Re: [squid-users] Groupauthentification

From: Henrik Nordstrom <hno@dont-contact.us>
Date: 07 Apr 2003 16:59:40 +0200

Not without extending the squid_ldap_group helper with support for
nested groups. This requires some programming, and will quite negatively
impair performance of group lookups when enabled..

However, if these sub-groups have a attribute which identifies the base
group then searching should work just as if the members was listed in
the base group object. Just change the cn= part of the group filter to
the common attribute which identifies the group in both the base group
object and the sub-groups..

What does a typical base group and sub-group objects look like in
detail? (cut away uninteresting member= attributes please..)

Regards
Henrik

mån 2003-04-07 klockan 13.32 skrev Stefan.Vogel@temic.com:
> Hello,
>
> After I finally have squid 2.5stable2 running with the ldap_group-Helper
> against my LotusDomino5.0.11-Server, I am running in an other problem:
>
> because the membersfiled of a group in Notes is restricted in its size,
> usally there is one group, that has a few other groups as members. in this
> other groups, the real persons are members.
>
> Is there a way to check this with a single acl?
> I don't want to create 20 ACLs to check this.
>
> Regards
> Stefan

-- 
Free Squid-users support provided by Henrik Nordström <hno@squid-cache.org>
Donations welcome if you consider my Free Squid support helpful.
https://www.paypal.com/xclick/business=hno%40squid-cache.org
If you need commercial Squid support or cost effective Squid and
firewall appliances please refer to MARA Systems AB, Sweden
http://www.marasystems.com/, info@marasystems.com
Received on Mon Apr 07 2003 - 08:59:47 MDT

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 17:14:44 MST