Re: add posixGroup to ispmanDomain

ispman-schema-admin-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org Mon, 23 Feb 2004 20:59:46 -0500 (EST)
Newsgroups gmane.comp.isp.ispman.schema
Message-ID <[email protected]>
ispman-schema-admin-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org said:
> On Mon, 2004-02-23 at 13:34, ispman-schema-admin-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
> wrote:
>> Hi I was setting up the ispman server infrastructure and noticed that =
it
>> may be helpful if that when creating a domain that the object class
>> include posixGroup.
>>
>> The first thing that struck me that this is uselful is that if users d=
o
>> get shell access, when logging in though ssh there is no ldap result f=
or
>> searching for the groupname attribute.
>>
>> the ldap search performed when loggin in through ssh is
>> Feb 23 16:28:01 unix slapd[1797]: conn=3D16901 op=3D1 SRCH base=3D"o=3D=
ispman"
>> scope=3D2 filter=3D"(&(objectClass=3DposixGroup))"
>>
>> Would it be harmless to add posixGroup to the objectClass list for
>> domains ?
>
> Not entirely.  The problem is that posixGroup is a structural
> objectClass and there is already another structural, which violated
> schema rules and will not work on OpenLDAP 2.1 and greater, which is
> more restrictive and correct schema rules.
>
I see you are correct. I did try this in the meantime and saw the
violation error. I will try to read up a bit on ldap and try to come up
with an idea, but if anyone else has any ideas on how to properly handle
groups that would be interesting.


-------------------------------------------------------
SF.Net is sponsored by: Speed Start Your Linux Apps Now.
Build and deploy apps & Web services for Linux with
a free DVD software kit from IBM. Click Now!
http://ads.osdn.com/?ad_id=1356&alloc_id=3438&op=click