Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bugzilla DB migration completed. Please report issues to Infra team via email via infra@gentoo.org or IRC
Bug 115130 - LDAP howto badly out of date
Summary: LDAP howto badly out of date
Status: RESOLVED WONTFIX
Alias: None
Product: [OLD] Docs-user
Classification: Unclassified
Component: Other (show other bugs)
Hardware: All Linux
: High major (vote)
Assignee: Andrea Barisani (RETIRED)
URL: http://www.gentoo.org/doc/en/ldap-how...
Whiteboard:
Keywords:
: 103163 (view as bug list)
Depends on:
Blocks:
 
Reported: 2005-12-10 14:03 UTC by Quanah Gibson-Mount
Modified: 2006-05-04 05:16 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Quanah Gibson-Mount 2005-12-10 14:03:24 UTC
Hello,

The web page that you have on seting up OpenLDAP authentication is so out of
date as to be detrimental to your users.  Having already had to help several
people on the #ldap channel in IRC who were having problems after following the
guide, it would be of more benefit at this time to remove the page.  Among the
issues I see:

(a) It still lists using the LDBM database.  This is problematic, see:
http://www.openldap.org/faq/data/cache/1167.html
http://www.openldap.org/faq/data/cache/756.html

(b) 2.7 tells the user to do a search against an empty database, and then says
if they get an error message to figure out why with extra debugging.  Since the
database is empty, they are always going to get an error message.

(c) 5.1 and 5.2 reference very old style ACL's that are likely not to work (or
only by accident) in the modern OpenLDAP releases.



Reproducible: Always
Steps to Reproduce:
1.  Follow the document

Actual Results:  
You get a misconfigured system with an unreliable unsupported database backend.

Expected Results:  
The documentation should reflect modern software requirements

I suggest having the guide use back-bdb or back-hdb, and you will point to the
guides on tuning the BDB database via DB_CONFIG.

http://www.stanford.edu/services/directory/openldap/configuration/bdb-config.html

and

http://www.stanford.edu/services/directory/openldap/configuration/slapd-conf-replica.html

may be of some help.
Comment 1 Jan Kundrát (RETIRED) gentoo-dev 2005-12-19 05:02:36 UTC
*** Bug 103163 has been marked as a duplicate of this bug. ***
Comment 2 Łukasz Damentko (RETIRED) gentoo-dev 2006-01-01 13:48:52 UTC
Maybe some of infra people who use LDAP on our servers could take care of fixing or rewriting this guide?
Comment 3 Andrea Barisani (RETIRED) gentoo-dev 2006-01-01 14:52:31 UTC
I'll take care of this (hopefully soon but I don't make any promises).
Comment 4 Carsten Lohrke (RETIRED) gentoo-dev 2006-01-01 15:27:43 UTC
As long as it is that misleading, it's better to replace the page with another one, stating that the original needs to be reworked, imho.
Comment 5 Dominik Kozaczko 2006-01-26 05:51:16 UTC
I'm struggling with LDAP for two weeks, please fix the HOWTO!

Provided .schema's are faulty and I have no idea how to fix them.
Including nis.schema produces this error: /etc/openldap/schema/nis.schema: line 194: AttributeType not found: "manager"
Including interorgperson.schema produces this error: /etc/openldap/schema/inetorgperson.schema: line 155: AttributeType not
found:
"audio"

I think the schemas should REALLY work aout-of-the-box.

Well-written foolproof HOWTO on LDAP authentication is a must. Or at least point to well written HOWTO.
Comment 6 Andrea Barisani (RETIRED) gentoo-dev 2006-01-26 06:24:40 UTC
> I'm struggling with LDAP for two weeks, please fix the HOWTO!

The bug is open and we know about it, don't shout about it ok? The fact that you
are struggling with LDAP is not a primary concern of the Gentoo Project and
there's plenty of docs out there. This was a helper for a general LDAP setup
it's nothing gentoo specific anyway but since we are nice guys we'll *try* to
update it and give something that works when we have time for it. In any case the doc is *not* advertised on the Documentation listing since it's outdated. In the mean time you can check the presentation that you can find here http://dev.gentoo.org/~lcars/ldap.

docs-team: feel free to remove the doc or hide it completely since docs listing 
removal is not enough apparently.
Comment 7 Benjamin Smee (strerror) (RETIRED) gentoo-dev 2006-05-04 05:16:41 UTC
after a discussion with the relevant parties it was decided that due to other good HOWTOs there is no reason to write one specifically for gentoo. That said I will be writing something up that our doc team are welcome to use if they are so inclined.