mike at jurney.org wrote:
| On Mon, 7 Feb 2005, Gerald (Jerry) Carter wrote:
|>IMO the privileges should be stored in local tdb files.  I'm working on
|>trying to get enough of the SAM replication protocol working to
|>replicate the privilege assignments working.
| Out of curiosity, is there a reason why they shouldn't
| be stored in the LDAP directory when using ldapsam?

IMO there is no advantage.  The privileges would be
separate entries that would be stored as a bitmask
or an octet-string.  Nothing that you would be editing
via LDAP tools.

The main advantage of LDAP is to consolidate
information that is shared by 2 or more applications.
Storing users makes sense.  Storing privileges is just
using LDAP like a database.

