Re: OpenLDAP UTF8 values support

2018-03-22 Thread Andrew Findlay
in the LDAP mail attribute, which should be just LHS@RHS.domain Andrew -- ----------- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: LDAP Account expiry

2018-03-17 Thread Andrew Findlay
ot;interesting" behaviour when replication is involved. Andrew -- ----------- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: Using virtual IP and N-way mutlimaster mode

2018-01-24 Thread Andrew Findlay
ld probably want to keep it for that. Andrew -- ----------- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: Using virtual IP and N-way mutlimaster mode

2018-01-24 Thread Andrew Findlay
to specify the server ID so that it can go the other way through the config, convert ID to FQDN, and drop that FQDN from the set of replication sources? Andrew -- ----------- | From Andrew Findlay, Skills 1st Ltd

Re: Using virtual IP and N-way mutlimaster mode

2018-01-24 Thread Andrew Findlay
Anyway, running with fully-replicated config makes it even more important to have a good solution to the problem I described. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large

Re: Using virtual IP and N-way mutlimaster mode

2018-01-24 Thread Andrew Findlay
ncing/failover in this environment would be done separately ] Andrew -- ------- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services |

Re: Antw: Re: [Q] amendments to schemes existent

2017-10-20 Thread Andrew Findlay
On Fri, Oct 20, 2017 at 01:08:01PM +0300, Zeus Panchenko wrote: > 1. search works with filter: (authorizedService=mail@hh001.umidb) >(and without index it returns empty result) That is odd. Th eindex should only be a performance thing - it should not change the results at all. You need to be

Re: Antw: Re: [Q] amendments to schemes existent

2017-10-19 Thread Andrew Findlay
ry=finance)(dhcpOption:caseIgnoreSubstringsMatch:=boot*)) Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills

Re: [Q] amendments to schemes existent

2017-10-18 Thread Andrew Findlay
ity. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

LDAPCon 2017 programme now online

2017-08-11 Thread Andrew Findlay
2017. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: ppolicy issues

2017-08-08 Thread Andrew Findlay
Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: Openldap Configuration issues

2017-08-08 Thread Andrew Findlay
ple,dc=com" mech=SIMPLE ssf=0 Aug 8 17:48:33 owl slapd[616]: conn=1282270 op=105 RESULT tag=97 err=0 text= Finally the password is checked by binding to LDAP using the account DN and password as credentials. Andrew -- ---

Re: Openldap Configuration issues

2017-08-07 Thread Andrew Findlay
. This will tell you what the app is actually doing. Andrew -- ----------- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: [Q] "selective" ACL

2017-06-29 Thread Andrew Findlay
oupOfNames then you could use the memberof overlay to reflect membership into an attribute of the user entry. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: syncrepl fails after upgrade to openldap 2.4.45

2017-06-29 Thread Andrew Findlay
onfig file (probably /etc/ldap/ldap.conf). I seem to remember a change in behaviour of OpenSSL libs a while ago where I was bitten by something similar. Maybe Juergen's earlier setup used ldap.conf and the new one is ignoring it? Andrew -- -------

Re: [Q] can I replicate several branches to the same slave from one master?

2017-06-29 Thread Andrew Findlay
On Thu, Jun 29, 2017 at 03:47:07PM +0100, Andrew Findlay wrote: > I suspect part of the trouble is that you have two syncrepl clauses using the > same search base on the same master. The timestamps are likely to be stored > in the same place, causing a clash. > > One definite er

Re: [Q] can I replicate several branches to the same slave from one master?

2017-06-29 Thread Andrew Findlay
ncrepl rid=123 > provider=ldap://master.example:389 > starttls=critical > searchbase="ou=ABC,ou=Sendmail,dc=example" > bindmethod=simple > binddn="uid=replABC,ou=repl,dc=example" > credentials="***" > tls_cacert=/usr/local/etc/openldap/ssl/ca.crt > tls_ce

Re: Permission issue for normal user with ldap_add

2017-01-23 Thread Andrew Findlay
rew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: LDAP search rule to find group owners

2017-01-20 Thread Andrew Findlay
gather up all the ownerOf values. To be really cute you could add the dynlist overlay to do this for you... Andrew -- ----------- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scal

Re: Slapd.conf for doing stress

2017-01-20 Thread Andrew Findlay
s... Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: Searches with dereferncing causing high CPU load.

2015-11-18 Thread Andrew Findlay
that 64k aliases would trigger a problem, or is something else going on here? Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory

Re: Searches with dereferncing causing high CPU load.

2015-11-17 Thread Andrew Findlay
view of your data that it can cope with. Does the app need to modify LDAP data or is it read-only? Andrew -- ------- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems,

Re: Searches with dereferncing causing high CPU load.

