[Bug 763389] New: ldap bind dn doesn't get written to /etc/ldap.conf installing via autoyast
https://bugzilla.novell.com/show_bug.cgi?id=763389
https://bugzilla.novell.com/show_bug.cgi?id=763389#c0
Summary: ldap bind dn doesn't get written to /etc/ldap.conf
installing via autoyast
Classification: openSUSE
Product: openSUSE 12.2
Version: Milestone 3
Platform: x86-64
OS/Version: openSUSE 12.2
Status: NEW
Severity: Normal
Priority: P5 - None
Component: AutoYaST
AssignedTo: ug@suse.com
ReportedBy: kleinrob@mpip-mainz.mpg.de
QAContact: qa-bugs@suse.de
Found By: ---
Blocker: ---
User-Agent: Opera/9.80 (X11; Linux x86_64; U; en) Presto/2.10.229
Version/11.64
When doing a autoyast installation, including a ldap section, the
https://bugzilla.novell.com/show_bug.cgi?id=763389
https://bugzilla.novell.com/show_bug.cgi?id=763389#c
Uwe Gansert
https://bugzilla.novell.com/show_bug.cgi?id=763389
https://bugzilla.novell.com/show_bug.cgi?id=763389#c1
Jiří Suchomel
When doing a autoyast installation, including a ldap section, the
tag only gets written in /etc/sysconfig/ldap in the installed system, but doesn't find its way into /etc/ldap.conf, where it is needed.
Is it needed there? We've never actually write it into /etc/ldap.conf ... -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=763389
https://bugzilla.novell.com/show_bug.cgi?id=763389#c2
Ralf Haferkamp
Is it needed there? We've never actually write it into /etc/ldap.conf ... Hm, no. /etc/ldap.conf allows setting a binddn, but using the same value as in /etc/sysconfig/ldap is the wrong choice in most cases.
The DN defined in /etc/sysconfig/ldap is usually a priviledge DN (it has at least some administrative rights on the LDAP Server) in most cases it currently will just be the Admin DN. The one in ldap.conf should be one with only just enough priviledges to read the users and groups. It shouldn't have any write access. If we'd want to support binddn in ldap.conf we'd need to add addtional elements to the UI as well. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=763389
https://bugzilla.novell.com/show_bug.cgi?id=763389#c3
Jiří Suchomel
https://bugzilla.novell.com/show_bug.cgi?id=763389
https://bugzilla.novell.com/show_bug.cgi?id=763389#c4
--- Comment #4 from Robert Klein
participants (1)
-
bugzilla_noreply@novell.com