Re: reducing information duplication

2007-10-27 Thread Pierangelo Masarati
Guillaume Rousse wrote: > I'm not judging code quality (I have absolutly no clue), I'm judging > ease of deployment, and ease of maintainance, both for myself and the > rest of my colleagues. OK, let me try to re-state it in yet another manner. It seems that what you exactly need is collective a

Re: Access Control by group

2007-10-27 Thread Pierangelo Masarati
Jason Dearborn wrote: > Ack. > > Just found this: > http://www.openldap.org/lists/openldap-software/200710/msg00343.html > and this: > http://www.mail-archive.com/openldap-software@openldap.org/msg08524.html > > Looks like other people are trying to work with posixGroups as well. > > > > On 10

Re: extended characterset/binary/base64 support

2007-10-27 Thread Dieter Kluenter
Naufal Sheikh <[EMAIL PROTECTED]> writes: > ok, so what are my options here. I am very new at ldap, and am doing this > migration by installing the > software and copying the config files. Is there any module or library which > needs to be installed to get > this resolved, because this thing is

Re: problem with access by set and group membership (posixgroup, groupofnames)

2007-10-27 Thread Pierangelo Masarati
Dr. Hansjörg Maurer wrote: > I am trying to garnt users access to a group by there group membership. > Because the groups are posixgroups and not groupofnames > I have tried the following ACL's according to > (running openldap-2.3.27-5) > > http://www.openldap.org/faq/data/cache/1133.html > and >

Re: problem with access by set and group membership (posixgroup, groupofnames)

2007-10-27 Thread Pierangelo Masarati
Pierangelo Masarati wrote: >> access to dn.sub="cn=Domain Admins,ou=Groups,dc=byn,dc=drv" >>by set="([uid=] + ([cn=domain >> admins,ou=groups,dc=byn,dc=drv])/memberUid + [,ou=users,dc=byn,dc=drv]) >> & user" write >>by * none You can check if my analysis was correct and, in that

Re: reducing information duplication

2007-10-27 Thread Gavin Henry
Pierangelo Masarati wrote: Guillaume Rousse wrote: I'm not judging code quality (I have absolutly no clue), I'm judging ease of deployment, and ease of maintainance, both for myself and the rest of my colleagues. OK, let me try to re-state it in yet another manner. It seems that what you exa

Re: reducing information duplication

2007-10-27 Thread Gavin Henry
Here, here. Hear, hear! ;-) -- Kind Regards, Gavin Henry. OpenLDAP Engineering Team. E [EMAIL PROTECTED] Community developed LDAP software. http://www.openldap.org/project/

Re: delta-syncrepl replica out of date

2007-10-27 Thread Quanah Gibson-Mount
--On Thursday, October 25, 2007 9:59 PM -0400 Francis Swasey <[EMAIL PROTECTED]> wrote: You don't? Does your accesslog DB keep it's contextCSN updated while the server runs or does it only update the contextCSN when you start slapd? It updates the context CSN every time a modification is mad

Re: delta-syncrepl replica out of date

2007-10-27 Thread Quanah Gibson-Mount
--On Saturday, October 27, 2007 11:14 AM -0700 Quanah Gibson-Mount <[EMAIL PROTECTED]> wrote: Everything's happy. Two other notes. (a) Stopping, then restarting, all CSN's are on sync in the master: [EMAIL PROTECTED] libexec]$ ldapsearch -LLL -x -D "uid=zimbra,cn=admins,cn=zimbra" -h free

Re: Access Control by group

2007-10-27 Thread Jason Dearborn
Quanah pointed out we're running a pretty old version, which could be the culprit. I know + signs in sets aren't supported. I'm slightly less than enthusiastic about upgrading since we rely on LDAP+Samba groups. It's been a few years since I slogged through that implementation, but it may be time