I've managed to muddle through getting all the really nasty stuff working...
OpenLDAP works
OpenLDAP directory contains appropriate user entries
Users can authenticate through PAM against their OpenLDAP records (and I can
even control what they can log into using the authorizedService attribute,
so, some users get FTP, some get SSH, some get SMTP, some IMAP, etc.)
Anyhow, I'm down to one thing I need to make work that isn't. I need to get
[29]Apache (2.0.53, Fedora Core 3) to authenticate users against LDAP. I
think I know how to make the Apache queries work and query the right things
from the LDAP server and such, but, here's the rub:
Apache LDAP support is divided into two parts. mod_auth_ldap which seems
pretty straightforward (at least after dealing with everything else), and,
mod_ldap (which unlike the rest of apache modules is util_ldap.c instead
of mod_ldap.c WHEE!!).
My problem is that mod_ldap is refusing to make SSL connections to the LDAP
server, and, my LDAP server (deliberately) won't allow authenticated binds
using cleartext passwords without SSL.
Any ideas how to make this all work together or know anyone who knows this
stuff cold and could help me?
Thanks,
Time passes, this is pretty late in the month that it was sent, one TAG
member offers a little bit of aid, but...
I got some help from an openLDAP list finally... I was able to make the
dynamic group thing work. (Just got it working last night).
The 24th, on the edge of our TAG deadline. -- Heather
Thanks for your assistance.
I wasn't able to get sets working (if anyone knows appropriate set voodoo,
please feel free to contact me off-line and I'll share what I learn)...
However, for dynamic groups, I was able to create the following group:
See attached [30]owen.ldap-dynamic-group.txt
Hope this is enough to be useful as a short blurb. Much more useful full
information coming (hopefully) soon.
Owen
If you're an LDAP user with an answer to the remaining part of his puzzle
- and not already involved with his thread on the OpenLDAP mailing list...
by all means drop him a line!
Otherwise, look forward to what chef Owen's been cooking up, next month.
____________________________________________________
MoinMoin seeks translators
Tue, 22 Feb 2005 22:46:17 -0800
alex ([31]alex from alexanderweb.de)
I was lurking in #moin sometime recently, and was asked to pass this
request along to you gentle readers -- Heather
We can always use more people to help us not only translate but to make sure
the translations are readable, and mean what we think they do...
Relevant URL for a potential translator to take a look at, so you can get
involved:
[32]http://moinmoin.wikiwikiweb.de/MoinDev/Translation
A description of moin and the list of languages we currently support is
described at:
[33]http://www.python.org/pypi?:action=display&name=MoinMoin&version=1.3.1
Please also feel welcome to join us in IRC on #moin at freenode.
irc.debian.org, the default destination of IRC clients in debian, also
goes to freenode. Your distro may vary. MoinMoin is a python based wiki
package with themes, access control lists, and other antispam abilities.
-- Heather
_________________________________________________________________
GENERAL MAIL
_________________________________________________________________
* [34]Fvwm
* [35]Re: after installing new kernel running lilo crushes system
____________________________________________________
Fvwm
Mon, 14 Feb 2005 19:34:02 +0100
Heather Stern ([36]The Answer Gang's Editor Gal)
I've been seeing happy cross references from the FvwmForums about the
=2= |