Re: Mapping attributes in nslcd.conf
[
Date Prev][
Date Next]
[
Thread Prev][
Thread Next]
Re: Mapping attributes in nslcd.conf
- From: Greg Newton <gregster [at] uvic.ca>
- To: nss-pam-ldap <nss-pam-ldapd-users [at] lists.arthurdejong.org>
- Subject: Re: Mapping attributes in nslcd.conf
- Date: Thu, 9 Sep 2010 09:30:52 -0700
Thanks for the quick response David.
If I understand you correctly, the answer is that there is nothing in
the local machine's /etc/group file that can be used to create a home
group for ldap users, and "getent group<gidNumber>" returns nothing,
which doesn't surprise me; as I said, those attributes are not populated
in ldap.
So, I *think* I'm still left with using the map feature in nslcd.conf to
"create" a gid from the ldap-returned uid.
Do you if I need to be able to read an attribute from ldap before I can
change it?
In my configuration, we don't have a gid value for users either. The
string representation of their group is obtained by the system looking
up the gid (either in /etc/group or via LDAP, if you're using LDAP for
groups). Try using "getent group<gidNumber>" to see if your host is
properly looking up groups via LDAP.
--
To unsubscribe send an email to
nss-pam-ldapd-users-unsubscribe@lists.arthurdejong.org or see
http://lists.arthurdejong.org/nss-pam-ldapd-users