[Date Prev][Date Next]
[Chronological]
[Thread]
[Top]
Re: (ITS#6057) "slapo-rwm interferes with content-sensitive ACLs"
- To: openldap-its@OpenLDAP.org
- Subject: Re: (ITS#6057) "slapo-rwm interferes with content-sensitive ACLs"
- From: ando@sys-net.it
- Date: Wed, 15 Apr 2009 14:06:57 GMT
- Auto-submitted: auto-generated (OpenLDAP-ITS)
David wrote:
> Yup this works, good work, thanks.
>
> Seems a tad slow though, do filters like these drastically slow down the
> search?
It applies some overhead: for each value of each attribute of each entry
it needs to check whether the memberOf attr is present; if it is, a
berval comparison is needed (compare the length first, and the value in
case of match). As usual, it depends on the structure of your data.
Also, but this is independent of ACL evaluation, slapo-rwm duplicates
each entry as soon as it needs to do some manipulation on it (like
massaging the DNs and so).
If you notice any significant overhead, you might want to profile the
execution of your slapd, to point out what's the actual bottleneck.
p.
Ing. Pierangelo Masarati
OpenLDAP Core Team
SysNet s.r.l.
via Dossi, 8 - 27100 Pavia - ITALIA
http://www.sys-net.it
-----------------------------------
Office: +39 02 23998309
Mobile: +39 333 4963172
Fax: +39 0382 476497
Email: ando@sys-net.it
-----------------------------------