Pierangelo Masarati
6624f68725
fix braindead config option (mostly harmless)
2004-04-15 20:27:43 +00:00
Pierangelo Masarati
8ea2f6e157
further clarify size limits
2004-04-15 01:16:53 +00:00
Pierangelo Masarati
6b2347be6a
document lastmod overlay
2004-04-14 23:35:17 +00:00
Pierangelo Masarati
8bf68bc796
clarify the use of the fail_if_no_mapping switch and minor cleanup
2004-04-14 13:10:00 +00:00
Pierangelo Masarati
25c672a844
document search disable feature (spin-off of limit on unchecked entries)
2004-04-09 17:57:48 +00:00
Pierangelo Masarati
2e13fbeea1
completion of limits w/ paged results control
2004-04-09 15:54:46 +00:00
Hallvard Furuseth
6b45e32da3
Add NEW_LOGGING note for the commented-out "debug" and "logfile" options.
2004-04-09 05:27:04 +00:00
Pierangelo Masarati
85b078a3cb
clarify what rewrite rules suffixmassage corresponds to
2004-04-07 20:55:32 +00:00
Kurt Zeilenga
bd7cd42669
clarify updatedn (again)
2004-04-07 03:32:55 +00:00
Kurt Zeilenga
bd765b849d
ITS#2768: configuring slurpd's interval between replog checks
...
based upon a patch submitted by Jason Townsend (Apple).
2004-03-23 01:12:11 +00:00
Howard Chu
d4d5e253d9
Fix header
2004-03-19 20:23:26 +00:00
Howard Chu
057a385346
Rename slapd-ppolicy.5 to slapo-ppolicy.5
2004-03-19 20:18:46 +00:00
Pierangelo Masarati
9e159e2382
remove outdated comment
2004-03-18 21:48:21 +00:00
Pierangelo Masarati
fa3baaeae9
overlays reworking
2004-03-18 18:59:46 +00:00
Howard Chu
d1292c1b14
Added ppolicy_use_lockout keyword; Default behavior is not to issue the
...
PP_accountLocked error for locked accounts. (Gives too much information
to attackers.)
2004-03-18 10:35:54 +00:00
Pierangelo Masarati
cd105fab4e
man page
2004-03-18 00:36:50 +00:00
Howard Chu
e5ec72c2b9
Add note about overlay directive
2004-03-16 22:25:08 +00:00
Howard Chu
9e39c5e0b6
Docs for ppolicy overlay
2004-03-16 22:00:30 +00:00
Pierangelo Masarati
65b49dd312
add "searchFilterAttrDN" rewrite context, and allow filterstring rewrite
2004-03-10 21:11:14 +00:00
Pierangelo Masarati
006745430e
allow "expand" style in peername, sockname, sockurl as well; more sanity checks
2004-03-09 19:44:14 +00:00
Pierangelo Masarati
042869366d
use "expand" instead of "regex" for group ACLs that allow substring expansion, preserving backwards compatibility; add sanity checks
2004-03-09 16:33:05 +00:00
Pierangelo Masarati
4645eeb5ec
cleanup DN style in limits
2004-03-08 13:13:30 +00:00
Pierangelo Masarati
5716b7f1b2
document saslAuthzTo/saslAuthzFrom new syntax; add onelevel style to DN type
2004-03-06 11:00:49 +00:00
Howard Chu
5f9a87c041
password-hash now takes a list of mechanisms
2004-03-02 22:17:20 +00:00
Kurt Zeilenga
b927f86e3f
Clarify updatedn
2004-02-25 17:37:59 +00:00
Pierangelo Masarati
4e57108991
allow search limits based on groups (ITS#2967)
2004-02-18 16:40:36 +00:00
Pierangelo Masarati
cf5e2496f7
map type/name were swapped
2004-02-05 18:17:27 +00:00
Pierangelo Masarati
f5a9f62578
clarify that's useless to give write privileges to the roodn of a database...
