[PATCH]Re: ldap machine suffix behavior

Steve Langasek vorlon at netexpress.net
Wed Jun 11 16:12:42 GMT 2003


On Wed, Jun 11, 2003 at 09:12:41AM -0500, Gerald (Jerry) Carter wrote:
> On Wed, 11 Jun 2003, Stefan (metze) Metzmacher wrote:

> > At 15:43 10.06.2003 +0200, Stefan (metze) Metzmacher wrote:
> > >Hi Jerry,

> > >ldap suffix = DC=MX,DC=BASE
> > >ldap machine suffix = CN=Computers,

> > >will end in "ldap machine suffix" = CN=Computers,DC=MX,DC=BASE

> > >That's a bit like in ldap.conf for nss_ldap

> > here's a patch for that...

> Please do not apply this.  I'm not convinced that we should revert 
> to the old behavior.  I'll review it some more later this week.

The crucial difference seems to be that with the new patch, the 'ldap
suffix' is only appended if the 'ldap machine suffix' has a trailing
comma -- indicating that it's not a fully-qualified dn.  So this is not
really equivalent to the old behavior, it merely provides added
flexibility to the configuration.

OTOH, the amount of flexibility already present in smb.conf frightens me
most days. :)

-- 
Steve Langasek
postmodern programmer
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
Url : http://lists.samba.org/archive/samba-technical/attachments/20030611/10cbae4f/attachment.bin


More information about the samba-technical mailing list