strategy for getting groupOfNames (AD) and posixAccount (Unix) to coexist?

2014-02-21 Thread Jefferson Davis
This has been beating me like a red-headed stepchild... In the AD world, groupOfNames is expected (in combination with the member attribute, provides for reverse group resolution, ie users by group membership AND groups by member inclusion). On the unix side of the fence, groups REQUIRE a gid

Cyrus IMAPD + virtual domains + SASL + OpenLDAP ldapdb

2014-02-21 Thread Nels Lindquist
I'm attempting to configure Cyrus IMAPD with ldapdb for SASL authentication. As I'm using virtual domains, I need users to be able to authenticate using their e-mail addresses, or just a bare userid for the default domain. I'm having some trouble getting everything working[1]. Based on this docu

Re: Cyrus IMAPD + virtual domains + SASL + OpenLDAP ldapdb

2014-02-21 Thread Dan White
On 02/21/14 13:09 -0700, Nels Lindquist wrote: I'm attempting to configure Cyrus IMAPD with ldapdb for SASL authentication. As I'm using virtual domains, I need users to be able to authenticate using their e-mail addresses, or just a bare userid for the default domain. I'm having some trouble g

Re: strategy for getting groupOfNames (AD) and posixAccount (Unix) to coexist?

2014-02-21 Thread btb
On Feb 21, 2014, at 14.14, Jefferson Davis wrote: > This has been beating me like a red-headed stepchild... > > In the AD world, groupOfNames is expected (in combination with the member > attribute, provides for reverse group resolution, ie users by group > membership AND groups by member incl

Re: strategy for getting groupOfNames (AD) and posixAccount (Unix) to coexist?

2014-02-21 Thread Dieter Klünter
Am Fri, 21 Feb 2014 11:14:12 -0800 (PST) schrieb Jefferson Davis : > This has been beating me like a red-headed stepchild... > > In the AD world, groupOfNames is expected (in combination with the > member attribute, provides for reverse group resolution, ie users by > group membership AND groups

Re: Cyrus IMAPD + virtual domains + SASL + OpenLDAP ldapdb

2014-02-21 Thread Dieter Klünter
Am Fri, 21 Feb 2014 13:09:13 -0700 schrieb Nels Lindquist : > I'm attempting to configure Cyrus IMAPD with ldapdb for SASL > authentication. As I'm using virtual domains, I need users to be able > to authenticate using their e-mail addresses, or just a bare userid > for the default domain. I'm h