overlay unique in cn=config

2010-06-14 Thread Nick Urbanik
Dear Folks, 1. Can I use the unique overlay with the dynamic cn=config configuration? 2. If so, what is the LDIF syntax for the configuration? 3. Would this work with OpenLDAP 2.3.43? -- Nick Urbanik http://nicku.org 808-71011 nick.urba...@optusnet.com.au GPG: 7FFA CDC7 5A77 0558 DC7A 790A 16D

Re: Tool to covert from LDIF cn=config to slapd.conf?

2010-06-14 Thread Frank Swasey
On 6/13/10 10:34 PM, Howard Chu wrote: Useful feedback is always welcome. Francis' post was self-admittedly not even worth a cup of coffee, and he made this personal a long time ago. If his post had been written from an informed standpoint I would have let it slide. Nor do I believe there was

Re: Posix group with /etc/ldap.conf read priv

2010-06-14 Thread Buchan Milne
On Monday, 14 June 2010 17:03:29 Ariel wrote: > I don't like having the /etc/ldap.conf world readable because then anyone > who has shell access can see our general ldap login credentials (without > which you cannot see anything in the ldap tree). So I have added a > posixgroup in ldap, added o

Re: Posix group with /etc/ldap.conf read priv

2010-06-14 Thread Zdenek Styblik
On 06/14/10 20:54, Ariel wrote: > > On Jun 14, 2010, at 1:56 PM, Aaron Richton wrote: > >> Please keep replies on the list. >> >> On Mon, 14 Jun 2010, Ariel wrote: >> >>> On Jun 14, 2010, at 1:33 PM, Aaron Richton wrote: >>> On Mon, 14 Jun 2010, Ariel wrote: > I don't like havin

Re: Restricting client access using pam_groupdn with dynamic groups : Was[Re: restrict host login based on group]

2010-06-14 Thread Adam Hough
On Mon, Jun 14, 2010 at 12:32 AM, Shamika Joshi wrote: > Ya here it is ...output of slapcat attached. Please let me knw if u could > see anything missing from this. > > Thanks & regards > Shamika > > > > > Howard, I will remember that. I always use the ldap commands normally since I have a 3 way

Re: Best way to merge two local DITs vs empty search base suffix

2010-06-14 Thread Howard Chu
Chris Jacobs wrote: Where is it documented how the conf file slapd.conf file is processed? I've read the documentation, more than once, and still don't know. I suspect this whole 'order thing' is pretty darn important (outside of access config). slapd.conf(5): suffix Specify the DN

Re: How to use BLOB while using Back-NDB

2010-06-14 Thread Howard Chu
Priyesh Potdar wrote: Hi All, I am using back-ndb as a backend for my openldap. I want to know, what is configuration change in slapd.conf I need to make to instruct openldap to always use BLOB and not the VARCHAR. Use attrblob . Apparently this is missing from the manpage. You should file an

Re: Posix group with /etc/ldap.conf read priv

2010-06-14 Thread Ariel
On Jun 14, 2010, at 1:56 PM, Aaron Richton wrote: > Please keep replies on the list. > > On Mon, 14 Jun 2010, Ariel wrote: > >> On Jun 14, 2010, at 1:33 PM, Aaron Richton wrote: >> >>> On Mon, 14 Jun 2010, Ariel wrote: >>> I don't like having the /etc/ldap.conf world readable [...]

Re: Posix group with /etc/ldap.conf read priv

2010-06-14 Thread Aaron Richton
Please keep replies on the list. On Mon, 14 Jun 2010, Ariel wrote: On Jun 14, 2010, at 1:33 PM, Aaron Richton wrote: On Mon, 14 Jun 2010, Ariel wrote: I don't like having the /etc/ldap.conf world readable [...] Advice? And you didn't chmod /etc/passwd and /etc/group too? What if people ge

Re: Posix group with /etc/ldap.conf read priv

2010-06-14 Thread Aaron Richton
On Mon, 14 Jun 2010, Ariel wrote: I don't like having the /etc/ldap.conf world readable [...] Advice? And you didn't chmod /etc/passwd and /etc/group too? What if people get valuable information out of those? You can't do this and be POSIX multi-user; getgr*/getpw* are unprivileged operation

Re: Best way to merge two local DITs vs empty search base suffix

2010-06-14 Thread Quanah Gibson-Mount
--On Monday, June 14, 2010 7:51 AM -0700 Chris Jacobs wrote: Where is it documented how the conf file slapd.conf file is processed? I've read the documentation, more than once, and still don't know. I suspect this whole 'order thing' is pretty darn important (outside of access config). Seri

Posix group with /etc/ldap.conf read priv

2010-06-14 Thread Ariel
I don't like having the /etc/ldap.conf world readable because then anyone who has shell access can see our general ldap login credentials (without which you cannot see anything in the ldap tree). So I have added a posixgroup in ldap, added our shell users to it and did: chown root:usergroup /e

Re: Best way to merge two local DITs vs empty search base suffix

2010-06-14 Thread Chris Jacobs
Where is it documented how the conf file slapd.conf file is processed? I've read the documentation, more than once, and still don't know. I suspect this whole 'order thing' is pretty darn important (outside of access config). Seriously, please me at it. Thanks, - chris Chris Jacobs, Systems A

How to use BLOB while using Back-NDB

2010-06-14 Thread Priyesh Potdar
Hi All, I am using back-ndb as a backend for my openldap. I want to know, what is configuration change in slapd.conf I need to make to instruct openldap to always use BLOB and not the VARCHAR. Thanks, Best Regards, Priyesh Potdar