Re: Object Class Violation

"Manuel Amador (Rudd-O)" <[email protected]> Wed, 03 Aug 2005 19:06:02 -0500
Newsgroups gmane.network.directoryadmin
Message-ID <[email protected]>
El mar, 02-08-2005 a las 21:39 +0200, Dieter Kluenter escribi=C3=B3:

>=20
> You are getting mixed up here. A person may *have* an account, but a
> person *is* not an account. An account may be valid *for* a host, the
> persons data may reside on a host. To describe this host, you may
> include the object class iphost, this object class is auxiliary and
> uses the attribute 'comon name' (cn) to define this host. In order to
> distinguish the users cn and the hosts cn, you may add a tag 'x-' to
> this attribute, that is cn;x-host:=20

Oh, from your POV that's true.  But nevertheless it's quite logical to
store both the account attributes and the inetorgperson attributes in
the same LDAP object that *represents* the person.  Remember that DA was
designed to serve as directory administrator for both the "white pages"
and the "unix account" requirements.

>=20
> -Dieter
>=20
--=20
                Rudd-O          <[email protected]>
                http://www.amautacorp.com/staff/Rudd-O/