[PATCH] pdb_ldap: Use lp_ldap_group_suffix

Volker Lendecke Volker.Lendecke at SerNet.DE
Wed Jul 11 06:01:55 MDT 2012

On Tue, Jul 10, 2012 at 01:42:35PM -0700, Christof Schmitt wrote:
> I do not have the information about the exact performance
> problem. The request for this change was made to me since it is
> possible to configure "ldap group suffix" and "ldap user suffix",
> but those are not used for searching. There is some worry that
> this affects performance, but i don't have any data. I will
> respond to the request and recommend to create the indexes on the
> LDAP server.

ldap group suffix and ldap user suffix are used when smbd
adds objects to ldap, that is at least what the intention
is. They are not used for search, right. In my experience a
correctly configured LDAP does not have any issue with the
specific searches that Samba makes. We can certainly try to
assist you and your customer in optimizing the directory
server, so that this is no longer an issue.

We have deliberatly changed the searches, as in many
scenarios we had problems with the search base being a
subtree. Unfortunately there is no general solution for all
DIT's, there is a much too large variety in tree design.

With best regards,

Volker Lendecke

SerNet GmbH, Bahnhofsallee 1b, 37081 Göttingen
phone: +49-551-370000-0, fax: +49-551-370000-9
AG Göttingen, HRB 2816, GF: Dr. Johannes Loxen
http://www.sernet.de, mailto:kontakt at sernet.de

More information about the samba-technical mailing list