Re: Re-investigating ppolicy + chain issues on a consumer: chain configuration

2010-06-24 Thread Dieter Kluenter
Siddhartha Jain sj...@silverspringnet.com writes: I am still stuck at the same place where a chained consumer allows a client to auth with a bad password. Remove chaining and bad passwords are no longer accepted. To troubleshoot from scratch, I am curious about how chaining should be

Unique Overlay Help

2010-06-24 Thread Piyush Joshi
Dear Expert, I have used unique overlay with my openldap install and that's working now i want two of my attributes to be unique and that's not possible currnetly. Can it be added in following openldap releases or can any one make change in unique overlay to perform the same.

Re: ldaprc with ldaps:// and ldap:// fallback

2010-06-24 Thread Emmanuel Dreyfus
Dieter Kluenter die...@dkluenter.de wrote: No, ldapi:/// doesn't present a certificate, but you may establish a startTLS session to ldapi:///, in this case the client requests a server certificate. Let me rephrase: I would like to specify two LDAP servers in ldaprc - one ldapi:/// with

RE: openldap pwdReset

2010-06-24 Thread Allgood, John
Yes I set that yesterday but now my password history is not working. It seems when I get one thing working something else breaks. Any ideas on the password history? John Allgood Senior Systems Administrator OHL Transportation Services 2251 Jesse Jewell Pky. NE Gainesville, GA 30507 tel: (678)

Re: ldaprc with ldaps:// and ldap:// fallback

2010-06-24 Thread Dan White
On 24/06/10 11:57 +0200, Emmanuel Dreyfus wrote: Dieter Kluenter die...@dkluenter.de wrote: No, ldapi:/// doesn't present a certificate, but you may establish a startTLS session to ldapi:///, in this case the client requests a server certificate. Let me rephrase: I would like to specify two

LDAP Account Manager

2010-06-24 Thread Foo Bar
hi thanks for your answers. I have begin to test with the *LDAP Account Manager and it works. :-) know my question. **i** have create a user with a standard password. i will when the user make his first login than the client make a request to cange his password. how can i create this on **LDAP

Migration from Novell eDirectory to OpenLDAP

2010-06-24 Thread Stefan-Michael Guenther
Hello, has anyone on this list migrated the data of a Novell eDirectory into an OpenLDAP Server? Our first problem is that the schemas files of the eDirectoy contains nearly the same information as the schema files of OpenLDAP, but the structure of these files is completly different.

Fwd: ldapsearch using entryCSN

2010-06-24 Thread Pierre Laporte
Hi, I'm trying to search entries in an OpenLDAP (v2.4.7) directory using their last modification date as a criteria. Digging in the schemas, I couldn't find an attribute that contained such a value. The only thing I found was the internal attribute entryCSN used by OpenLDAP to manage

Re: Unique Overlay Help

2010-06-24 Thread Quanah Gibson-Mount
--On Thursday, June 24, 2010 2:03 PM +0530 Piyush Joshi joy.piy...@gmail.com wrote: Dear Expert, I have used unique overlay with my openldap install and that's working now i want two of my attributes to be unique and that's not possible currnetly. Can it be added in

Re: openldap pwdReset

2010-06-24 Thread Adam Leach
It would help if you would attach the ppolicy that this entry uses in order to make sure it is configured correctly... On Thu, Jun 24, 2010 at 7:56 AM, Allgood, John jallg...@ohl.com wrote: Yes I set that yesterday but now my password history is not working. It seems when I get one thing

Windows 7 users's authentication with openldap ?

2010-06-24 Thread Frank Bonnet
Hello Anyone knows if it is possible to authenticate users of a windows 7 client machine as we do with UNIX clients with pam_ldap + nss_ldap to our openldap server ? Thank you. F

Re: ldaprc with ldaps:// and ldap:// fallback

2010-06-24 Thread Michael Ströder
Emmanuel Dreyfus wrote: Dieter Kluenter die...@dkluenter.de wrote: No, ldapi:/// doesn't present a certificate, but you may establish a startTLS session to ldapi:///, in this case the client requests a server certificate. Let me rephrase: I would like to specify two LDAP servers in ldaprc

Re: Can password-hash be database specific? also, storing and verifying cleartext passwords

2010-06-24 Thread masarati
Is the 'password-hash' configuration function a server-wide setting only Yes. or can it be set to different values for separate databases? No. I'm trying to add MAC-auth RADIUS functionality to my LDAP server (openldap-2.4.21) and I need to store the password for the MAC addresses in

RE: openldap pwdReset

2010-06-24 Thread Allgood, John
Here is my defined ppolicy. I have defined in my /etc/ldap.conf pam_password exop. Password history and check_password was working when I had pam_password md5. I wonder if it has something to do with the way the password is being hashed. dn: cn=default,ou=policies,dc=turbocorp,dc=com cn:

RE: Unique Overlay Help

2010-06-24 Thread Siddhartha Jain
You can set more than one attribute to be unique. Please read the man page for slapo-unique: http://www.openldap.org/software/man.cgi?query=slapo-uniqueapropos=0sektion=0manpath=OpenLDAP+2.4-Releaseformat=html unique_attributes attribute... This legacy configuration parameter

Re: How to change openldap database directory

2010-06-24 Thread Quanah Gibson-Mount
--On Wednesday, June 23, 2010 12:50 PM +0530 Mail Admin pinemai...@gmail.com wrote: Hello Team, I am very new to Linux and Openldap. We have setup a mail server on CentOS, Postfix, Dovecot, etc witth OpenLDAP as backend. 1) We want to change the daabase directory of Openldap from

Re: LDAP Account Manager

2010-06-24 Thread Benjamin Griese
Hi, Please reply to the appropriate thread you were asking your question. :) I have no idea what you are talking about. Thanks. On Wed, Jun 23, 2010 at 10:27, Foo Bar foocc...@googlemail.com wrote: hi thanks for your answers. I have begin to test with the *LDAP Account Manager and it