Re: Fwd: Directory administrator 1.5 release announcement

Tarjei Huse <[email protected]>
Newsgroups gmane.network.directoryadmin
Message-ID <[email protected]>
Adam Williams wrote:

> I agree, but there is no way to save "host" functionality in OpenLDAP
>
>2.1.x without extending the schema. [Altering the schema is wrong].  It
>is up the DA developer(s) to determine the right path.  I'd prefer
>dropping the "account" objectclass.
>
+1

>
>>You mean to create an inventory of the machines?  This would be great.  What do
>>you recommend?  Are there object classes for the purpose?  If the machines have
>>been created, I don't find it's problem to modify DA to let the user add/remove
>>hosts/machines from an user's allowed list, grabbing the existing machine list.
>>    
>>

There's a few different uses for this, I would suggest we define some 
machine "roles" and try to work out what is needed for each role:
-> DHCP, DNS integration -> defining ips and hostnames in the directory
-> Kerberos principals -> heimdal has LDAP support so integrating 
everything into an heimdal directory would be great. However, this would 
have to be part of an larger kerberos patch to DA.
-> LTSP-clients (www.ltsp.org)  has a patch for using ldap to add 
clientsetups.
-> Samba machineaccounts. I belive 3.0 stores this in a private database 
outside the directory. Administering it should be possible some way.

I'm not good for coding, but I may volunteer to write the documentation 
needed to teach people to integrate the different systems (DNS,DHCP, 
Kerberos etc). As DA develops, documenting this will be a need.

tarjei


>There are lots of schema to do this; "ipHost", for one.  Samba PDC,
>Kerberos, etc..., already require machines to exist in the Dit.  
>
>We even use the dnsZone schema so that bind (DNS server) has all of the
>zone information in LDAP.
>
>But for the purpose of creating a general purpose tool it would be nice
>to have as few Dit requirements as possible.
>
>Login access can be controlled by membership in posixGroups,  which NSS
>supports - I recommend this approach.  People simply need to configure
>their authentication accordingly.
>
>
>
>-------------------------------------------------------
>This SF.Net email is sponsored by: INetU
>Attention Web Developers & Consultants: Become An INetU Hosting Partner.
>Refer Dedicated Servers. We Manage Them. You Get 10% Monthly Commission!
>INetU Dedicated Managed Hosting http://www.inetu.net/partner/index.php
>_______________________________________________
>Directoryadmin-list mailing list
>[email protected]
>https://lists.sourceforge.net/lists/listinfo/directoryadmin-list
>  
>




-------------------------------------------------------
This SF.Net email is sponsored by: INetU
Attention Web Developers & Consultants: Become An INetU Hosting Partner.
Refer Dedicated Servers. We Manage Them. You Get 10% Monthly Commission!
INetU Dedicated Managed Hosting http://www.inetu.net/partner/index.php
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.