Re: OpenLDAP session authentication

2010-10-07 Thread Marc Patermann
Erik, Erik Lotspeich schrieb am 05.10.2010 22:04 Uhr: I have two questions/concerns: 1. If I leave the -Y plain option off of the argument list to ldapsearch, I get Invalid credentials: As far as I know from other SASL using software (like Postfix), the client always chooses the securest

Re: questions about openldap replication

2010-10-07 Thread Christian Manal
Am 07.10.2010 11:15, schrieb plug bert: Hi All, i've read through the replication section of the admin guide, but i'm still not clear on the ff: 1. For push-type setups, do i really need to set up a sync proxy? the docs seem to imply this is necessary only if there are firewall

RE: memberOf module install on ubuntu 10.04 slapd package gives:Insufficient access using admin interface

2010-10-07 Thread Jon Skarpeteig
To clarify some: As I understand it, the interface I use is for admin purposes only, doing changes from r...@localhost without any cn credentials. In fact, I created an admin account from the same interface, which could import schemas, create OU and CN entries, and generally behaving like

subordinate + translucent

2010-10-07 Thread Wouter D'Haeseleer
This is what I would like todo: - Have a local DB which contains only groups under ou=Groups,OU=example,DC=com - Have a translucent conection to Active Directory - using subordinate gue this 2 databases together This should make it possible to administrate local Groups And add the needed Posix

Re: questions about openldap replication

2010-10-07 Thread Quanah Gibson-Mount
--On Thursday, October 07, 2010 12:59 PM +0200 Christian Manal moen...@informatik.uni-bremen.de wrote: Hi, I think you misunderstood the docs there. If you speak about push replication you mean RefreshAndPersist, right? That doesn't mean that the master connects to the slaves and pushes the

Re: questions about openldap replication

2010-10-07 Thread Jonathan Clarke
On 07/10/2010 15:45, Quanah Gibson-Mount wrote: --On Thursday, October 07, 2010 12:59 PM +0200 Christian Manal moen...@informatik.uni-bremen.de wrote: Hi, I think you misunderstood the docs there. If you speak about push replication you mean RefreshAndPersist, right? That doesn't mean that

Re: best practice and account management (passwd)

2010-10-07 Thread Chris Jacobs
Please reply-to-all. :) And, no, your confusion can never be wrong. :s However, I haven't heard or seen anyone trying to store user's files in LDAP. Even with Windows AD networks, using roaming profiles, the AD stores the user's account and group info, and the user's 'profiles' (ie: homedir)

Re: (ITS#6666) Feature Request: Triggers implementation

2010-10-07 Thread Buchan Milne
On Thursday, 7 October 2010 08:35:45 n...@eurobjects.com wrote: Sorry, I' m not a developer. I'm trying to find a solution from an administrator's point of view. I think you should have discussed this on a mailing list first, coming to some feasible method that would be acceptable, before

OpenLDAP configured as Proxy

2010-10-07 Thread Marco Pizzoli
Hi all, is there a way to obtain a OL configuration to permit proxying an ldap connection without knowledge in advance about the target ldap server? Simple scenario, I would like to put a proxy system in front of a client which is trying to check a Certificate Revocation List (CRL), which is

Re: Recommended approach for LDAP as backend for virtual domain mail hosting?

2010-10-07 Thread Andreas Ntaflos
On Tuesday 05 October 2010 10:19:37 Buchan Milne wrote: On Monday, 4 October 2010 19:47:16 Andreas Ntaflos wrote: So the requirements are basically: * Independent domains and users, i.e. john@example.org is completely different/distinct from john@example.net, even though

Re: Recommended approach for LDAP as backend for virtual domain mail hosting?

2010-10-07 Thread Andreas Ntaflos
On Tuesday 05 October 2010 04:35:59 Quanah Gibson-Mount wrote: --On Tuesday, October 05, 2010 4:22 AM +0200 Andreas Ntaflos d...@pseudoterminal.org wrote: Hi Quanah, thank you too for your reply! Could you elaborate on using an empty base/suffix? The concept seems strange to me and I

Re: Recommended approach for LDAP as backend for virtual domain mail?hosting?

2010-10-07 Thread Andreas Ntaflos
On Tuesday 05 October 2010 05:57:16 Dan White wrote: Postfix, as you probably already know, has LDAP support for looking up most tables, which is how I implement virtual domain lookups. I've asked this in another message as well but how would an LDAP query for Postfix's virtual_mailbox_domains

Re: meta backend olc?

2010-10-07 Thread Howard Chu
Marc Patermann wrote: Hi, while migrating servers form 2.3.x to 2.4.x I stumbled upon this with openldap2-2.4.20-0.4.29 SLES11SP1. When I try online config based on my slapd.conf file, I get an error # slaptest -f /etc/openldap/slapd.conf -F /etc/openldap/slapd.d -u config file testing

Re: Recommended approach for LDAP as backend for virtual domain mail?hosting?

2010-10-07 Thread Dan White
On 07/10/10 22:57 +0200, Andreas Ntaflos wrote: On Tuesday 05 October 2010 05:57:16 Dan White wrote: Postfix, as you probably already know, has LDAP support for looking up most tables, which is how I implement virtual domain lookups. I've asked this in another message as well but how would an

Re: How can I make the unique overlay play nicely with my ACL?

2010-10-07 Thread Howard Chu
Owen Jacobson wrote: Hi there, I'm trying to enforce that the 'uid' attribute is globally unique in my tree using the unique overlay. For a collection of mostly-uninteresting reasons, the LDAP server is publicly connectable but not publicly searchable (details below). It appears that the

Re: How can I make the unique overlay play nicely with my ACL?

2010-10-07 Thread Owen Jacobson
On 2010-10-07, at 9:03 PM, Howard Chu wrote: Owen Jacobson wrote: Hi there, I'm trying to enforce that the 'uid' attribute is globally unique in my tree using the unique overlay. For a collection of mostly-uninteresting reasons, the LDAP server is publicly connectable but not publicly