<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel>
	  <title>Ask MetaFilter questions tagged with ldap</title>
      <link>http://ask.metafilter.com/tags/ldap</link>
      <description>Questions tagged with 'ldap' at Ask MetaFilter.</description>
	  <pubDate>Thu, 05 Nov 2009 12:05:13 -0800</pubDate> <lastBuildDate>Thu, 05 Nov 2009 12:05:13 -0800</lastBuildDate>

      <language>en-us</language>
	  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
	  <ttl>60</ttl>	  
	<item>
	<title>LDAP ADAM Active Directory combining</title>
	<link>http://ask.metafilter.com/137337/LDAP%2DADAM%2DActive%2DDirectory%2Dcombining</link>	
	<description>how can i combine multiple AD domains into one directory for application authentication? can i use ADAM? we have some applications that need to authenticate users against our AD.  we have 3 domains that are not child domains of any one master domain.  the application can only use one directory at at time.  can these 3 AD domains be combined into one directory, using ADAM or some other LDAP application?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2009:site.137337</guid>
	<pubDate>Thu, 05 Nov 2009 12:05:13 -0800</pubDate>
	<category>active</category>
	<category>directory</category>
	<category>ldap</category>
	<dc:creator>fumbducker</dc:creator>
	</item>
	<item>
	<title>How not to store plaintext passwords?</title>
	<link>http://ask.metafilter.com/134955/How%2Dnot%2Dto%2Dstore%2Dplaintext%2Dpasswords</link>	
	<description>Best practices for storing OracleDB/mysql/ldap/smtp/etc... system passwords for enterprise application integration use? I&apos;m working with a vendor who currently is storing passwords in plain text in configuration files. &lt;br&gt;
&lt;br&gt;
If you&apos;ve ever configured Wordpress you are familiar with how your mysql password gets placed in plain text in the wp-config.php file.&lt;br&gt;
This vendor is doing a similar thing for mysql, ldap, smtp, etc...&lt;br&gt;
&lt;br&gt;
This has made some people uncomfortable.&lt;br&gt;
&lt;br&gt;
I&apos;d like some suggestions for best practices to minimize the use of passwords in plaintext (or trivially encoded text) in text configuration files.&lt;br&gt;
&lt;br&gt;
These passwords are being used to drive external databases, ldap auth, smtp sending, etc...&lt;br&gt;
&lt;br&gt;
Their Java / Tomcat application is expected to be running 24/7 as a Server. This particular  instance will be on Windows Server 2003 though Linux is also supported.&lt;br&gt;
&lt;br&gt;
It would be nice if it would be possible to have unattended restarting of the application without a user having to enter in a master password, but if that is the only solution we may be comfortable with it.&lt;br&gt;
&lt;br&gt;
Some background:&lt;br&gt;
&lt;br&gt;
The application uses LDAP to authenticate users (and hence has the LDAP system password in a configuration file)&lt;br&gt;
&lt;br&gt;
The application stores its data in a SQL database (Oracle in this case, though they also support mysql. We have to stay on Oracle)&lt;br&gt;
&lt;br&gt;
The application sends mail using SMTP&lt;br&gt;
&lt;br&gt;
Thanks.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2009:site.134955</guid>
	<pubDate>Thu, 08 Oct 2009 09:56:51 -0800</pubDate>
	<category>cleartext</category>
	<category>ldap</category>
	<category>mysql</category>
	<category>oracle</category>
	<category>passwords</category>
	<category>plaintext</category>
	<category>security</category>
	<category>smtp</category>
	<dc:creator>bottlebrushtree</dc:creator>
	</item>
	<item>
	<title>How to centralize adminsitration of multiple Unix machines (and others)?</title>
	<link>http://ask.metafilter.com/132383/How%2Dto%2Dcentralize%2Dadminsitration%2Dof%2Dmultiple%2DUnix%2Dmachines%2Dand%2Dothers</link>	
	<description>I&apos;m curious as to what are the current &quot;best practices&quot; when it comes to centralized administration of a network of Unix (primarily Linux, but not necessarily so) machines? Essentially, what is the equivalent of Active Directory for a network with one or more Unix hosts? The immediate answer I come up with would be something like &lt;a href=&quot;http://www.howtoforge.com/linux_ldap_authentication&quot;&gt;OpenLDAP plus PAM&lt;/a&gt; but what I&apos;m looking for is the suite of tools (GUI and CLI apps) for managing the directory, deploying software, centralizing sign-on and security, managing printers, etc. 

