Pierangelo Masarati
7444352358
describe detailed access levels required for each operation
2003-12-15 17:55:55 +00:00
Kurt Zeilenga
eec0f83fd7
Fix typos
2003-12-14 21:00:52 +00:00
Pierangelo Masarati
529a03df53
use dedicated admin identity to proxyAuthz
2003-12-13 10:57:42 +00:00
Howard Chu
2f06437348
Updated for proxycache overlay. Probably belongs on its own now...
2003-12-07 04:30:39 +00:00
Kurt Zeilenga
17939ccdca
Clarify that the updatedn should not be same as the rootdn.
2003-12-02 21:18:19 +00:00
Pierangelo Masarati
f0ea4161ba
add administrative bind and proxyAuthz control to enable bound operations in distributed directories (need to manually #define LDAP_BACK_PROXY_AUTHZ and patches from ITS#2851 and ITS#2852)
2003-12-01 08:29:06 +00:00
Jong Hyuk Choi
4ae382fd79
misc updates
...
- syncrepl : id -> rid
- man page update
2003-11-26 21:37:44 +00:00
Jong Hyuk Choi
1fdda703e6
Support multiple sync replication at the consumer :
...
1) simultaneous operation of multiple active sync replication threads
2) cookie management for individual sync replication thread
(include rid=%3d to the slapd cookie command line option (-c))
2003-11-26 19:49:47 +00:00
Kurt Zeilenga
e3a4c4ec9c
Notice/Acknowledge updates
2003-11-26 02:58:56 +00:00
Jong Hyuk Choi
c204f4061f
keeps syncrepl manpage sections current
2003-11-24 23:16:45 +00:00
Pierangelo Masarati
9620cacd34
clarify the usage of the <modifier> field in 'dn' and 'domain' clauses of <who> access directive
2003-11-01 14:14:09 +00:00
Kurt Zeilenga
d0c05e814d
Add a basic DIT content rule test.
...
Fix DIT rules to allow extensibleObject in AUX
unifdef -DSLAP_EXTENDED_SCHEMA
2003-10-24 04:40:32 +00:00
Kurt Zeilenga
f6c1163eea
clarify that replacement, but not expression evaluation,
...
is done on the string in group.regex=string
We really should rename the style, in this case, to "replacement".
2003-10-15 08:04:25 +00:00
Luke Howard
976f61f0ed
Update SLAPI manual page
2003-10-12 06:36:29 +00:00
Kurt Zeilenga
d03c83f077
ITS#2621, reference slapd.plugin
2003-10-12 04:22:26 +00:00
Kurt Zeilenga
fd445970fb
document ditcontentrule directive
2003-10-12 04:20:20 +00:00
Howard Chu
878bff913a
Added description for idlcachesize, shm_key
2003-09-27 07:06:48 +00:00
Howard Chu
0eca4fa42f
More for dynamic groups
2003-09-21 10:52:44 +00:00
Howard Chu
11148522ec
ITS#2573 dynamic group support
2003-09-21 10:45:57 +00:00
Howard Chu
b93a0f45d5
ITS#2497 value-level ACLs
2003-09-21 10:34:40 +00:00
Jong Hyuk Choi
7f882daf15
Schema checking option for LDAP Sync replication
2003-09-03 21:42:52 +00:00
Jong Hyuk Choi
8dc1ac85dd
manual update for proxy cache (apurva)
2003-09-03 16:26:17 +00:00
Jong Hyuk Choi
372cb876a0
slapd.conf man page update (LDAP Sync replication configuration)
2003-08-28 22:29:55 +00:00
Kurt Zeilenga
9b0de44b91
Add clarification about authzDN which don't exist in the DIT
2003-08-14 18:38:20 +00:00
Kurt Zeilenga
443d4c8999
sasl-regexp clarifications
2003-07-29 15:28:52 +00:00
Kurt Zeilenga
0a1be4b126
ITS#2622: ucdata is in DATADIR
2003-06-30 18:39:17 +00:00
Hallvard Furuseth
d0582fb4c2
Replace some tabs with spaces.
