Re: Oracle OpenLDAP PPolicy ppolicy and the hierarchy

2013-12-25 Thread Arthur de Jong
On Mon, 2013-12-23 at 22:52 +0100, Dieter Klünter wrote: You use attribute type uniqueMember without any additional UID in order to enforce uniqueness. The syntax of uniqueMember attribute type is Name and optional UID. But without any additional UID any sort of uniqueness cannot be provided.

Re: Oracle OpenLDAP PPolicy ppolicy and the hierarchy

2013-12-25 Thread Michael Ströder
Arthur de Jong wrote: On Mon, 2013-12-23 at 22:52 +0100, Dieter Klünter wrote: You use attribute type uniqueMember without any additional UID in order to enforce uniqueness. The syntax of uniqueMember attribute type is Name and optional UID. But without any additional UID any sort of

Re: Oracle OpenLDAP PPolicy ppolicy and the hierarchy

2013-12-25 Thread Michael Ströder
Michael Ströder wrote: Arthur de Jong wrote: Since you cannot do joins in LDAP, every group with member attributes such as cn=Joe,ou=People,dc=... will require another lookup per member to find the username (uid attribute). This very much depends on the implementation of the NSS provider.

Re: Oracle OpenLDAP PPolicy ppolicy and the hierarchy

2013-12-25 Thread Howard Chu
Michael Ströder wrote: Michael Ströder wrote: Arthur de Jong wrote: Since you cannot do joins in LDAP, every group with member attributes such as cn=Joe,ou=People,dc=... will require another lookup per member to find the username (uid attribute). This very much depends on the implementation