DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUGĀ·
RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT
<http://issues.apache.org/bugzilla/show_bug.cgi?id=40075>.
ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED ANDĀ·
INSERTED IN THE BUG DATABASE.

http://issues.apache.org/bugzilla/show_bug.cgi?id=40075

           Summary: unable to use ldap groups that contain DNs and usernames
                    for AuthZ
           Product: Apache httpd-2
           Version: 2.2.2
          Platform: Other
               URL: http://www-personal.umich.edu/~canna/mod_authnz_ldap-
                    UMICH.diff
        OS/Version: Linux
            Status: NEW
          Severity: enhancement
          Priority: P2
         Component: mod_authz_ldap
        AssignedTo: [email protected]
        ReportedBy: [EMAIL PROTECTED]


We have identities at the University of Michigan that don't have their own 
entries in
our LDAP directory, but they do appear in groups. This brings up a
few issues in regards to authorization with mod_authnz_ldap:

1) We'd like some way to say "if we can't find a DN
for this identity, that's OK."

2) Since some of our users are in the directory ( have a person
entry ) and some are not,  AuthLDAPGroupAttributeisDN is not rich
enough for us. Many of our groups contain both DNs and usernames.
We'd like to extend "AuthLDAPGroupAttribute" to say whether the
attribute in question is a DN or username, and thus be able to
authorize both DNs and usernames for the same resource.

-- 
Configure bugmail: http://issues.apache.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.

---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to