...
Split some too long preformatted lines.
2003-06-29 15:34:32 +00:00
Hallvard Furuseth
c20dbfb4f6
Remove SEE ALSO locale(5); the locale option has been gone for ages.
2003-06-27 17:30:13 +00:00
Hallvard Furuseth
e613b1a353
Add BACKENDS section in slapd.conf(5).
...
Briefly compare back-bdb and back-ldbm.
Remove mention of MDBM and NDBM. Rename GNU DBM to GDBM.
Fix spacing typos. Prefix an octal file mode with 0.
Mention "notags" (new name for "nolang" from the attribute options patch).
Add SEE ALSO slapd-monitor(5) to slapd.conf(5).
2003-06-27 12:22:27 +00:00
Pierangelo Masarati
ade4642f85
Document proxy cache extensions (by way of Jong Hyuk Choi)
2003-06-24 11:49:56 +00:00
Howard Chu
44e32b3f7f
ITS#2594 add URI support for replica config
2003-06-14 00:06:36 +00:00
Kurt Zeilenga
256732f2ce
s/tls/starttls/
2003-06-10 18:32:36 +00:00
Hallvard Furuseth
feef99c760
Axe abandon support (ITS#2564)
2003-06-03 12:02:00 +00:00
Kurt Zeilenga
0954351565
Change ACL default style to exact (from regex)
2003-05-30 05:24:39 +00:00
Howard Chu
5ce0e3afb1
Add authors
2003-05-25 03:50:59 +00:00
Kurt Zeilenga
d6bfa4ab8f
remove documentation for bind_simple_unprotected
...
(which was axed log ago)
2003-05-24 01:26:38 +00:00
Kurt Zeilenga
b378944fc1
Zap "TLS hard"
2003-05-22 00:15:57 +00:00
Hallvard Furuseth
437e179098
Fix typo.
2003-05-19 17:30:14 +00:00
Pierangelo Masarati
ea8e28c6c1
update back-monitor man page
2003-05-18 23:26:30 +00:00
Kurt Zeilenga
c8a6d52e04
Rework CAVEATS
2003-05-17 18:37:40 +00:00
Pierangelo Masarati
904f513028
clarify DN regex match quirks
2003-05-17 12:39:10 +00:00
Kurt Zeilenga
7c8f3b351f
Warn folks that setting TLS option may break some applications.
...
URI should be used instead.
2003-05-17 01:08:09 +00:00
Kurt Zeilenga
c661a77268
axe suffixAlias
2003-04-26 23:52:28 +00:00
Kurt Zeilenga
26badc8174
Add some comments about DB_CONFIG
2003-04-24 16:22:46 +00:00
Kurt Zeilenga
099c2426b8
clarify that updatedn permits replica updating subject to access controls.
2003-04-21 02:29:46 +00:00
Pierangelo Masarati
ab9f7108f1
add caveats to man page; cleanup and small improvements
2003-04-16 22:23:46 +00:00
Pierangelo Masarati
9a39dcb7d4
add slurpd pid/args files
2003-04-15 21:56:21 +00:00
Pierangelo Masarati
8563681f18
document recent changes
2003-04-15 20:55:29 +00:00
Kurt Zeilenga
06da0f5e6f
Clarify "users" terminology
2003-04-15 02:20:01 +00:00
Pierangelo Masarati
3e3e5fdec5
first cut at documenting back-monitor
2003-04-08 23:46:56 +00:00
Pierangelo Masarati
250934254b
cleanup
2003-04-07 21:42:51 +00:00
Pierangelo Masarati
d275fee025
new rewrite example
2003-04-03 21:17:09 +00:00
Howard Chu
2c2bf67cea
ITS#2389, describe conn_max_pending/auth keywords
2003-03-27 04:18:16 +00:00
Hallvard Furuseth
1f00bd3c7f
Manpage nitpicks
2003-03-23 16:37:06 +00:00
Kurt Zeilenga
f4bb9a5d64
Fix typo (ITS#2379)
2003-03-15 23:36:23 +00:00
Kurt Zeilenga
472a79f211
LDAPv2 is Historic
2003-03-10 15:34:14 +00:00
Kurt Zeilenga
6fb4582d5c
suffixalias is no longer supported
2003-03-07 18:57:30 +00:00
Howard Chu
a60f6fe1a3
Added proxy-whoami keyword and some mention of connection pooling. Depends
...
on libldap_r, proxy authz control...
