Hi all,

I'm using qmail-ldap on different servers since about more than one
year. Now I've set up a new one with virtual users environment. My
qmail-installation uses a dedicated account for retrieving
LDAP-attributes and I have set the LDAP ACL very restrictive to prevent
users from seeing other accounts. Mail delivery for normal qmailusers
works very well, but I observe a strange problem with qmailgroups. The
following is derived from slapd's logfile:
qmail binds correctly as the dedicated user to search the mail address.
After the entry with the corresponding address is found, it retrieves
all LDAP Attributes for a normal qmailuser within the existing bind and
therefore succeeds with delivery.
But for a qmailgroup entry  it unbinds and rebinds anonymously and is
then not able to read the attribute "entry" and all other attributes
since this is prohibited by my LDAP-ACLs for anonymous binds.

Can anyone of you experts tell me if this is desired behaviour and why?
Or did I miss a simple configuration option?
Any help greatly appreciated,

Thanks,

Robert

-- 
Robert Müller
Thinxsolutions Müller,Bender,Guth GbR
Maarweg 139
50825 Köln

Fon: +49 221 3550353 0
Fax: +49 221 3550353 99
Mob: +49 179 5303775

[EMAIL PROTECTED]
http://www.thinxsolutions.de

Reply via email to