Re: urpmi and ldap
Michael Scherer <[email protected]> Mon, 16 May 2005 20:06:17 +0200
| Newsgroups | gmane.linux.mandrake.server |
|---|---|
| Message-ID | <[email protected]> |
On Monday 16 May 2005 18:37, Buchan Milne wrote: > Michael Scherer wrote: > > Hi. > > As already said on this list, I was working on a ldap enabled > > urpmi. > > > > Well, good news, it works : http://www.zarb.org/~misc/urpmi-ldap/. > > > > Even better, you can deploy it on LE2005/10.2 without patch or > > anything, and update the module without change. In the future, we > > could even place it in a rpm usable on this release. > > > > There is a minimal doc, a schema using private oid, > > Hmm, 1.1.1 isn't really private, quoting from rfc 3383: > > " > To avoid interoperability problems between early implementations > of "works in progress" and implementations of the published > specification (e.g., the RFC), experimental OIDs SHOULD be used in > "works in progress" and early implementations. OIDs under the > Internet Experimental OID arc (1.3.6.1.3.x) may be used for this > purpose. > " > > See attached patch ... Applied by rafael on cvs. We will need to change it to something more official once we ironed all=20 bugs. > > and i didn't tested more > > than urpmq. > > I couldn't urpmi.update until I made the other change in the patch. the cn stuff ? applied too by rgs. I will use a clean openldap server next time. I am not a expert in ldap schema, but cn shouldn't be listed in "must"=20 instead of "may" ? And maybe we should remove the source-name and use cn instead ? > > There is also some know problem, like hdlist being left when you > > change the sources. > > I think a urpmi.clean utility ( something that clean > > /var/lib/urpmi/* from spurious files ) would be a solution, > > > > I will also add the missing features ( autoconfiguration from dns ) > > later once someone ( buchan ) give me guidelines. > > urpmi-ldap should also use upper-case for configuration items from > /etc/openldap/ldap.conf (OpenLDAP libs use upper-case, > nss_ldap/pam_ldap use lower case and fall back to the upper-case ones > AFAIK), or use /etc/ldap.conf > > Since some of the items we might need are not valid for OpenLDAP > libs, I changed to use /etc/ldap.conf ldap.conf is for pam_ldap and the other is for openldap library ? I tought they were the same ? Anyway, I applied to cvs. > For dns-autoconfiguration, I don't think the OpenLDAP libs support it > (but pam_ldap and nss_ldap do to some extent, though I am not sure > about autofs and sudo - which use /etc/ldap.conf as well ...). > > So, I'll need to think about this some more. It would be nice to have a common way to autoconfigure, using srv=20 record, we just need to agree with other people about the name ( and=20 the need ) Either we use srv record to give the server and other informations, or=20 we use the dns to give the url of the file to download with the=20 configuration ( like ie proxy detection http://www.wlug.org.nz/WPAD ). What would be nice also is to use the same system with $ARCH/$VERSION in=20 the ldap config file, especially with the filter. > > Tests, comments, patchs and chocolates welcome. > > Not so sure about chocolates ... but maybe we can arrange a t-shirt > ... I have enough tshirts to wash, but thanks anyway :) > I'll probably have a package by tomorrow that we'll use internally > for our PXE-deployed 10.2. Good. I will try to add some documentation on the wiki, in order to have more=20 test. And to merge the other part of your patch too. =2D-=20 Micha=EBl Scherer On the importance to respond to proposal email : http://www.nntp.perl.org/group/perl.bootstrap/1127