Re: urpmi and ldap

Michael Scherer <[email protected]> Mon, 16 May 2005 20:06:17 +0200
Newsgroups gmane.linux.mandrake.server
Message-ID <[email protected]>
On Monday 16 May 2005 18:37, Buchan Milne wrote:
> Michael Scherer wrote:
> > Hi.
> > As already said on this list, I was working on a ldap enabled
> > urpmi.
> >
> > Well, good news, it works : http://www.zarb.org/~misc/urpmi-ldap/.
> >
> > Even better, you can deploy it on LE2005/10.2 without patch or
> > anything, and update the module without change. In the future, we
> > could even place it in a rpm usable on this release.
> >
> > There is a minimal doc,  a  schema using private oid,
>
> Hmm, 1.1.1 isn't really private, quoting from rfc 3383:
>
> "
>    To avoid interoperability problems between early implementations
> of "works in progress" and implementations of the published
>    specification (e.g., the RFC), experimental OIDs SHOULD be used in
>    "works in progress" and early implementations.  OIDs under the
>    Internet Experimental OID arc (1.3.6.1.3.x) may be used for this
>    purpose.
> "
>
> See attached patch ...

Applied by rafael on cvs.
We will need to change it to something more official  once we ironed all=20
bugs.

> > and i didn't tested more
> > than urpmq.
>
> I couldn't urpmi.update until I made the other change in the patch.

the cn stuff ?
applied too by rgs. I will use a clean openldap server next time.

I am not a expert in ldap schema, but cn shouldn't be listed in "must"=20
instead of "may"  ?

And maybe we should remove the source-name and use cn instead ?

> > There is also some know problem, like hdlist being left when you
> > change the sources.
> > I think a urpmi.clean utility ( something that clean
> > /var/lib/urpmi/* from spurious files )  would be a solution,
> >
> > I will also add the missing features ( autoconfiguration from dns )
> > later once someone ( buchan ) give me guidelines.
>
> urpmi-ldap should also use upper-case for configuration items from
> /etc/openldap/ldap.conf (OpenLDAP libs use upper-case,
> nss_ldap/pam_ldap use lower case and fall back to the upper-case ones
> AFAIK), or use /etc/ldap.conf
>
> Since some of the items we might need are not valid for OpenLDAP
> libs, I changed to use /etc/ldap.conf

ldap.conf is for pam_ldap and the other is for openldap library ?
I tought they were the same ?

Anyway, I applied to cvs.

> For dns-autoconfiguration, I don't think the OpenLDAP libs support it
> (but pam_ldap and nss_ldap do to some extent, though I am not sure
> about autofs and sudo - which use /etc/ldap.conf as well ...).
>
> So, I'll need to think about this some more.

It would be nice to have a common way to autoconfigure, using srv=20
record, we just need to agree with other people about the name ( and=20
the need )

Either we use srv record to give the server and other informations, or=20
we use the dns to give the url of the file to download with the=20
configuration ( like ie proxy detection http://www.wlug.org.nz/WPAD ).


What would be nice also is to use the same system with $ARCH/$VERSION in=20
the ldap config file, especially with the filter.

> > Tests, comments, patchs and chocolates welcome.
>
> Not so sure about chocolates ... but maybe we can arrange a t-shirt
> ...

I have enough tshirts to wash, but thanks anyway :)

> I'll probably have a package by tomorrow that we'll use internally
> for our PXE-deployed 10.2.

Good.

I will try to add some documentation on the wiki, in order to have more=20
test.  And to merge the other part of your patch too.

=2D-=20
Micha=EBl Scherer

On the importance to respond to proposal email :
http://www.nntp.perl.org/group/perl.bootstrap/1127