, so should someone get a hold of it's password, and still will not be able

Re: Slapd Security based on port

2011-02-12 Thread Jonathan Clarke
Le 11/02/2011 18:58, Chris Jackson a écrit : I want to apologize in advance for the forthcoming duplicated messages. My original question wasnt very clear and neither of them were getting to the list and I didnt know why. Maybe a 24hr lock out for new posters. Not exactly - new

Re: question about cn=config replication and security.

2011-02-12 Thread Alister Forbes
I think it should be possible to use an ACL to set up an RO (read only?) user from, for example a specific IP address, but you are always going to have to have at least one user that can r/w. As far as I'm aware, it's not possible to set cn=config into read only mode. (which is a good thing