server-side sub-search

2013-01-30 Thread Benin Technologies
Hi, Is it possible to do a server-side sub-search before returning the data to the client ? Let's say I have this tree : ---> dc=com | |-->dc=mycompany | | --> cn=Jane Doe |

indexing with mdb

2013-01-30 Thread anil beniwal
Hi i am using openldap 2.4.33 on rhel 6.3 with large mdb database size. We are using it for last few weeks, now we want to add index few attributes. What approach we should take, so that there is no downtime. How we can check the status if indexing is complete or not ? with both dynamic and s

problem with ldap group check in squid

2013-01-30 Thread Fuhrmann, Marcel
Hello, i'm trying to to configure squid to use a ldap (ADS 2008) group check to give access to the internet. The squid mailing list couldn't help me. Maybe you can. /usr/lib64/squid/squid_ldap_group -d -v3 -b 'ou=OU3,ou=OU2,ou=OU1,dc=DOMAIN,dc=LOCAL' -f \ '(&(sAMAccountName=%v)(memberOf=cn=%a,o

Re: missing entry in slapcat backup

2013-01-30 Thread Meike Stone
Hello Andrew, > > Dryrun won't be able to detect missing structural entries: that > requires a database. Even an internal list of DNs is not > enough, as the actual entries have to be available in order to > check things like schema and content rules. > > To be a valid test you really have to impor

Re: Access control

2013-01-30 Thread Philip Colmer
Thank you, Andrew, for that clear example and explanation. I have successfully implemented this now. Regards Philip On 30 January 2013 08:00, Andrew Findlay wrote: > On Thu, Jan 24, 2013 at 12:22:18PM +, Philip Colmer wrote: > > > What I want/need to be able to do is for LDAP to read the

Re: Access control

2013-01-30 Thread Andrew Findlay
On Thu, Jan 24, 2013 at 12:22:18PM +, Philip Colmer wrote: > What I want/need to be able to do is for LDAP to read the DN of the group that > has permission, in the same what that it does with dnattr. I thought that I > had > read something about this being possible with sets, but slapd.acces

Re: missing entry in slapcat backup

2013-01-30 Thread Andrew Findlay
On Mon, Jan 28, 2013 at 12:15:19PM +0100, Meike Stone wrote: > I think, it would be a great thing to test the slapcat file (after > dumping it) instantly. Testing backups is always wise... > So as reported in > http://www.openldap.org/lists/openldap-technical/201301/msg00254.html > I tried to do

RE: Kerberos/LDAP integration

2013-01-30 Thread Asmaa Ahmed
Hi, Actually I found it like that in pam_ldap.conf without any modification from my side and changed as described coz I had the same error beforeBut looks didn't work any way! # Another way to specify your LDAP server is to provide anuri ldapi:///ldap.domain.com# Unix Domain Sockets to connect