Samba4 and LDAP backend status

Andrew Bartlett abartlet at samba.org
Mon Jun 30 03:02:55 GMT 2008


I've been working to have Samba4 pass all it's tests against the LDAP
backend.

I need to use a patched openldap.  See
http://abartlet.net/openldap-cvs.tar.gz or
http://abartlet.net/memberof.patch

I've not had complete success, but between a full run, and an isolated
re-run of the ldap.py test, it seems to work.  (one of the test is quite
literally racy, I need to cope with both response orders). 

I'm also looking at a more secure way to handle talking to the LDAP
backend.  The current hack of using anonymous connections is clearly not
the best :-). 

I'm hoping to at some point move to a scheme using a fixed 'trust'
account and proxy authorization, if possible. 

In the meantime, I'm thinking to make a Samba4 alpha5 release, as the
alpha4 release didn't have the backend working, and didn't allow
OpenChange to build against it. 

Andrew Bartlett
-- 
Andrew Bartlett
http://samba.org/~abartlet/
Authentication Developer, Samba Team           http://samba.org
Samba Developer, Red Hat Inc.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://lists.samba.org/archive/samba-technical/attachments/20080630/9c6b913b/attachment.bin


More information about the samba-technical mailing list