[Fedora-directory-users] GSSAPI / kerberos

2006-09-25 Thread Gordon Messmer
Is anyone using GSSAPI / kerberos in production? I've come across what looks like a bug, and I'd like any available info from other users: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=208058 -- Fedora-directory-users mailing list Fedora-directory-users@redhat.com https://www.redhat.com/

Re: [Fedora-directory-users] Re: Extending inetOrgPerson's schema to support custom attributes

2006-09-25 Thread kevin james
Ahhh thanks, I did not know the Fedora DS GUI could modify schema, I'll have to get my GUI working now.     - Original Message From: David Boreham <[EMAIL PROTECTED]>To: General discussion list for the Fedora Directory server project. Sent: Monday, September 25, 2006 4:42:51 PMSubject: Re:

Re: [Fedora-directory-users] Re: Extending inetOrgPerson's schema to support custom attributes

2006-09-25 Thread David Boreham
Any ideas ? Yes. RTFM : http://www.redhat.com/docs/manuals/dir-server/ag/7.1/scmacfg.html#1079595 Use the GUI to extend schema and see what it puts in the ldif files. Then you can copy that content to extend schema in a server sans GUI. -- Fedora-directory-users mailing list Fedora-direct

Re: [Fedora-directory-users] Re: Extending inetOrgPerson's schema to support custom attributes

2006-09-25 Thread kevin james
Francois, Thanks for your quick and helpful reply, I tried what you explained,   So I create a new file called 70kevin.ldif and put this into it   dn: cn=schemaobjectClass: topobjectClass: inetorgPersonobjectClass: subschemaattributeTypes: ( 1.3.6.1.4.1.5923.1.1.1.2 NAME 'policyNos' DESC 'Policy N

Re: [Fedora-directory-users] Confusion over admserv_host_ip_check message

2006-09-25 Thread David Bogen
Dave Della Costa wrote: > > http://directory.fedora.redhat.com/wiki/Howto:AdminServerLDAPMgmt > See the section entitled "How to set the hosts/IP addresses allowed to access the Admin Server" and pay special attention to the NOTE: about the bug that you are likely encountering. David smime

Re: [Fedora-directory-users] Re: Extending inetOrgPerson's schema to support custom attributes

2006-09-25 Thread François Beretti
Hi,a few thoughts from someone who is not a fedoraDS expert :- you created a new attribute type, but did not add it to the inetorgperson class definition. So the class itself is not modified. The way the LDIF files are named does not imply you modify a given class. Only the number has a meaning, an

[Fedora-directory-users] Re: Extending inetOrgPerson's schema to support custom attributes

2006-09-25 Thread kevin james
Oops I pressed the enter key and the mail got sent, Yahoo Beta Mail is too Ajaxified :)   These were the lines I added to the bottom of the 99users.ldif My custom attribute being called "policyNos"   attributeTypes: ( 1.3.6.1.4.1.5923.1.1.1.2 NAME 'policyNos' DESC 'Policy Numbers for Insured' EQUAL

[Fedora-directory-users] Extending inetOrgPerson's schema to support custom attributes

2006-09-25 Thread kevin james
Hello All, I'm trying to extend the inetOrgPerson's schema in order to better support our companie's user profile. I 've been doing some googling and I understand that modifications need to be done to the 99users.ldif file, I've tried a couple of settings but I'm unable to see my custom attributes

[Fedora-directory-users] Re: Does userattr="parent[1].attribute#LDAPURL" work ?

2006-09-25 Thread François Beretti
Hi,I seem to have found a workaround (at least for my special case) by using a macro ACI :(targetattr="*")(target="ldap:///cn=*,cn=($dn),o=bug")(version 3.0; acl "Test 2"; allow (all) userdn ="ldap:///o=bug??sub?(nsuniqueid=[$dn])";) This works for my first post, which is my real life problem, wher

[Fedora-directory-users] Confusion over admserv_host_ip_check message

2006-09-25 Thread Dave Della Costa
Hi folks, I'm having a lot of problems getting into the console admin to the server remotely. I'm getting this in the admin-serv/logs/error log (I've changed the IPs below, obviously...they are all the same one FYI): [Mon Sep 25 08:51:57 2006] [notice] [client xxx.xx.xx.xxx] admserv_host_i

[Fedora-directory-users] Re: Does userattr="parent[1].attribute#LDAPURL" work ?

2006-09-25 Thread François Beretti
Hi again,since my first post may be complex, I made a much simpler sample, with standard objects.I created a root suffix 'o=bug'with two ACI:aci: (targetattr="*")(version 3.0; acl "Test"; allow (all)userattr ="description#LDAPURL";) aci: (targetattr="*")(version 3.0; acl "Test"; allow (all)userattr