2003-02-26 16:35:09 +00:00
Kurt Zeilenga
63efc41728
clarify global ACL use
...
clarify root and subschema DSE ACLs
2003-02-24 19:53:03 +00:00
Kurt Zeilenga
607215a8d6
Some dn.regex clarifications
2003-02-23 19:38:32 +00:00
Kurt Zeilenga
f620aa08f9
Max workers was lowered to 16.
2003-02-21 07:18:43 +00:00
Kurt Zeilenga
5abec40030
Document URI and SASL directives
2003-02-09 06:49:34 +00:00
Kurt Zeilenga
698d73d5f3
Disable reverse lookups by default for security
...
(and performance) reasons.
2003-02-08 07:40:19 +00:00
Pierangelo Masarati
f19df0a307
add 'rebind-as-user' according to back-ldap's implementation
2003-02-05 22:04:20 +00:00
Kurt Zeilenga
1aae1854ac
delete (7) after UTF-8
2003-02-05 20:42:50 +00:00
Pierangelo Masarati
eed2d5db4d
only document 'subtree', but also allow 'sub'
2003-02-05 20:38:42 +00:00
Pierangelo Masarati
381e293b41
allow 'sub' and 'subtree' in acl (fix ITS#2300)
2003-02-05 19:39:34 +00:00
Pierangelo Masarati
ac895cd4d5
document the multiple URI feature
2003-02-04 19:50:17 +00:00
Pierangelo Masarati
55d21236d1
comment a useful feature of using URIs
2003-02-04 19:43:10 +00:00
Kurt Zeilenga
d2bb1b5691
Add a few notes about intended usage of these backends
2003-01-09 12:07:14 +00:00
Kurt Zeilenga
6939c53170
Happy new year
2003-01-03 20:20:47 +00:00
Hallvard Furuseth
5ca8773a8b
Fix typos.
2002-12-16 07:31:13 +00:00
Pierangelo Masarati
df5d69df8f
allow a custom error log file for plugins by means of a slapd.conf directive; add very bare-bone back-monitor info about installed plugins
2002-12-14 15:04:37 +00:00
Howard Chu
143603690f
Added searchstack keyword description. (Sorry, I don't like the word "slab"...)
2002-12-12 23:39:21 +00:00
Hallvard Furuseth
54728f367e
Implement user-defined tagging attribute options and ranges
2002-12-12 13:56:05 +00:00
Pierangelo Masarati
9cce5e4c98
a skeleton of slapd.conf directives for SLAPI configuration (lot to do)
2002-12-07 18:03:13 +00:00
Pierangelo Masarati
8473f6e778
set keyword to noEstimate and document it
2002-11-21 20:57:00 +00:00
Pierangelo Masarati
59aea47963
improve limits handling and consistency; return "Admin limit exceeded" instead of "Unwilling to perform"
2002-11-21 12:58:59 +00:00
Pierangelo Masarati
b9e442d7de
clarify how to specify no limits
2002-10-31 11:26:19 +00:00
Pierangelo Masarati
53e1930fd0
use keyword "unlimited" instead of -1 for no limits
2002-10-31 09:57:24 +00:00
Kurt Zeilenga
c14cbc1fb7
Update anon
2002-10-26 02:53:36 +00:00
Kurt Zeilenga
6bc33d28c0
Note --without-threads limitation
2002-10-16 16:54:27 +00:00
Kurt Zeilenga
023d0e2a5c
Rework unprotected simple bind checks
2002-10-08 19:03:18 +00:00
Kurt Zeilenga
36fca96695
if "disallow bind_simple_unprotected", require at least SSF of 2
2002-10-08 01:06:49 +00:00
Kurt Zeilenga
90e320398a
Clarify that "security ssf=n" applies to "disallow bind_simple_unprotected".
