Re: config backend with SASL

2006-09-05 Thread Eran Leiserowitz
Hi, I thought that the rootdn of the config backend is hardcoded to "cn=config". Since this is not the case, can you please give more details regarding your example ? Please notice, that in the test database, I'm only using the "core.schema" schema. So, what exactly should I add to the config f

Re: config backend with SASL

2006-09-05 Thread Pierangelo Masarati
> Hi, > > I thought that the rootdn of the config backend is hardcoded to > "cn=config". Originally, it was. Now it's not. If you're fine with simple bind, then you can use simple bind by adding a "rootpw " statement below the "database config", and binding as the "cn=config" which is the defaul

Howto time expires an Openldap account ?

2006-09-05 Thread LABICHE Alexandre
Hello, I would like to know if I can use somethiing like this in slapd.conf After adding a "Generalized Time" attribut in schema (for example expiredtime) access to attrs=userpassword filter=(expiredtime<=NOW) But how can I implement the function NOW because slapd must evaluate this val

Re: Howto time expires an Openldap account ?

2006-09-05 Thread Pierangelo Masarati
LABICHE Alexandre wrote: I would like to know if I can use somethiing like this in slapd.conf After adding a "Generalized Time" attribut in schema (for example expiredtime) access to attrs=userpassword filter=(expiredtime<=NOW) But how can I implement the function NOW because slapd must

Re: Howto time expires an Openldap account ?

2006-09-05 Thread LABICHE Alexandre
Hello Pierangelo, Thanks for your quick reply and your perfect analyse. To explain what I use in ppolicy is to lock an account at a specific time. Exactly the account is locked because user doesn't change his password after a graceful period. But if he changes his password before graceful peri

Re: Howto time expires an Openldap account ?

2006-09-05 Thread Howard Chu
LABICHE Alexandre wrote: Hello Pierangelo, Thanks for your quick reply and your perfect analyse. To explain what I use in ppolicy is to lock an account at a specific time. Exactly the account is locked because user doesn't change his password after a graceful period. But if he changes his pas