(ITS#5654) memberof syntax clunky

Full_Name: Andrew Bartlett
Version: CVS HEAD
OS: Fedora 9
URL: ftp://ftp.openldap.org/incoming/
Submission from: (NULL) (

As instructed by Howard:

From: 	Howard Chu <hyc@highlandsun.com>
To: 	samba-technical@lists.samba.org
Subject: 	Re: samba4-ol-mmr
Date: 	Mon, 11 Aug 2008 21:09:52 -0700 (Tue, 14:09 EST)

> # Generated from schema in /usr/local/samba/private/ldap/schema-tmp.ldb
> overlay memberof
> memberof-dn cn=samba-admin,cn=samba
> memberof-dangling error
> memberof-refint TRUE
> memberof-group-oc top
> memberof-member-ad msDS-ObjectReference
> memberof-memberof-ad msDS-ObjectReferenceBL
> memberof-dangling-error 32

(repeats once per attribute link)


Mmm, that's really clunky. Someone should file an OpenLDAP enhancement request 
on the memberof config syntax. You should only need to instantiate the overlay 
once, and then it should just take a list of oc/forward-ad/back-ad config 

> Look closely at how we sub in memberof configuration into the
> slapd.conf.  I suggest that you could add a ${REPL_CONFIG} after each
> database, which the script could sub with either "" or by reading and
> subing in a slapd-replica.conf
   -- Howard Chu
   CTO, Symas Corp.           http://www.symas.com
   Director, Highland Sun     http://highlandsun.com/hyc/
   Chief Architect, OpenLDAP  http://www.openldap.org/project/