Howard Chu hyc at
Tue Aug 12 04:09:52 GMT 2008

> # Generated from schema in /usr/local/samba/private/ldap/schema-tmp.ldb
> overlay memberof
> memberof-dn cn=samba-admin,cn=samba
> memberof-dangling error
> memberof-refint TRUE
> memberof-group-oc top
> memberof-member-ad msDS-ObjectReference
> memberof-memberof-ad msDS-ObjectReferenceBL
> memberof-dangling-error 32

Mmm, that's really clunky. Someone should file an OpenLDAP enhancement request 
on the memberof config syntax. You should only need to instantiate the overlay 
once, and then it should just take a list of oc/forward-ad/back-ad config 

> Look closely at how we sub in memberof configuration into the
> slapd.conf.  I suggest that you could add a ${REPL_CONFIG} after each
> database, which the script could sub with either "" or by reading and
> subing in a slapd-replica.conf
   -- Howard Chu
   CTO, Symas Corp. 
   Director, Highland Sun
   Chief Architect, OpenLDAP

More information about the samba-technical mailing list