[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: Using dyngroup





--On Friday, February 18, 2005 1:42 PM +0100 Josà Accino <accino@uma.es> wrote:


Hello.

We are trying to get the dyngroup overlay working but without any
results until now. Just for testing, we have defined a group entry such
as"cn=faculty_users,ou=groups,dc=our,dc=domain", with a memberURL
attribute such as

 ldap:///ou=users,dc=our,dc=domain???(eduPersonAffiliation=faculty)

to get all the users with the value 'faculty' in eduPersonAffiliation
attribute. Looking for info at the source code in overlays/dyngroup.c,
it seems that the configuration in slapd.conf should take the form:

     overlay dyngroup
     attrpair member memberURL

but although OpenLDAP restarts without error, it keeps returning the
same result when I do a search for the group, that is: no entries from
members of that group; only the group entry itself (with cn, objectClass
and memberURL attributes). Maybe I'm missing something and the use of
dyngroup overlay is a bit different...

I've been looking for further help in OpenLDAP lists and Google but a
search there for 'attrpair dyngroup' (to reduce it to the overlay
configuration) returns zero entries...

Is there anyone there using this dynamic groups overlay who could post
some info about how to configure and use it, or some pointers to get it
running?

Thanks in advance,

As I recall, the dynamic group overlay only lets you compare whether or not someone is a member of a group, and does not create lists of members for searches.


--Quanah

--
Quanah Gibson-Mount
Principal Software Developer
ITSS/Shared Services
Stanford University
GnuPG Public Key: http://www.stanford.edu/~quanah/pgp.html

"These censorship operations against schools and libraries are stronger
than ever in the present religio-political climate. They often focus on
fantasy and sf books, which foster that deadly enemy to bigotry and blind
faith, the imagination." -- Ursula K. Le Guin