On Fri, Mar 17, 2006 at 09:36:08PM +0100, Michael Ströder wrote: > Andreas Hasenack wrote: > > (heimdal 0.7.2, openldap-2.3.20, samba-3.0.21c) > > > > I was playing with heimdal's ldap backend in the hopes of having only > > one password source. Today, in a complete setup, there are three > > sources: > > - userPassword: used for simple binds > > - sambaNTPassword and sambaLMPassword: used for samba > > - kerberos tickets: have their own database > > > > With heimdal, I was able to reduce this to: > > - sambaNTPassword: used for samba and kerberos > > - userPassword: still there > > How about deploying overlay smbk5pwd together with > Password Modify Extended Operation?
That's an option, not to abolish userPassword, but to keep it in sync. That is, I would still have two attributes as the source of passwords. Also, another scenario would be not having samba around: I would have only kerberos and userPassword. --- You are currently subscribed to [email protected] as: [EMAIL PROTECTED] To unsubscribe send email to [EMAIL PROTECTED] with the word UNSUBSCRIBE as the SUBJECT of the message.