2004-01-14 23:11:48 +00:00
Kurt Zeilenga
3c598e89fb
Happy new year
2004-01-01 19:15:16 +00:00
Pierangelo Masarati
3994dc645a
allow to set max passes per rule
2003-12-29 18:02:49 +00:00
Pierangelo Masarati
9e86d9ffe2
clarify field description in rewriteRule statement
2003-12-29 17:12:29 +00:00
Pierangelo Masarati
c860ba6a23
fix, clarify and document previous commit
2003-12-29 17:06:43 +00:00
Pierangelo Masarati
3ddfddb1a7
typo
2003-12-29 15:22:10 +00:00
Jong Hyuk Choi
cd16a93244
update syncrepl and session log info
2003-12-21 16:32:00 +00:00
Pierangelo Masarati
8e89944abc
for consistency, always allow 'onelevel' as an alias for 'one' in dnstyle
2003-12-20 15:29:05 +00:00
Kurt Zeilenga
aabcce3e58
Document +0
2003-12-19 05:06:51 +00:00
Pierangelo Masarati
113727ba53
allow 'all' vs. 'any' sasl-authz-policy
2003-12-18 18:28:43 +00:00
Pierangelo Masarati
ca52621c1b
some notes on access required by proxyAuthz control;
...
note that other controls may need different access
privileges via, e.g., backend_attribute() (syncrepl?)
2003-12-18 00:27:01 +00:00
Kurt Zeilenga
c4c6a38a0b
Dont mention bare oc in list.
2003-12-17 17:48:56 +00:00
Kurt Zeilenga
30a1ff596d
s/+/@/ in OC attr lists
2003-12-17 17:36:41 +00:00
Pierangelo Masarati
947f41832e
more clarifications on dnstyle usage
2003-12-16 11:20:59 +00:00
Pierangelo Masarati
ee34f3fb64
add to 'val[.<style>=<value>' ACLs special match styles for DN-valued attributes; add negated objectClass to attribute name lists for ACLs and partial replication
2003-12-16 00:49:10 +00:00
Kurt Zeilenga
75b9f8acdc
Make a few OPERATIONAL REQUIREMENT clarifications
...
Clean up formating
2003-12-15 18:41:23 +00:00
Pierangelo Masarati
7444352358
describe detailed access levels required for each operation
2003-12-15 17:55:55 +00:00
Kurt Zeilenga
eec0f83fd7
Fix typos
2003-12-14 21:00:52 +00:00
Pierangelo Masarati
529a03df53
use dedicated admin identity to proxyAuthz
2003-12-13 10:57:42 +00:00
Howard Chu
2f06437348
Updated for proxycache overlay. Probably belongs on its own now...
2003-12-07 04:30:39 +00:00
Kurt Zeilenga
17939ccdca
Clarify that the updatedn should not be same as the rootdn.
2003-12-02 21:18:19 +00:00
Pierangelo Masarati
f0ea4161ba
add administrative bind and proxyAuthz control to enable bound operations in distributed directories (need to manually #define LDAP_BACK_PROXY_AUTHZ and patches from ITS#2851 and ITS#2852)
2003-12-01 08:29:06 +00:00
Jong Hyuk Choi
4ae382fd79
misc updates
...
- syncrepl : id -> rid
- man page update
2003-11-26 21:37:44 +00:00
Jong Hyuk Choi
1fdda703e6
Support multiple sync replication at the consumer :
...
1) simultaneous operation of multiple active sync replication threads
2) cookie management for individual sync replication thread
(include rid=%3d to the slapd cookie command line option (-c))
2003-11-26 19:49:47 +00:00
Kurt Zeilenga
e3a4c4ec9c
Notice/Acknowledge updates
2003-11-26 02:58:56 +00:00
Jong Hyuk Choi
c204f4061f
keeps syncrepl manpage sections current
2003-11-24 23:16:45 +00:00
Pierangelo Masarati
9620cacd34
clarify the usage of the <modifier> field in 'dn' and 'domain' clauses of <who> access directive
2003-11-01 14:14:09 +00:00
Kurt Zeilenga
d0c05e814d
Add a basic DIT content rule test.
...
