Re: Fwd: Directory administrator 1.5 release announcement
Tarjei Huse <[email protected]>
| Newsgroups | gmane.network.directoryadmin |
|---|---|
| Message-ID | <[email protected]> |
Adam Williams wrote: > I agree, but there is no way to save "host" functionality in OpenLDAP > >2.1.x without extending the schema. [Altering the schema is wrong]. It >is up the DA developer(s) to determine the right path. I'd prefer >dropping the "account" objectclass. > +1 > >>You mean to create an inventory of the machines? This would be great. What do >>you recommend? Are there object classes for the purpose? If the machines have >>been created, I don't find it's problem to modify DA to let the user add/remove >>hosts/machines from an user's allowed list, grabbing the existing machine list. >> >> There's a few different uses for this, I would suggest we define some machine "roles" and try to work out what is needed for each role: -> DHCP, DNS integration -> defining ips and hostnames in the directory -> Kerberos principals -> heimdal has LDAP support so integrating everything into an heimdal directory would be great. However, this would have to be part of an larger kerberos patch to DA. -> LTSP-clients (www.ltsp.org) has a patch for using ldap to add clientsetups. -> Samba machineaccounts. I belive 3.0 stores this in a private database outside the directory. Administering it should be possible some way. I'm not good for coding, but I may volunteer to write the documentation needed to teach people to integrate the different systems (DNS,DHCP, Kerberos etc). As DA develops, documenting this will be a need. tarjei >There are lots of schema to do this; "ipHost", for one. Samba PDC, >Kerberos, etc..., already require machines to exist in the Dit. > >We even use the dnsZone schema so that bind (DNS server) has all of the >zone information in LDAP. > >But for the purpose of creating a general purpose tool it would be nice >to have as few Dit requirements as possible. > >Login access can be controlled by membership in posixGroups, which NSS >supports - I recommend this approach. People simply need to configure >their authentication accordingly. > > > >------------------------------------------------------- >This SF.Net email is sponsored by: INetU >Attention Web Developers & Consultants: Become An INetU Hosting Partner. >Refer Dedicated Servers. We Manage Them. You Get 10% Monthly Commission! >INetU Dedicated Managed Hosting http://www.inetu.net/partner/index.php >_______________________________________________ >Directoryadmin-list mailing list >[email protected] >https://lists.sourceforge.net/lists/listinfo/directoryadmin-list > > ------------------------------------------------------- This SF.Net email is sponsored by: INetU Attention Web Developers & Consultants: Become An INetU Hosting Partner. Refer Dedicated Servers. We Manage Them. You Get 10% Monthly Commission! INetU Dedicated Managed Hosting http://www.inetu.net/partner/index.php