In a perfect world, I would like to centralize administration of Windows, Unix, and OS X machines via a single directory service, though I imagine such a solution would be expensive and/or cumbersome if it even existed. Or is this something &lt;a href=&quot;http://wiki.samba.org/index.php/Samba4&quot;&gt;Samba 4&lt;/a&gt; will do?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2009:site.132383</guid>
	<pubDate>Wed, 09 Sep 2009 11:45:34 -0800</pubDate>
	<category>ActiveDirectory</category>
	<category>administration</category>
	<category>LDAP</category>
	<category>linux</category>
	<category>OSX</category>
	<category>Samba</category>
	<category>unix</category>
	<category>windows</category>
	<dc:creator>Imhotep is Invisible</dc:creator>
	</item>
	<item>
	<title>Rebuilding Ubuntu Server 8.04 Help!!</title>
	<link>http://ask.metafilter.com/114457/Rebuilding%2DUbuntu%2DServer%2D804%2DHelp</link>	
	<description>I recently lost a raid array on a ubuntu 8.04 server forcing me to rebuild it from scratch and/or restore data from backup. (I have copies of /var, /etc, and /home) The problem is I can&apos;t seem to rebuild the server so that it works exactly the way it did before, this is killing me!!  (fyi... I inherited this system).  My specific problem seems to be with Samba.    I&apos;m looking for help in two different ways...  help 1) either figure out how to restore this system with what I&apos;ve got backed up.  Or fix samba so it works.  See details below: The previous system was Ubuntu 8.04.  I&apos;ve got good backups of /etc /var and /home. &lt;br&gt;
&lt;br&gt;
What I want to do is simply build a basic install of ubuntu server 8.04 and restore /etc and /var.  But this fails, because I am missing packages.  I don&apos;t know what packages need to be installed to make this system complete.  It seems like there should be something in my backup of /var/lib/apt should be able to tell me what packages are missing, need to installed, or reinstalled.&lt;br&gt;
&lt;br&gt;
If I can&apos;t restore the server with the strategy above, I guess I need to rebuild the thing from scratch... which is what I&apos;ve been doing and leads me to my next problem: Samba, LDAP, name resolution, and/or other unknown problems....&lt;br&gt;
&lt;br&gt;
Samba user authenticate to openldap directory on another network.  I&apos;ve got nss working.  I can do a #getent passwd and see ldap data.  I&apos;ve got my secrets.tdb setup and it seems like samba can query ldap.  But I&apos;m not sure all the naming services are working.  In my /var/log/samba/log.smbd I see some errors  &quot;warning: failed to create BUILTIN\Administrators group! Can Winbind allocate gids?&quot;. (smb.conf log level = 5)&lt;br&gt;
&lt;br&gt;
anyhow, I can post whatever log files or config files that might be helpful.  &lt;br&gt;
&lt;br&gt;
Another interesting clue to what might be wrong.... I have a win2k and wink3 server that both have shares with permissions for users from the domain that the failed Samba server was advertising.   On the windows servers I&apos;ve added the IP address of the WINS server on the network that the LDAP server is located... now the windows servers at least show user info in the permissions dialog box for the shares.  But folks still can not authenticate to these windows shares... access is denied because of invalid credentials (or something).&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
Any ideas?&lt;br&gt;
&lt;br&gt;
TIA,&lt;br&gt;