Fix DIT rules to allow extensibleObject in AUX
unifdef -DSLAP_EXTENDED_SCHEMA
2003-10-24 04:40:32 +00:00
Kurt Zeilenga
f6c1163eea
clarify that replacement, but not expression evaluation,
...
is done on the string in group.regex=string
We really should rename the style, in this case, to "replacement".
2003-10-15 08:04:25 +00:00
Luke Howard
976f61f0ed
Update SLAPI manual page
2003-10-12 06:36:29 +00:00
Kurt Zeilenga
d03c83f077
ITS#2621, reference slapd.plugin
2003-10-12 04:22:26 +00:00
Kurt Zeilenga
fd445970fb
document ditcontentrule directive
2003-10-12 04:20:20 +00:00
Howard Chu
878bff913a
Added description for idlcachesize, shm_key
2003-09-27 07:06:48 +00:00
Howard Chu
0eca4fa42f
More for dynamic groups
2003-09-21 10:52:44 +00:00
Howard Chu
11148522ec
ITS#2573 dynamic group support
2003-09-21 10:45:57 +00:00
Howard Chu
b93a0f45d5
ITS#2497 value-level ACLs
2003-09-21 10:34:40 +00:00
Jong Hyuk Choi
7f882daf15
Schema checking option for LDAP Sync replication
2003-09-03 21:42:52 +00:00
Jong Hyuk Choi
8dc1ac85dd
manual update for proxy cache (apurva)
2003-09-03 16:26:17 +00:00
Jong Hyuk Choi
372cb876a0
slapd.conf man page update (LDAP Sync replication configuration)
2003-08-28 22:29:55 +00:00
Kurt Zeilenga
9b0de44b91
Add clarification about authzDN which don't exist in the DIT
2003-08-14 18:38:20 +00:00
Kurt Zeilenga
443d4c8999
sasl-regexp clarifications
2003-07-29 15:28:52 +00:00
Kurt Zeilenga
0a1be4b126
ITS#2622: ucdata is in DATADIR
2003-06-30 18:39:17 +00:00
Hallvard Furuseth
d0582fb4c2
Replace some tabs with spaces.
...
Split some too long preformatted lines.
2003-06-29 15:34:32 +00:00
Hallvard Furuseth
c20dbfb4f6
Remove SEE ALSO locale(5); the locale option has been gone for ages.
2003-06-27 17:30:13 +00:00
Hallvard Furuseth
e613b1a353
Add BACKENDS section in slapd.conf(5).
...
Briefly compare back-bdb and back-ldbm.
Remove mention of MDBM and NDBM. Rename GNU DBM to GDBM.
Fix spacing typos. Prefix an octal file mode with 0.
Mention "notags" (new name for "nolang" from the attribute options patch).
Add SEE ALSO slapd-monitor(5) to slapd.conf(5).
2003-06-27 12:22:27 +00:00
Pierangelo Masarati
ade4642f85
Document proxy cache extensions (by way of Jong Hyuk Choi)
2003-06-24 11:49:56 +00:00
Howard Chu
44e32b3f7f
ITS#2594 add URI support for replica config
2003-06-14 00:06:36 +00:00
Kurt Zeilenga
256732f2ce
s/tls/starttls/
2003-06-10 18:32:36 +00:00
Hallvard Furuseth
feef99c760
Axe abandon support (ITS#2564)
2003-06-03 12:02:00 +00:00
Kurt Zeilenga
0954351565
Change ACL default style to exact (from regex)
2003-05-30 05:24:39 +00:00
Howard Chu
5ce0e3afb1
Add authors
2003-05-25 03:50:59 +00:00
Kurt Zeilenga
d6bfa4ab8f
remove documentation for bind_simple_unprotected
...
(which was axed log ago)
2003-05-24 01:26:38 +00:00
Kurt Zeilenga
b378944fc1
Zap "TLS hard"
2003-05-22 00:15:57 +00:00
Hallvard Furuseth
437e179098
Fix typo.
