[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: proxyAttrSet: Only using the LAST value



>>>>> "Pierangelo" == Pierangelo Masarati <ando@sys-net.it> writes:

    Pierangelo> I think you need different indices for different
    Pierangelo> proxyattrset, e.g

I figured that, but I wanted to be absolutely sure. That complicates
matters, but is feasible. Any plans on simplifying this (my way :)?

    Pierangelo> I'm not sure about what you can do for that in 2.2,
    Pierangelo> but note that even 2.3 is not going to forward sasl
    Pierangelo> authentication anyway.  All it's going to do is to
    Pierangelo> proxyAuthz __local__ identities, optionally using a
    Pierangelo> SASL bind as administrative user.  I don't think
    Pierangelo> proxying SASL binds is at all possible.

He! You said that last time to, and Howard corrected you :). 
http://www.openldap.org/lists/openldap-software/200407/msg00595.html


http://www.openldap.org/lists/openldap-software/200407/threads.html#00577

Just to be sure. Did something change? Neither of you seemed perfectly
sure exactly HOW things where...

Maybe I should say 'GSSAPI' here on instead of 'SASL'. I don't care
about anything else than Kerberos V right now :)

And don't nag about that, my girlfriend is already doing that :D



Could you please elaborate on what you mean by 'proxyAuthz __local__ identities'?