2002-10-08 00:51:19 +00:00
Kurt Zeilenga
68aebc05c9
Clean up hash password scheme stuff
2002-09-20 17:27:08 +00:00
Kurt Zeilenga
11a07153d6
Add some clarification as to what hash algorithms are used
...
with each password-hash scheme.
2002-09-20 17:12:58 +00:00
Kurt Zeilenga
2ca678ea2e
More LDAPNOINIT statement to top of DESCRIPTION
2002-09-04 20:59:57 +00:00
Pierangelo Masarati
5a0ba6e429
document another (optional) config directive
2002-08-31 10:27:49 +00:00
Pierangelo Masarati
f11c6b27e7
Final run of changes to back-sql; IBM db2 support has been tested.
...
Now related ITSes need be audited and possibly closed.
Enhancements:
- re-styled code for better readability
- upgraded backend API to reflect recent changes
- LDAP schema is checked when loading SQL/LDAP mapping
- AttributeDescription/ObjectClass pointers used for more efficient
mapping lookup
- bervals used where string length is required often
- atomized write operations by committing at the end of each operation
and defaulting connection closure to rollback
- added LDAP access control to write operations
- fully implemented modrdn (with rdn attrs change, deleteoldrdn,
access check, parent/children check and more)
- added parent access control, children control to delete operation
- added structuralObjectClass operational attribute check and
value return on search
- added hasSubordinate operational attribute on demand
- search limits are appropriately enforced
- function backsql_strcat() has been made more efficient
- concat function has been made configurable by means of a pattern
- added config switches:
- fail_if_no_mapping write operations fail if there is no mapping
- has_ldapinfo_dn_ru overrides autodetect
- concat_pattern a string containing two '?' is used
(note that "?||?" should be more portable
than builtin function "CONCAT(?,?)")
- strcast_func cast of string constants in "SELECT DISTINCT statements (needed by PostgreSQL)
- upper_needs_cast cast the argument of upper when required
(basically when building dn substring queries)
Todo:
- add security checks for SQL statements that can be injected (?)
- re-test with previously supported RDBMs
- replace dn_ru and so with normalized dn (no need for upper() and so
in dn match)
- implement a backsql_normalize() function to replace the upper()
conversion routines
- note that subtree deletion, subtree renaming and so could be easily
implemented (rollback and consistency checks are available :)
- implement "lastmod" and other operational stuff (ldap_entries table ?)
2002-08-23 08:54:08 +00:00
Howard Chu
33d5c0abd7
Fix errors in replica directive
2002-08-22 20:32:09 +00:00
Pierangelo Masarati
76e936e274
reflect recent additions to backend configuration
2002-08-13 17:13:57 +00:00
Howard Chu
1be4ab9d07
ITS#1893 Add (terse) schemadn description
2002-08-10 04:09:28 +00:00
Kurt Zeilenga
9c28c9b361
Zap LDAPv2-only stuff
2002-08-08 03:01:14 +00:00
Kurt Zeilenga
99133f7944
Fix a few typos
2002-07-10 03:12:47 +00:00
Kurt Zeilenga
b839e6fc8b
Remove misleading (untrue) text about known syntax OID macros.
2002-06-27 16:27:07 +00:00
Kurt Zeilenga
9a38d98d37
Add option to disallow unprotected simple authentication.
...
Add protected simple authentication as a "strong" mechanism.
2002-06-17 22:18:27 +00:00
Howard Chu
98b1e09c44
Note that TLS_CERT and TLS_KEY are user-only options.
2002-06-16 12:10:23 +00:00
Howard Chu
dca986280e
Fix typo in previous commit
2002-06-16 07:29:06 +00:00
Howard Chu
0f0c268c6d
Minor cleanup and reformat, added TLS options.
2002-06-16 07:19:31 +00:00