2003-05-19 17:30:14 +00:00
Pierangelo Masarati
ea8e28c6c1
update back-monitor man page
2003-05-18 23:26:30 +00:00
Kurt Zeilenga
c8a6d52e04
Rework CAVEATS
2003-05-17 18:37:40 +00:00
Pierangelo Masarati
904f513028
clarify DN regex match quirks
2003-05-17 12:39:10 +00:00
Kurt Zeilenga
7c8f3b351f
Warn folks that setting TLS option may break some applications.
...
URI should be used instead.
2003-05-17 01:08:09 +00:00
Kurt Zeilenga
c661a77268
axe suffixAlias
2003-04-26 23:52:28 +00:00
Kurt Zeilenga
26badc8174
Add some comments about DB_CONFIG
2003-04-24 16:22:46 +00:00
Kurt Zeilenga
099c2426b8
clarify that updatedn permits replica updating subject to access controls.
2003-04-21 02:29:46 +00:00
Pierangelo Masarati
ab9f7108f1
add caveats to man page; cleanup and small improvements
2003-04-16 22:23:46 +00:00
Pierangelo Masarati
9a39dcb7d4
add slurpd pid/args files
2003-04-15 21:56:21 +00:00
Pierangelo Masarati
8563681f18
document recent changes
2003-04-15 20:55:29 +00:00
Kurt Zeilenga
06da0f5e6f
Clarify "users" terminology
2003-04-15 02:20:01 +00:00
Pierangelo Masarati
3e3e5fdec5
first cut at documenting back-monitor
2003-04-08 23:46:56 +00:00
Pierangelo Masarati
250934254b
cleanup
2003-04-07 21:42:51 +00:00
Pierangelo Masarati
d275fee025
new rewrite example
2003-04-03 21:17:09 +00:00
Howard Chu
2c2bf67cea
ITS#2389, describe conn_max_pending/auth keywords
2003-03-27 04:18:16 +00:00
Hallvard Furuseth
1f00bd3c7f
Manpage nitpicks
2003-03-23 16:37:06 +00:00
Kurt Zeilenga
f4bb9a5d64
Fix typo (ITS#2379)
2003-03-15 23:36:23 +00:00
Kurt Zeilenga
472a79f211
LDAPv2 is Historic
2003-03-10 15:34:14 +00:00
Kurt Zeilenga
6fb4582d5c
suffixalias is no longer supported
2003-03-07 18:57:30 +00:00
Howard Chu
a60f6fe1a3
Added proxy-whoami keyword and some mention of connection pooling. Depends
...
on libldap_r, proxy authz control...
2003-02-26 16:35:09 +00:00
Kurt Zeilenga
63efc41728
clarify global ACL use
...
clarify root and subschema DSE ACLs
2003-02-24 19:53:03 +00:00
Kurt Zeilenga
607215a8d6
Some dn.regex clarifications
2003-02-23 19:38:32 +00:00
Kurt Zeilenga
f620aa08f9
Max workers was lowered to 16.
2003-02-21 07:18:43 +00:00
Kurt Zeilenga
5abec40030
Document URI and SASL directives
2003-02-09 06:49:34 +00:00
Kurt Zeilenga
698d73d5f3
Disable reverse lookups by default for security
...
(and performance) reasons.
2003-02-08 07:40:19 +00:00
Pierangelo Masarati
f19df0a307
add 'rebind-as-user' according to back-ldap's implementation
2003-02-05 22:04:20 +00:00
Kurt Zeilenga
1aae1854ac
delete (7) after UTF-8
2003-02-05 20:42:50 +00:00
Pierangelo Masarati
eed2d5db4d
only document 'subtree', but also allow 'sub'
2003-02-05 20:38:42 +00:00
Pierangelo Masarati
381e293b41
allow 'sub' and 'subtree' in acl (fix ITS#2300)
2003-02-05 19:39:34 +00:00
Pierangelo Masarati
ac895cd4d5
document the multiple URI feature
2003-02-04 19:50:17 +00:00
Pierangelo Masarati
55d21236d1
comment a useful feature of using URIs
2003-02-04 19:43:10 +00:00
Kurt Zeilenga
d2bb1b5691
Add a few notes about intended usage of these backends
2003-01-09 12:07:14 +00:00
Kurt Zeilenga
6939c53170
Happy new year
2003-01-03 20:20:47 +00:00
Hallvard Furuseth
5ca8773a8b
Fix typos.
