[Date Prev][Date Next]
(ITS#7461) slapo-pcache not used for ACL which contains DN pointing to the remote LDAP server
- To: openldap-its@OpenLDAP.org
- Subject: (ITS#7461) slapo-pcache not used for ACL which contains DN pointing to the remote LDAP server
- From: firstname.lastname@example.org
- Date: Tue, 4 Dec 2012 09:55:48 GMT
- Auto-submitted: auto-generated (OpenLDAP-ITS)
Full_Name: Tio Teath
OS: Debian GNU Linux Wheezy
Submission from: (NULL) (220.127.116.11)
I'm trying to set up group ACL, which contains DN located on the remote LDAP
server. I have working ldap-proxy (olcSuffix: dc=remote) with slapo-pcache up
and running. I can do the following search request, and get proper result,
stored in the pcache database:
ldapsearch -bcn=test2,ou=group,dc=remote "(objectClass=groupOfNames)"
But whenever I trying to get access to the RDN, the ACL of which contains
following group entry:
'to dn.base="ou=people,dc=local" by group.exact="cn=test2,ou=group,dc=remote"
I can't see any activity in the log (using pcache loglevel). Looks like, for
some unknown reason, pcache are totally ignored while ACLs are processed.
This decreases performance dramatically, as search statements are produced for
each ACL containing remote DN.