[Freeipa-devel] [PATCH] configure bind+ldap driver

Rob Crittenden rcritten at redhat.com
Fri Jul 10 13:40:23 UTC 2009


Simo Sorce wrote:
> On Mon, 2009-06-29 at 14:20 -0400, Rob Crittenden wrote:
>> Simo Sorce wrote:
>>> This creates also role/task groups to authorize the ldap driver to
>>> perform DNS updates using its service principal.
>>> Does not support yet installing replicas.
>>>
>>> Simo.
>>>
>> What is the rationale for creating the delegation entries via ldif 
>> rather than an update? I seem to recall a chicken-and-egg problem.
>>
>> Can we create just the structural portions via the ldif and leave the 
>> taskgroups and rolegroups as updates?
> 
> It was the first thing I tried but didn't work.
> We need the groups to exist before the various *instance(0 classes are
> run so that group memberships can be added.
> In the case of bind I need to put the service in the right
> role/taskgroup, and I was thinking of doing something similar for other
> cases.
> 
> Simo.
> 

Ok, ack.

rob
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3245 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20090710/760d3a0b/attachment.bin>


More information about the Freeipa-devel mailing list