-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Andrew Bartlett wrote:

Naturally, this just means you need to give nss_ldap the same ldap base
DN to search under as samba is using.  Naturally, if nss_ldap only looks
under ou=people, then it's not going to work, but I set my base dn to
just 'dc=hawkerc,dc=net', and carry the minor cost of a possible search
against other ou's that might not contain accounts.

Right. And my only point is that for large directories this
cost can be non-zero. So IMO we need to redisgn the LDAP suffix and searches in Samba altogether to be more localized and efficient.






cheers, jerry
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD4DBQFAD7yzIR7qMdg1EfYRAqnVAJiI0iu3184MHl/vmdzAa20tGU0IAJ4qNkh4
ota5VylZ3zYsqXVswE/EtA==
=ksYK
-----END PGP SIGNATURE-----

--
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba

Reply via email to