Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
Apple's open LDAP
System
We are using Apples OS X Server 10.4 for our LDAP server it uses a version of open ldap.
We are able to see the users, with no issues but we are unable to see the groups.
I was unable to find a description field when I did a ldapsearch command
this is part of the output
# groups, latcha.com
dn: cn=groups,dc=latcha,dc=com
cn: groups
objectClass: container
================
sample group
================
# bizopsrocket, groups, latcha.com
dn: cn=bizopsrocket,cn=groups,dc=latcha,dc=com
objectClass: posixGroup
objectClass: apple-group
objectClass: extensibleObject
objectClass: top
gidNumber: 1029
apple-generateduid: 9C6EEA99-85A5-44C2-879C-6B299165A493
apple-group-realname: bizops Rocket
cn: bizopsrocket
apple-group-memberguid: B0360543-4BAD-41B6-9C19-AC7538915ECA
apple-group-memberguid: E0DF2AFB-90F9-47ED-9359-2F6A0578EF25
apple-group-memberguid: E6B2D1E1-9F13-4931-9551-110B8AEFA39B
apple-group-memberguid: 4E752CBF-45E9-4207-B8B2-4BCF4033C838
apple-group-memberguid: D042BD36-6985-44CF-B468-B0E9CD703449
apple-group-memberguid: B85D492E-937E-4D6B-B716-61BECB2B97AF
apple-group-memberguid: D4B6D341-0ACF-4846-84AE-5CAEAF453A8F
apple-group-memberguid: CB0E6FBF-59C7-41E3-9663-4FE9268665B8
memberUid: debbie
memberUid: lindap
memberUid: marty
memberUid: tony
memberUid: steve
memberUid: rachelle
memberUid: jill
===========================
when we use
class = container
Display Name = cn
Description = description ( we also tried "apple-group-realname" )
members = memberUid
we see no groups.
any one able to help with this issue?
Find more posts tagged with
Comments
lyman
I put the issue to our LDAP expert and received the following:
"The issue with the LDAP interface accessing groups is the selection of the Group Attributes Class specification. Based on the data presented, it should be 'apple-group' or 'posixGroup'. Unfortunately, while this will display the groups, the method by which the group membership is accertained, no users logging into MediaBin will be matched with the groups they are members of. The server assumes that group membership is assigned via DN (distinguished name) which doesn't appear to be the case for this directory."
My understanding is that the problem arises because LDAP may have a well-defined interface but the exact way users and groups are populated is not standardized. We have attempted a great deal of configuarability but the way groups are stored is beyond the knobs provided.
Hope this helps,
Lyman Hurd
MB Server Team
MediaBin Server Team
Interwoven, Inc.
Migrateduser
Thanks of the info.