Bug#471146: nslcd: refuses to start with rootbinddn in old configuration

2008-03-19 Thread Arthur de Jong
tags 471146 + pending thanks On Mon, 2008-03-17 at 23:12 +0100, Petter Reinholdtsen wrote: I'm afraid that is currently already impossible to simply copy the configuration file because not all options are supported and not all options have the same syntax (e.g. attribute mapping). You

Bug#471146: nslcd: refuses to start with rootbinddn in old configuration

2008-03-18 Thread Arthur de Jong
On Sun, 2008-03-16 at 16:38 +0100, Petter Reinholdtsen wrote: I am not sure if that is the use case for it. The use case I know about is to get passwd passowrd changing working for the root user. For that to work, one also need to store the ldap admin password in clear text on the disk, so I

Bug#471146: nslcd: refuses to start with rootbinddn in old configuration

2008-03-18 Thread Petter Reinholdtsen
[Arthur de Jong] On Sun, 2008-03-16 at 16:38 +0100, Petter Reinholdtsen wrote: I am not sure if that is the use case for it. The use case I know about is to get passwd passowrd changing working for the root user. For that to work, one also need to store the ldap admin password in clear

Bug#471146: nslcd: refuses to start with rootbinddn in old configuration

2008-03-16 Thread Petter Reinholdtsen
Package: libnss-ldapd Version: 0.6 When installing libnss-ldapd on a test machine, and after fixing the issue with double base entries (bug #471131), the nslcd daemon refuses to start because it find the rootbinddn option in /etc/nss-ldapd.conf: minerva:/# /etc/init.d/nslcd restart

Bug#471146: nslcd: refuses to start with rootbinddn in old configuration

2008-03-16 Thread Arthur de Jong
On Sun, 2008-03-16 at 11:14 +0100, Petter Reinholdtsen wrote: When installing libnss-ldapd on a test machine, and after fixing the issue with double base entries (bug #471131), the nslcd daemon refuses to start because it find the rootbinddn option in /etc/nss-ldapd.conf: [...] Why does this

Bug#471146: nslcd: refuses to start with rootbinddn in old configuration

2008-03-16 Thread Petter Reinholdtsen
[Arthur de Jong] The only real usecase of having this option (as far as I know) would be to expose password hashes through passwd and/or shadow lookups for authentication. Using PAM is a much better way to do authentication because you don't have to expose the password hashes at all and can