lists.arthurdejong.org
RSS feed

Re: Revisiting Map limit to map base option

[Date Prev][Date Next] [Thread Prev][Thread Next]

Re: Revisiting Map limit to map base option



On Mon, 7 Oct 2013, Ashutosh Mahajan wrote:

We have machines where we only want to allow access from ~10 different 'groups' in our LDAP directory. So we need to keep 10 base options in nslcd.conf. As the limit is 7 it becomes a road-block for us.

Without more details on your configuration it is a bit difficult to guess but an ACL such as with pam_authz_search in general scales better than many search bases. You may be able to use pam_authz_search: the only limitation is that the search has to return one or more entries.

Is there an alternative way to compiling our own binary (using pam_authz_search, for example)? Sorry if it sounds stupid. I am new to ldapd and also to LDAP. Can you increase it to, say, 31 in your next release? That should be enough for everyone.

I will increase the number in the next 0.9 release.

--
-- arthur - arthur@arthurdejong.org - http://arthurdejong.org/ --
--
To unsubscribe send an email to
nss-pam-ldapd-users-unsubscribe@lists.arthurdejong.org or see
http://lists.arthurdejong.org/nss-pam-ldapd-users/