Dave</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2009:site.114457</guid>
	<pubDate>Tue, 17 Feb 2009 11:40:27 -0800</pubDate>
	<category>804</category>
	<category>ldap</category>
	<category>nss</category>
	<category>pam</category>
	<category>restore</category>
	<category>samba</category>
	<category>system</category>
	<category>ubuntu</category>
	<dc:creator>purenitrous</dc:creator>
	</item>
	<item>
	<title>openldap password change webapp?</title>
	<link>http://ask.metafilter.com/109442/openldap%2Dpassword%2Dchange%2Dwebapp</link>	
	<description>Need a webapp to allow my users to change their own LDAP passwords. I&apos;ve got slapd (openldap) running on an Ubuntu server. I have various webapps (mediawiki, trac, cacti, etc.) that auth against slapd. I&apos;d like my users to be able to change their own LDAP passwords by going to a webapp, and I thought I might be able to use phpldapadmin for that, but no dice. Does anybody know of a (preferably standalone) webapp for allowing users to change their LDAP passwords? I do not currently give my users login shells, and most of them wouldn&apos;t be comfortable using a CLI to change a password anyway. If you know of something packaged for Fedora (the OS), that&apos;s good, too.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.109442</guid>
	<pubDate>Wed, 17 Dec 2008 08:17:24 -0800</pubDate>
	<category>LDAP</category>
	<category>openldap</category>
	<category>password</category>
	<category>slapd</category>
	<category>webapp</category>
	<dc:creator>tarheelcoxn</dc:creator>
	</item>
	<item>
	<title>cross platform shared address book</title>
	<link>http://ask.metafilter.com/103892/cross%2Dplatform%2Dshared%2Daddress%2Dbook</link>	
	<description>What is the best / easiest shared cross platform shared address book solution out there? I&apos;m a part of a small organization (50 people) spread across the country. Our company uses Linux (Thunderbird), Mac (Mail.app) and Windows (Outlook). What is the best solution to setup that will allow all of use to share a common contact list? I&apos;m assuming LDAP will be used for address lookups but what is the best way to allow people to add entries. If not a LDAP based solution, what else can we use?</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.103892</guid>
	<pubDate>Fri, 10 Oct 2008 06:29:21 -0800</pubDate>
	<category>addressbook</category>
	<category>contacts</category>
	<category>email</category>
	<category>ldap</category>
	<category>shared</category>
	<dc:creator>cowmix</dc:creator>
	</item>
	<item>
	<title>Anyone had any success using Apple&apos;s portable home directory feature without OS X server or a linux server?</title>
	<link>http://ask.metafilter.com/94601/Anyone%2Dhad%2Dany%2Dsuccess%2Dusing%2DApples%2Dportable%2Dhome%2Ddirectory%2Dfeature%2Dwithout%2DOS%2DX%2Dserver%2Dor%2Da%2Dlinux%2Dserver</link>	
	<description>I&apos;ve read &lt;a href=&quot;http://www.emmes-world.de/mac-afp-homes.html&quot;&gt;this&lt;/a&gt;, &lt;a href=&quot;http://mattfleming.com/node/190&quot;&gt;this&lt;/a&gt;, &lt;a href=&quot;http://www.radiotope.com/node/22&quot;&gt;this&lt;/a&gt; and a bunch of other sites. I&apos;ve got a Mac Pro and a Powerbook I&apos;d like to share home directories over, but I&apos;d rather not purchase OS X Server or get a small machine up and running Linux to deal with authentication (LDAP). Anyone authenticate locally, but still use the portable home directories?

Alternatively, anyone just unison their entire /user/ directory?

