Re: why posixAccount MUST contain 'cn'?
Michael Ströder <[email protected]> Tue, 16 Dec 2014 23:11:40 +0100
| Newsgroups | gmane.ietf.ldapext |
|---|---|
| Message-ID | <[email protected]> |
Charlie, Charlie wrote: > Michael asked, "Also what's the distinction of 'cn' and 'gecos' in > 'posixAccount'? It seems most NSS LDAP clients use attribute 'cn' as > gecos field today." Ah, someone answers my original question! Thanks! :-) > Today the GECOS field is subfielded, holding multiple data items, Frankly I never saw more things like the user's full name put in the GECOS field or a short description for a demon's system account. My personal usage of finger is 17+ years ago. > I have never seen an LDAP implementation where GECOS and CN were > synonymous. Hmm, one can only have either LDAP attribute 'cn' or 'gecos' appearing as passwd's GECOS field. Anyway this is one more reason to question whether posixAccount (or a future object class serving the same purpose) should have 'cn' (or similar name attribute) as mandatory attribute. In one of my recent setups the NSS LDAP clients can't even read 'cn' or 'gecos'. So "getent passwd" will simply return an empty GECOS field. The system admins are supposed to use LDAP client to find out more about a user's account. Yes, it's a paranoid setup. Ciao, Michael. _______________________________________________ Ldapext mailing list [email protected] https://www.ietf.org/mailman/listinfo/ldapext
smime.p7s
(application/pkcs7-signature, 4.2 KB) - not displayed