2015-11-16 Thread Andrew Findlay
ld be worth checking that you have indexed the objectclass attribute. I prefer to avoid aliases... Andrew -- ------- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, a

Re: ldiftopasswd: Can it be done with SSHA hashes?

2015-11-05 Thread Andrew Findlay
he only thing that needs to care about hash formats is the LDAP server process. Andrew -- ------- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: Allowing users to update their passwords

2015-10-13 Thread Andrew Findlay
lcPasswordHash: {CRYPT} olcPasswordCryptSaltFormat: "$6$%.12s" It should be added to the olcDatabase=frontend,cn=config entry. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: SSL based LDAP client verification

2015-10-08 Thread Andrew Findlay
hines only need a copy of the CA cert to verify trust. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.s

Re: New User unable to authenticate on new client

2015-10-06 Thread Andrew Findlay
ou have the basic service working you can start thinking about ACLs. You may then want to define an account for your Linux client machines to use when accessing LDAP so that you don't have to give anon access to your data. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: uniqueness unique_uri specification help

2015-09-14 Thread Andrew Findlay
tribute (e.g. if the new one is mixed case and the existing one is all upper case). It would still be wise to load the data through LDAP rather than using slapadd, but the process will be much slower. How many entries do you have? Do you run multiple LDAP servers? Andrew -- --------

Re: OpenLDAP error - ldap_sasl_bind(SIMPLE): Can't contact LDAP server (-1)

2015-09-14 Thread Andrew Findlay
_host: lines. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

LDAPCon 2015 booking now open

2015-09-09 Thread Andrew Findlay
! There are opportunities for commercial sponsorship that will be of interest to companies working in related areas. See http://ldapcon.org/2015/?page_id=101 for details. Andrew Findlay Conference Chairman Thanks to our sponsors for their support. Our first Platinum sponsor: Symas http

Re: ldapmodrdn accented characters with windows client

2015-09-09 Thread Andrew Findlay
ing like iconv to process the command-line args and input files: iconv --from-code=CP1250 --to-code=UTF-8 /path/to/inputfile Andrew -- ------- | From Andrew Findlay, Skills 1st Ltd | | Consultant

Re: load balancer

2015-09-02 Thread Andrew Findlay
run an instance of it on every client machine if you need to. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.s

Re: disable simple paged results control support?!

2015-09-02 Thread Andrew Findlay
client during testing. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: Replication speed and data sizing (mdb)

2015-08-12 Thread Andrew Findlay
if run on a server that has a heavy write load at the time. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http

Re: Adding Members to Groups

2015-08-12 Thread Andrew Findlay
-- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | --- Network Working Group

A new open-source TLS implementation

2015-07-02 Thread Andrew Findlay
-- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: group email addresses

2015-06-20 Thread Andrew Findlay
of the mailing list as well as the address of the list. The Postfix LDAP README has some ideas about how you might set this up: http://www.postfix.org/LDAP_README.html#example_group Andrew -- --- | From Andrew Findlay

Re: group email addresses

2015-06-20 Thread Andrew Findlay
-- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

LDAPCon 2015 submission deadline approaching

2015-06-19 Thread Andrew Findlay
-- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: group email addresses

2015-06-18 Thread Andrew Findlay
the list. If the MTA cannot do this two-stage process itself, you could consider using the dynlist overlay in slapd to collect the members' mail addresses into the group entry itself. Andrew -- --- | From Andrew

Re: getent passwd only catch local user passwd

2015-04-30 Thread Andrew Findlay
nscd. It is not helpful when sssd is in use, and can cause great confusion and problems of its own. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks

Re: getent passwd only catch local user passwd

2015-04-29 Thread Andrew Findlay
or CentOS mailing list or forum. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk

Re: Antw: Re: Slapd running very slow

2015-04-28 Thread Andrew Findlay
transaction to finish and report back before queuing the next one... Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http

Re: All entries belong to the top object class?

2015-04-28 Thread Andrew Findlay
. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: Ldap challenge

2015-04-27 Thread Andrew Findlay
with sensible values to work with then you will have to maintain a parallel or overlay directory service. There are several ways to do that, so let's start by establishing what you have! Andrew -- --- | From Andrew Findlay

Re: All entries belong to the top object class?

2015-04-27 Thread Andrew Findlay
Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: separate loglevels for different databases?

2015-04-27 Thread Andrew Findlay
-- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: Ldap challenge

2015-04-27 Thread Andrew Findlay
-- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: All entries belong to the top object class?