2002-12-16 07:31:13 +00:00
Pierangelo Masarati
df5d69df8f
allow a custom error log file for plugins by means of a slapd.conf directive; add very bare-bone back-monitor info about installed plugins
2002-12-14 15:04:37 +00:00
Howard Chu
143603690f
Added searchstack keyword description. (Sorry, I don't like the word "slab"...)
2002-12-12 23:39:21 +00:00
Hallvard Furuseth
54728f367e
Implement user-defined tagging attribute options and ranges
2002-12-12 13:56:05 +00:00
Pierangelo Masarati
9cce5e4c98
a skeleton of slapd.conf directives for SLAPI configuration (lot to do)
2002-12-07 18:03:13 +00:00
Pierangelo Masarati
8473f6e778
set keyword to noEstimate and document it
2002-11-21 20:57:00 +00:00
Pierangelo Masarati
59aea47963
improve limits handling and consistency; return "Admin limit exceeded" instead of "Unwilling to perform"
2002-11-21 12:58:59 +00:00
Pierangelo Masarati
b9e442d7de
clarify how to specify no limits
2002-10-31 11:26:19 +00:00
Pierangelo Masarati
53e1930fd0
use keyword "unlimited" instead of -1 for no limits
2002-10-31 09:57:24 +00:00
Kurt Zeilenga
c14cbc1fb7
Update anon
2002-10-26 02:53:36 +00:00
Kurt Zeilenga
6bc33d28c0
Note --without-threads limitation
2002-10-16 16:54:27 +00:00
Kurt Zeilenga
023d0e2a5c
Rework unprotected simple bind checks
2002-10-08 19:03:18 +00:00
Kurt Zeilenga
36fca96695
if "disallow bind_simple_unprotected", require at least SSF of 2
2002-10-08 01:06:49 +00:00
Kurt Zeilenga
90e320398a
Clarify that "security ssf=n" applies to "disallow bind_simple_unprotected".
2002-10-08 00:51:19 +00:00
Kurt Zeilenga
68aebc05c9
Clean up hash password scheme stuff
2002-09-20 17:27:08 +00:00
Kurt Zeilenga
11a07153d6
Add some clarification as to what hash algorithms are used
...
with each password-hash scheme.
2002-09-20 17:12:58 +00:00
Kurt Zeilenga
2ca678ea2e
More LDAPNOINIT statement to top of DESCRIPTION
2002-09-04 20:59:57 +00:00
Pierangelo Masarati
5a0ba6e429
document another (optional) config directive
2002-08-31 10:27:49 +00:00
Pierangelo Masarati
f11c6b27e7
Final run of changes to back-sql; IBM db2 support has been tested.
...
Now related ITSes need be audited and possibly closed.
Enhancements:
- re-styled code for better readability
- upgraded backend API to reflect recent changes
- LDAP schema is checked when loading SQL/LDAP mapping
- AttributeDescription/ObjectClass pointers used for more efficient
mapping lookup
- bervals used where string length is required often
- atomized write operations by committing at the end of each operation
and defaulting connection closure to rollback
- added LDAP access control to write operations
- fully implemented modrdn (with rdn attrs change, deleteoldrdn,
access check, parent/children check and more)
- added parent access control, children control to delete operation
- added structuralObjectClass operational attribute check and
value return on search
- added hasSubordinate operational attribute on demand
- search limits are appropriately enforced
- function backsql_strcat() has been made more efficient
- concat function has been made configurable by means of a pattern
- added config switches:
- fail_if_no_mapping write operations fail if there is no mapping
- has_ldapinfo_dn_ru overrides autodetect
- concat_pattern a string containing two '?' is used
(note that "?||?" should be more portable
than builtin function "CONCAT(?,?)")
