Re: add posixGroup to ispmanDomain
ispman-schema-admin-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org Mon, 23 Feb 2004 20:59:46 -0500 (EST)
| Newsgroups | gmane.comp.isp.ispman.schema |
|---|---|
| Message-ID | <[email protected]> |
ispman-schema-admin-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org said: > On Mon, 2004-02-23 at 13:34, ispman-schema-admin-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org > wrote: >> Hi I was setting up the ispman server infrastructure and noticed that = it >> may be helpful if that when creating a domain that the object class >> include posixGroup. >> >> The first thing that struck me that this is uselful is that if users d= o >> get shell access, when logging in though ssh there is no ldap result f= or >> searching for the groupname attribute. >> >> the ldap search performed when loggin in through ssh is >> Feb 23 16:28:01 unix slapd[1797]: conn=3D16901 op=3D1 SRCH base=3D"o=3D= ispman" >> scope=3D2 filter=3D"(&(objectClass=3DposixGroup))" >> >> Would it be harmless to add posixGroup to the objectClass list for >> domains ? > > Not entirely. The problem is that posixGroup is a structural > objectClass and there is already another structural, which violated > schema rules and will not work on OpenLDAP 2.1 and greater, which is > more restrictive and correct schema rules. > I see you are correct. I did try this in the meantime and saw the violation error. I will try to read up a bit on ldap and try to come up with an idea, but if anyone else has any ideas on how to properly handle groups that would be interesting. ------------------------------------------------------- SF.Net is sponsored by: Speed Start Your Linux Apps Now. Build and deploy apps & Web services for Linux with a free DVD software kit from IBM. Click Now! http://ads.osdn.com/?ad_id=1356&alloc_id=3438&op=click