Thanks!</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.94601</guid>
	<pubDate>Fri, 20 Jun 2008 16:09:00 -0800</pubDate>
	<category>ldap</category>
	<category>mac</category>
	<category>osx</category>
	<category>portablehomedirectory</category>
	<category>sync</category>
	<category>unison</category>
	<dc:creator>Brian Puccio</dc:creator>
	</item>
	<item>
	<title>Can Address Book (OSX) show all of the LDAP entries in the given search base?</title>
	<link>http://ask.metafilter.com/82293/Can%2DAddress%2DBook%2DOSX%2Dshow%2Dall%2Dof%2Dthe%2DLDAP%2Dentries%2Din%2Dthe%2Dgiven%2Dsearch%2Dbase</link>	
	<description>Creating a shared address book on an LDAP server to be accessed from Mac clients. Can I somehow get the directory to show all of the entries without having to search for one? Goal: Company address book stored in the LDAP server on OSX Server, searchable and &lt;em&gt;browesable&lt;/em&gt; by anyone authenticated.&lt;br&gt;
&lt;br&gt;
Here&apos;s my problem. All of the tutorials I&apos;ve found end with Address Book connected to the LDAP server, and the entries stored, but you have to type a name to get it to show up. There is no &lt;strong&gt;list of entries in the directory&lt;/strong&gt;.*&lt;br&gt;
&lt;br&gt;
How can I get Address Book to show all of the LDAP entries in the given search base? This is a very small company, there is no danger of queries returning thousands of entries.&lt;br&gt;
&lt;br&gt;
&lt;small&gt;This is not going to fly with the client. &quot;What do you mean I type in who I&apos;m looking for? I don&apos;t know who I&apos;m looking for, if I knew that I wouldn&apos;t be looking for them.&quot;&lt;/small&gt;</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2008:site.82293</guid>
	<pubDate>Tue, 29 Jan 2008 16:10:06 -0800</pubDate>
	<category>address</category>
	<category>addressbook</category>
	<category>ldap</category>
	<category>leopard</category>
	<category>mac</category>
	<category>osx</category>
	<category>xserve</category>
	<dc:creator>odinsdream</dc:creator>
	</item>
	<item>
	<title>Workgroup Manager</title>
	<link>http://ask.metafilter.com/40574/Workgroup%2DManager</link>	
	<description>I&apos;m looking for a great end-user web-based LDAP interface.  Something like &lt;a href=&quot;https://gosa.gonicus.de/&quot;&gt;GOsa&lt;/a&gt; or simpler, but that will run on OSX.  For scale &lt;a href=&quot;http://ldapadmin.sourceforge.net/&quot;&gt;LDAP Admin&lt;/a&gt; is too low level.  Thanks!</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2006:site.40574</guid>
	<pubDate>Tue, 20 Jun 2006 12:36:56 -0800</pubDate>
	<category>LDAP</category>
	<category>web</category>
	<dc:creator>The Jesse Helms</dc:creator>
	</item>
	<item>
	<title>LDAP Netgroups Help?</title>
	<link>http://ask.metafilter.com/39343/LDAP%2DNetgroups%2DHelp</link>	
	<description>I am looking for information on setting LDAP based netgroups for a fedora core multi-user environment.  We are currently using a listfile setup, but would like to migrate to LDAP.  I have a couple of books and searched all over google, but have not found a good tutorial to do this.

Nate</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2006:site.39343</guid>
	<pubDate>Thu, 01 Jun 2006 15:15:46 -0800</pubDate>
	<category>administration</category>
	<category>LDAP</category>
	<category>netgroups</category>
	<category>unix</category>
	<dc:creator>dyno04</dc:creator>
	</item>
	<item>
	<title>Active Directory (LDAP) + Linux = passwords?</title>
	<link>http://ask.metafilter.com/38966/Active%2DDirectory%2DLDAP%2DLinux%2Dpasswords</link>	
	<description>Where do I find doccos that tell me how to authenticate my PAM-capable unix boxen against Microsoft&apos;s Active Directory?