- strcast_func cast of string constants in "SELECT DISTINCT statements (needed by PostgreSQL)
- upper_needs_cast cast the argument of upper when required
(basically when building dn substring queries)
Todo:
- add security checks for SQL statements that can be injected (?)
- re-test with previously supported RDBMs
- replace dn_ru and so with normalized dn (no need for upper() and so
in dn match)
- implement a backsql_normalize() function to replace the upper()
conversion routines
- note that subtree deletion, subtree renaming and so could be easily
implemented (rollback and consistency checks are available :)
- implement "lastmod" and other operational stuff (ldap_entries table ?)
2002-08-23 08:54:08 +00:00
Howard Chu
33d5c0abd7
Fix errors in replica directive
2002-08-22 20:32:09 +00:00
Pierangelo Masarati
76e936e274
reflect recent additions to backend configuration
2002-08-13 17:13:57 +00:00
Howard Chu
1be4ab9d07
ITS#1893 Add (terse) schemadn description
2002-08-10 04:09:28 +00:00
Kurt Zeilenga
9c28c9b361
Zap LDAPv2-only stuff
2002-08-08 03:01:14 +00:00
Kurt Zeilenga
99133f7944
Fix a few typos
2002-07-10 03:12:47 +00:00
Kurt Zeilenga
b839e6fc8b
Remove misleading (untrue) text about known syntax OID macros.
2002-06-27 16:27:07 +00:00
Kurt Zeilenga
9a38d98d37
Add option to disallow unprotected simple authentication.
...
Add protected simple authentication as a "strong" mechanism.
2002-06-17 22:18:27 +00:00
Howard Chu
98b1e09c44
Note that TLS_CERT and TLS_KEY are user-only options.
2002-06-16 12:10:23 +00:00
Howard Chu
dca986280e
Fix typo in previous commit
2002-06-16 07:29:06 +00:00
Howard Chu
0f0c268c6d
Minor cleanup and reformat, added TLS options.
2002-06-16 07:19:31 +00:00
Kurt Zeilenga
220b41bc91
Patch: Bugs with back-ldap/meta mappings (ITS#1787)
...
================
Written by Hallvard B. Furuseth and placed into the public domain.
This software is not subject to any license of the University of Oslo.
================
manpage patch for ITS#1787.
2002-06-14 20:41:40 +00:00
Howard Chu
7b9d3b4a26
Added sasl-authz-policy
2002-06-14 11:02:57 +00:00
Kurt Zeilenga
b43ad1dd0e
Generate man page date from version.sh
2002-06-13 03:59:10 +00:00
Kurt Zeilenga
faf91f1f1f
Update to the 'gentle SIGHUP' patch. (ITS#1679)
...
- Let write operations return unwilling-to-perform after
'gentle shutdown' has been initiated.
- Change -1 to 2 in slapd_gentle_shutdown and slapd_shutdown, since
sig_atomic_t can be unsigned (ITS#1736). The 'gentle SIGHUP' patch
is older than ITS#1736 but was applied later, so it reintroduced
the problem.
Hallvard B. Furuseth <h.b.furuseth@usit.uio.no>, June 2002.
2002-06-12 15:43:19 +00:00
Kurt Zeilenga
dfeac21baa
Add {CLEARTEXT} to password-hash possibilities
2002-06-12 00:50:28 +00:00
Kurt Zeilenga
133a4ebbc4
Note that rootpw can only be set if rootdn is under suffix.
2002-06-08 18:40:36 +00:00
Kurt Zeilenga
951ca2bd68
Patch: Non-unique msgid for abandon in back-<shell,tcl> (ITS#1793)
...
================
Written by Hallvard B. Furuseth and placed into the public domain.
This software is not subject to any license of the University of Oslo.
================
It has just occurred to me - duh - that the process ID of a back-shell
command is a perfectly good unique ID for it, and more useful than
any connection id/message id thingy. Doesn't need extra arguments
to the shell commands either, except a pid: line to abandon.
And msgid: can still be removed in a future version.
Here is a patch.
Hallvard B. Furuseth <h.b.furuseth@usit.uio.no>, May 2002.
2002-06-05 16:40:16 +00:00