2015-04-21 Thread Andrew Findlay
attributes that you want to use. LDAP does not support 'present but empty' attributes, so there must be a non-null value in each MUST attribute. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd

LDAPCon 2015

2015-04-21 Thread Andrew Findlay
/2015/ Contacts General enquiries: enquir...@lists.ldapcon.org Paper/Tutorial submissions:submissions2...@lists.ldapcon.org -- --- | From Andrew Findlay, Skills 1st Ltd

Re: i am new to ldap plz help i have provided ldif file and simple authentication code

2015-02-12 Thread Andrew Findlay
trivial BEFORE doing the tests. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk

Re: plz provide me any simple authentication code in ldap

2015-02-06 Thread Andrew Findlay
On Fri, Feb 06, 2015 at 10:42:45AM +0530, Bharath K wrote: To: Andrew Findlay andrew.find...@skills-1st.co.uk Please keep your replies on-list so that others with similar problems can learn from the archive. Subject: Re: plz provide me any simple authentication code in ldap i configured

Re: Openldap migration from 2.4.11 to 2.4.40 for 4-way multimaster servers

2015-02-05 Thread Andrew Findlay
-- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: plz provide me any simple authentication code in ldap

2015-02-05 Thread Andrew Findlay
, and by the olcLogLevel attribute of cn=config if you are using slapd-config. File based: loglevel stats stats2 or in LDIF: dn: cn=config ... olcLogLevel: stats stats2 Andrew -- --- | From Andrew Findlay, Skills 1st Ltd

Re: bind UID in DN instead of CN

2015-02-04 Thread Andrew Findlay
Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: Large Number of Transactions x Low performance

2015-01-30 Thread Andrew Findlay
to add. It should be very quick. Also look at your replication setup. With this sort of data you really do need delta mode. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large

LDAPCon 2015 Call for Papers

2015-01-29 Thread Andrew Findlay
/Tutorial submissions:submissi...@lists.ldapcon.org -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills

Re: Antw: Re: OpenLDAP Replication Issue

2015-01-23 Thread Andrew Findlay
will only probably solve the problem, why must he update? ;-) Because until he does, people on this list will assume that the problem is due to a bug that has already been fixed. Andrew -- --- | From Andrew Findlay

Re: I am new to ldap and i dont know much about ldap simple authentication could you plz help me and give some suggestions......and below is the simple code which i tried and ther is also uid test 12

2015-01-23 Thread Andrew Findlay
Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: OpenLDAP Replication Issue

2015-01-23 Thread Andrew Findlay
-- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: OpenLDAP Replication Issue

2015-01-22 Thread Andrew Findlay
libraries. LMDB (database mdb) is highly recommended. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills

Re: LDAP Search with non-existent attributes

2015-01-20 Thread Andrew Findlay
not. It would be interesting to have more detail on exactly what you did and what results you found. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems

Re: back-sql deployment woes

2015-01-15 Thread Andrew Findlay
: limited ACLs, fundamental mismatch in data model, poor performance and resource usage when compared with back-mdb etc... Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large

Re: Can't contact LDAP server (-1) additional info: error:14077410:SSL routines :SSL23_GET_SERVER_HELLO:sslv3 alert handshake failure

2014-11-22 Thread Andrew Findlay
config so ldaps: will not work. Quick test: ldapmodify -x -h ldap://server/ -W -D 'cn=root,dc=ier,dc=hit-u,dc=ac,dc=jp' Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant

Re: slapd read_config / interface bind errors

2014-11-20 Thread Andrew Findlay
one of those interfaces twice. Note also that you should be using fully-qualified domain names everywhere. Simple hostnames will not work properly with TLS. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd

Re: debugging OpenLDAP client

2014-11-19 Thread Andrew Findlay
Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: any help on ldap_sasl_bind_s failed (53)

2014-11-19 Thread Andrew Findlay
DIGEST-MD5 anyway, as it requires the server to store the password in cleartext rather than hashed. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks

Re: adding VLV support to OpenLDAP 2.4.31

2014-11-12 Thread Andrew Findlay
this is not something to be undertaken until you are more familiar with OpenLDAP. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services

Re: adding VLV support to OpenLDAP 2.4.31

2014-11-12 Thread Andrew Findlay
software then hdb may be safer. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk

Re: export directory in LDIF format

2014-11-11 Thread Andrew Findlay
in the config go through NFS or automount points? Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills

Re: adding VLV support to OpenLDAP 2.4.31

2014-11-11 Thread Andrew Findlay
-- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: LDAP Crafted Search Request Access Allowed

2014-10-31 Thread Andrew Findlay
databases into LDIF files then configure new MDB databases and slapadd the data. You will find that loading MDB with slapadd -q is extremely fast. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd

