Re: Errors in diradmin-1.6.0
Mike Jackson <[email protected]> Sun, 09 Jan 2005 01:01:14 +0200
| Newsgroups | gmane.network.directoryadmin |
|---|---|
| Message-ID | <[email protected]> |
Dieter Kluenter wrote: > > A revised version, complying to ldapv3 and samba3 would be great. It's > about a year ago, I suggested to replace object class account with > extensibleObject in order to overcome the objectclass violation.As the > attribute 'host' would be the only attribute used of object class > account, it would make sense to replace this object class. The LDAPv3 is working now with 1.6.0. RE your suggestion: The problem with the "account" objectclass is that it is the only standard objectclass which provides the "host" attribute, which pam_ldap relies on to do host-based access control, and that it is defined as structural. This is a mistake IMHO, but it would probably be impossible to get the RFC changed. Newer versions of OpenLDAP actually enforce structural integrity, e.g. only allowing one structural objectclass per object. This conflicts with "person", IIRC, which is also structural. If we were to do this right, we would have a "pam_ldap.schema" or something. In order to use pam_ldap host access control, and to comply with structural integrity, we must add new schema to the server, but I don't really like that. I wonder if this has been discussed on the pam_ldap mailing list already. Comments? -- mike ------------------------------------------------------- The SF.Net email is sponsored by: Beat the post-holiday blues Get a FREE limited edition SourceForge.net t-shirt from ThinkGeek. It's fun and FREE -- well, almost....http://www.thinkgeek.com/sfshirt