Re: Object Class Violation

Mike Jackson <[email protected]> Wed, 03 Aug 2005 23:30:57 +0300
Newsgroups gmane.network.directoryadmin
Message-ID <[email protected]>
Richard Bullington-McGuire wrote:

> The thing is, OpenLDAP is very widely deployed.

I know. It was previously the only free thing available, like it or not.


> As I see it, DA could 
> take one of three basic strategies:
> 
> 1. Continue with the status quo. DA is incompatible with OpenLDAP 2.2 
> with schema cheking on. Anyone who attempts to use it in this 
> configuration will probably be frustrated and move on to use a different 
> tool.

I understand, and it's no sweat off my back. I am not trying to become 
world famous :-)




> 2. Inform users of OpenLDAP 2.2 that to use DA, they must disable schema 
> checking by setting "schemacheck off". Explain the reasons why this 
> needs to happen, preferably without much venom. It's just a tool, after 
> all. Plenty of other projects do this in their example configuration 
> files for OpenLDAP, here's two examples:
> 
> http://www.opengroup.org/messaging/G260/tech9.htm
> http://www-fp.globus.org/gt2.4/replica.html
> 
> 3. Adapt DA so that dealing with the person-based attributes is 
> optional. It's easy enough to write a detection routine that will figure 
> out whether those classes are present and combinable with the acccount 
> objectclass. If they are not, just omit or disable the portions of the 
> UI that deal with those attributes.
> 
> I'd prefer adopting strategy 2 immediately, and striving for 3 in the 
> medium-to-long term.

That is the strategy which we will take. I put a note in the website 
about #2, and I asked Fredrik to write a patch for #3. If he doesn't do 
it, then I will get around to it.

BR,
--
mike