Re: LDAP Crafted Search Request Access Allowed

2014-10-30 Thread Andrew Findlay
deprecated for some time now. I would suggest using MDB. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http

Re: LDAP Crafted Search Request Access Allowed

2014-10-29 Thread Andrew Findlay
-- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: LDAP Crafted Search Request Access Allowed

2014-10-28 Thread Andrew Findlay
-- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: LDAP Crafted Search Request Access Allowed

2014-10-28 Thread Andrew Findlay
-- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: LDAP Crafted Search Request Access Allowed

2014-10-28 Thread Andrew Findlay
-- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: Openldap for proxy AD

2013-11-22 Thread Andrew Findlay
should help you to isolate the problem. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk

Re: separate login/password for several services?

2013-09-30 Thread Andrew Findlay
-- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: OpenLDAP duplication

2013-09-30 Thread Andrew Findlay
.500 are designed.  Is there any option to prevent it. ? Use the 'unique' overlay: http://www.openldap.org/doc/admin24/overlays.html#Attribute%20Uniqueness Andrew -- --- | From Andrew Findlay, Skills 1st

Re: separate login/password for several services?

2013-09-27 Thread Andrew Findlay
to fill in those attributes. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk

Re: separate login/password for several services?

2013-09-27 Thread Andrew Findlay
-- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: separate login/password for several services?

2013-08-09 Thread Andrew Findlay
to add the objectclass 'domainRelatedObject' as well. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http

Re: separate login/password for several services?

2013-08-09 Thread Andrew Findlay
On Fri, Aug 09, 2013 at 05:53:57PM +0300, Zeus Panchenko wrote: To: Andrew Findlay andrew.find...@skills-1st.co.uk Please keep replies on the list so that they become searchable and everyone can benefit. here is the diagram depicting what I am thinking about while talking :) https

Re: adding mail objectClass to schema

2013-08-02 Thread Andrew Findlay
on your own institution's allocation, but that is not critical at this stage. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services

Re: separate login/password for several services?

2013-08-02 Thread Andrew Findlay
)(authorizedService=smtp)) Your POP3 server would issue searches of the form: ((uid=USERNAME)(authorizedService=pop3)) Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant

Re: olcAccess best practices

2013-08-02 Thread Andrew Findlay
: http://www.skills-1st.co.uk/papers/ldap-acls-jan-2009/ Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http

Re: SSHA as default password-hash in next password change

2013-06-05 Thread Andrew Findlay
to nearer 12,000 guesses per second. If your LDAP database gets compromised or someone steals your backup tapes then that extra protection could be very valuable. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd

Re: SSHA as default password-hash in next password change

2013-06-04 Thread Andrew Findlay
-- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: Substring Indexes on userPassword Attribute

2013-06-04 Thread Andrew Findlay
). Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: Substring Indexes on userPassword Attribute

2013-06-03 Thread Andrew Findlay
userPassword and uid at the same time. The LDIF parser will take care of the Base-64 for you as well. You should be able to do the whole job in less than 20 lines of Perl or Python. Andrew -- --- | From Andrew

Re: Substring Indexes on userPassword Attribute

2013-06-03 Thread Andrew Findlay
said that, you still might be able to do substring searches on some of these attributes by using 'matching rule assertion' rather than 'attribute-value assertion' forms - see RFC4515. Andrew -- --- | From Andrew

Re: index on attribute in acl filter

2013-05-10 Thread Andrew Findlay
on pwdAccountLockedTime would be beneficial, but would it help for an acl filter? An index is very unlikely to make any difference to the ACL you propose. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd

Re: ACL on create questions

2013-05-02 Thread Andrew Findlay
-- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: Modern Password Hashes in Openldap?

2013-05-01 Thread Andrew Findlay
is in the ldif file. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44

Re: LDAP proxy

2013-04-19 Thread Andrew Findlay
in the Admin Guide. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk

Re: missing entry in slapcat backup

2013-02-01 Thread Andrew Findlay
when extended into swap, I would expect this to be faster than a normal filesystem as it does not have to take precautions to recover after a crash. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd

Re: Access control

2013-02-01 Thread Andrew Findlay
owners to write, nothing to everyone else. With the change given above, that bit should work. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks

Re: missing entry in slapcat backup

2013-01-30 Thread Andrew Findlay
tests. Andrew -- --- | From Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

Re: Access control

2013-01-30 Thread Andrew Findlay
Andrew Findlay, Skills 1st Ltd | | Consultant in large-scale systems, networks, and directory services | | http://www.skills-1st.co.uk/+44 1628 782565 | ---

  1   2   >