Re: Using dyngroup

El Fri, 18 Feb 2005 09:44:06 -0800 Quanah Gibson-Mount

El Fri, 18 Feb 2005 09:44:06 -0800 Quanah Gibson-Mount
escribiÃ:

As I recall, the dynamic group overlay only lets you compare whether
or not someone is a member of a group, and does not create lists of
members for searches.


Thanks. In that case, are there somewhere any samples about setting up slapd.conf and making those comparisons? I've been looking at the archives of the lists but I'm unable to find any hints...

The first thing you have to do is add the dynamic group overlay using the:

overlay dyngroup


Then read slapd.access(5) man page.

" For static groups, the  specified  attributeType  must  have
    DistinguishedName  or NameAndOptionalUID syntax. For dynamic
    groups the attributeType must be a subtype of the labeledURI
    attributeType.     Only    LDAP    URIs    of    the    form
    ldap:///<base>??<scope>?<filter>  will  be  evaluated  in  a
    dynamic group, by searching the local server only."


