[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: Limit which database is reachable on which port (slapd is listening on)?



On Tue, 2017-06-20 at 14:56 +0200, Karsten Heymann wrote:
> Hi John,
> 
> 2017-06-20 14:18 GMT+02:00 John Lewis <oflameo2@gmail.com>:
> > I know that, but can DNS influence LDAP or are they completely
> > independent and all of the name redirection all the clients
> > responsibility? For example I have two domains stuff.com and junk.net If
> > someone tried to connect to stuff.com of a port that is running
> > stuff.com can it automatically connect them into stuff.com and visa
> > versa or do they need to know where they are going to and would have to
> > see that both sites are running via the DIT and choose which site
> > themselves explicitly?
> 
> I see, that cannot work beause unlike http with ldap the server name
> is not part of the request, so the ldap server has no idea what
> hostname the client used to contact the ldap directory (only if the
> different hostnames resolve to different IP addresses, but that's not
> the case in your scenario). But if your intention is to save IP
> addresses, maybe my idea of using different ports for different
> directory trees is an option too?
> 
> Best regards
> Karsten

Using different ports for different directories is an option. Do you
think it would be better to just tell people to use the DIT and browse
to the correct directory?