[389-users] SASL mapping question

Prashanth Sundaram psundaram at wgen.net
Mon Sep 21 15:59:10 UTC 2009


Dear All,

I have few questions related to SASL mapping in 389-ds. I am using Windows
AD as kerberos server and here¹s the tree in both 389-ds and AD.

In Active Directory:
Users are located in different OU¹s like FullTime, PartTime, Contractors
etc.
example: ou=FullTime, OU=Users, OU=CompanyName,DC=ADDomain,DC=com

In 389-DS
Users are located only in one OU
example: ou=People,DC=ldapdomain,DC=com

<<<<<<<<Questions>>>>>>>

1. Is my SASL mapping correct?
nsSaslMapRegexString: \(.*\)@ldapdomain.com
nsSaslFilterTemplate: (objectclass=user)
nsSaslBaseDNTemplate:
sAMAccountName=\1,ou=Users,ou=CompanyName,dc=ADDomain,dc=com

2. Since users are in sub-ou in ADDomain, do I have to create separate SASL
mapping for each out? If, so then how will the 389-ds know if the user is in
PartTime OU and not in  FullTime OU.

3. How many SASL mapping should I have? By default I see 4 listed, should I
remove all others? I have read the RFCs which correspond but not sure why I
need them.

Thanks,
Prashanth 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/fedora-directory-users/attachments/20090921/187cc6e1/attachment.htm>


More information about the Fedora-directory-users mailing list