Re: More information on the directory_administrator issue

Guido Trotter <[email protected]> Fri, 23 Jan 2004 16:48:21 +0100
Newsgroups gmane.network.directoryadmin
Message-ID <[email protected]>
On Thu, Jan 15, 2004 at 03:56:53PM -0500, [email protected] wrote:

Hi,

> I found that I can fix the problem by creating a new user via the ldapadd 
> and an ldif.  Have objectclass posixAccount and objectclass inetOrgPerson 
> and in that case I am able to modify that user.  It seems that I need to 
> modify my ldap so that my posixAccount entries are also included with 
> objectclass inetOrgPerson.  Or I can possibly turn the schemacheck off. 
> 
> Is there a simple way to modify my ldap entries so that they are part of 
> objectclass inetOrgPerson?  

No. An LDAP entry cannot be posixAccount and inetOrgPerson at the same
time, without breaking LDAP schema checking rules. The fact that this setup
has worked till now is a bug in openldap > 2.1.x

Directory Administrator needs to be redesigned to support entries
conformant to the LDAP specification. Until then the only possibility is to
disable schema checking rules... :(

Bye,

Guido



-------------------------------------------------------
The SF.Net email is sponsored by EclipseCon 2004
Premiere Conference on Open Tools Development and Integration
See the breadth of Eclipse activity. February 3-5 in Anaheim, CA.
http://www.eclipsecon.org/osdn