[Date Prev][Date Next] [Chronological] [Thread] [Top]

(ITS#4057) [feature request] allow to defer bind to targets in back-meta when binding as rootdn

Full_Name: Pierangelo Masarati
Version: any
OS: irrelevant
URL: ftp://ftp.openldap.org/incoming/
Submission from: (NULL) (
Submitted by: ando

back-meta implements the pseudorootn feature; this is a sort of a subset of the
identity assertion implemented in back-ldap, consisting in mapping the client
identity onto a well-known identity for each of the target servers when bound as
the rootdn of the meta backend.  While having identity assertion would be fine,
a minimal enhancement would be to defer target binds to the time they're
actually needed by subsequent operations, allowing the client's authentication
to be evaluated by the proxy database alone.