Re: Object Class Violation
"Manuel Amador (Rudd-O)" <[email protected]> Wed, 03 Aug 2005 19:06:02 -0500
| Newsgroups | gmane.network.directoryadmin |
|---|---|
| Message-ID | <[email protected]> |
El mar, 02-08-2005 a las 21:39 +0200, Dieter Kluenter escribi=C3=B3:
>=20
> You are getting mixed up here. A person may *have* an account, but a
> person *is* not an account. An account may be valid *for* a host, the
> persons data may reside on a host. To describe this host, you may
> include the object class iphost, this object class is auxiliary and
> uses the attribute 'comon name' (cn) to define this host. In order to
> distinguish the users cn and the hosts cn, you may add a tag 'x-' to
> this attribute, that is cn;x-host:=20
Oh, from your POV that's true. But nevertheless it's quite logical to
store both the account attributes and the inetorgperson attributes in
the same LDAP object that *represents* the person. Remember that DA was
designed to serve as directory administrator for both the "white pages"
and the "unix account" requirements.
>=20
> -Dieter
>=20
--=20
Rudd-O <[email protected]>
http://www.amautacorp.com/staff/Rudd-O/