Re: [osol-discuss] root roles security holes

2010-07-30 Thread Doug Leavitt
The LDAP code is much more sophisticated that it once was, especially as it applies to the management of connections and LDAP server connection failure situations. If LDAP naming is enabled, and access to a server is unavailable the system is expected to respond properly and not hang on lookups.

Re: [osol-discuss] PAM with LDAP to login, changing reverse mapping?

2010-04-13 Thread Doug Leavitt
The get passwd by uid equivalent of get passwd by name where get passwd by name from the web link below is: passwd ((objectclass=posixaccount)(uid=%s)) is: passwd ((objectClass=posixAccount)(uidNumber=%ld) When SSDs are used objectClass=posixAccount is replaced by the SSD filter in

Re: [osol-discuss] SUNWopenldap doesn't start from smf

2010-01-25 Thread Doug Leavitt
FYI: CR 6766826 already exists for this issue and the fix is in the process of being tested at the moment. The default slapd.conf file (and corresponding manifest tweek) will place slapd.pid in /var/run vs /var/run/openldap where it should have been originally. The manifest (and slapd)

[osol-discuss] New packages added to the /pending repository

2009-01-27 Thread Doug Leavitt
Another round of 9659 software packages have been delivered to the /pending repository: http://pkg.opensolaris.org/pending/en/index.shtml Bringing the total to 11367 unique packages in the /pending repository. In this delivery, the majority of these packages are perl modules built against the

Re: [osol-discuss] [sysadmin-discuss] Configuring two nsswitch backends like LDAP and NIS?

2008-03-20 Thread Doug Leavitt
Having two major naming services in the same configuration has never been a Sun supported configuration. Primarily because the naming service administration tools do not deal with this. One of the objectives of the duckwater project is to fix the naming configuration and management issue, which

[osol-discuss] Re: Project Proposal: JDS Single System Administration

2006-06-23 Thread Doug Leavitt
I'll second this from the Duckwater team. This message posted from opensolaris.org ___ opensolaris-discuss mailing list opensolaris-discuss@opensolaris.org

[osol-discuss] Re: Project Proposal: Duckwater (Simplified Name Services Management)

2006-04-06 Thread Doug Leavitt
I second this project as well. Improvements in this area are long overdue. Doug. This message posted from opensolaris.org ___ opensolaris-discuss mailing list opensolaris-discuss@opensolaris.org

[osol-discuss] Re: Re: Project Proposal: Duckwater (Simplified Name Services Management)

2006-04-06 Thread Doug Leavitt
To elaborate a little bit more on what Anup said, the sparks project is focusing more on the framework and API level issues surrounding naming services, whereas the Duckwater project is focusing more on the management of the framework and the interactions of managing that framework in