Issue 6108 - unique overlay and rootdn
Summary: unique overlay and rootdn
Status: VERIFIED FIXED
Alias: None
Product: OpenLDAP
Classification: Unclassified
Component: documentation (show other issues)
Version: 2.4.11
Hardware: All All
: --- normal
Target Milestone: ---
Assignee: OpenLDAP project
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2009-05-11 13:10 UTC by mfn@fs-etit.de
Modified: 2014-08-01 21:04 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this issue.
Description mfn@fs-etit.de 2009-05-11 13:10:31 UTC
Full_Name: Christopher Dyck
Version: 2.4.11
OS: Linux
URL: ftp://ftp.openldap.org/incoming/
Submission from: (NULL) (130.83.183.3)


I found a strange behavior in the unique overlay.

unique overlay only works, when a rootdn is specified in the slapd.conf, because
the unique_search function uses the rootdn for searching. (took me hours to
determine why my configuration didn't do it's job)

Isn't it more reasonable to use the dn with which the add or modify is
performed? Or mention this circumstance at least in the manpage?!
Comment 1 Howard Chu 2009-05-27 11:01:14 UTC
mfn@fs-etit.de wrote:
> Full_Name: Christopher Dyck
> Version: 2.4.11
> OS: Linux
> URL: ftp://ftp.openldap.org/incoming/
> Submission from: (NULL) (130.83.183.3)
>
>
> I found a strange behavior in the unique overlay.
>
> unique overlay only works, when a rootdn is specified in the slapd.conf, because
> the unique_search function uses the rootdn for searching. (took me hours to
> determine why my configuration didn't do it's job)
>
> Isn't it more reasonable to use the dn with which the add or modify is
> performed?

Definitely not. The user performing the write may not have sufficient access 
to see all of the instances of the attribute in question.

> Or mention this circumstance at least in the manpage?!

Probably.

-- 
   -- Howard Chu
   CTO, Symas Corp.           http://www.symas.com
   Director, Highland Sun     http://highlandsun.com/hyc/
   Chief Architect, OpenLDAP  http://www.openldap.org/project/

Comment 2 Howard Chu 2009-05-27 11:15:22 UTC
changed notes
changed state Open to Test
moved from Incoming to Documentation
Comment 3 Quanah Gibson-Mount 2009-06-02 21:54:58 UTC
changed notes
changed state Test to Release
Comment 4 Quanah Gibson-Mount 2009-07-22 17:10:42 UTC
changed notes
changed state Release to Closed
Comment 5 OpenLDAP project 2014-08-01 21:04:09 UTC
fixed in HEAD
fixed in RE24