Microsoft says &quot;well, just upgrade your 2003 Server Enterprise to 2003 Server Enterprise R2 !&quot;  which sounds like paying &amp;gt;$10,000 just so I can get a couple-hundred byte snap-in for AD.&lt;br&gt;
&lt;br&gt;
I&apos;ve seen very little documentation on this, although I&apos;d think it would be very popular in a hetrogenous office network.  You&apos;ve already got a Domain Controller, running Active Directory, that everyone&apos;s workstation authorizes against.  You&apos;ve got a farm of Linux machines that can do the pam_ldap thing, and Active Directory speaks LDAP.  However, just pointing pam_ldap at AD doesn&apos;t work because AD is missing stuff.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2006:site.38966</guid>
	<pubDate>Fri, 26 May 2006 11:11:19 -0800</pubDate>
	<category>activedirectory</category>
	<category>ldap</category>
	<category>linux</category>
	<category>pam</category>
	<dc:creator>Mozai</dc:creator>
	</item>
	<item>
	<title>Message Board Software</title>
	<link>http://ask.metafilter.com/34238/Message%2DBoard%2DSoftware</link>	
	<description>Can anyone reccommend message board software that can run on Apache and authenticate through Active Directory / LDAP? For my needs this doesn&apos;t have to be free, but needs to be production quality.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2006:site.34238</guid>
	<pubDate>Mon, 13 Mar 2006 06:28:07 -0800</pubDate>
	<category>ldap</category>
	<category>messageboard</category>
	<category>web</category>
	<dc:creator>yeahyeahyeahwhoo</dc:creator>
	</item>
	<item>
	<title>Home Sync and Mac OS X</title>
	<link>http://ask.metafilter.com/33927/Home%2DSync%2Dand%2DMac%2DOS%2DX</link>	
	<description>Does anyone know how to get the Home Sync function in Mac OS X working? I know you need Mac OS X Server working, which I happen to have access too. I read something about needing to setup at LDAP server, which I&apos;m not sure how to do (but willing to learn)&lt;br&gt;
&lt;br&gt;
I&apos;d like to be able to get home, open up my iBook, and have it sync the home directory to a server at home, and then go to work, have it sync to a server as well.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2006:site.33927</guid>
	<pubDate>Tue, 07 Mar 2006 14:05:00 -0800</pubDate>
	<category>apple</category>
	<category>homesync</category>
	<category>ldap</category>
	<category>macosx</category>
	<category>server</category>
	<dc:creator>jasmeet</dc:creator>
	</item>
	<item>
	<title>proxy server authenticating w/LDAP?</title>
	<link>http://ask.metafilter.com/22081/proxy%2Dserver%2Dauthenticating%2DwLDAP</link>	
	<description>Anybody ever set up a proxy server that authenticates using an external LDAP server - so that (for example) off-campus university students can access third-party web services that are restricted to campus IP addresses?
&lt;small&gt;&lt;small&gt;Well, it is worth a shot!&lt;/small&gt;&lt;/small&gt;&lt;br&gt;
&lt;br&gt;
I&apos;m guessing that I would be using Squid, but the configuration is intimidating the heck out of me. RTFM? Or do you have any pointers? I&apos;m not interested in caching - just authenticating and presenting a campus IP number to the third party services.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2005:site.22081</guid>
	<pubDate>Tue, 02 Aug 2005 17:56:46 -0800</pubDate>
	<category>authentication</category>
	<category>LDAP</category>
	<category>proxy</category>
	<category>Squid</category>
	<dc:creator>spock</dc:creator>
	</item>
	<item>
	<title>polling LDAP for changes</title>
	<link>http://ask.metafilter.com/19734/polling%2DLDAP%2Dfor%2Dchanges</link>	
	<description>LDAPFilter: I&apos;m writing an application that stores its configuration in an LDAP server. I&apos;d like to have it poll the server and reload itself when the configuration changes. What&apos;s the best way to do this? My product will run on eDirectory, but I&apos;d like to make it as compatible with other servers (primarily OpenLDAP) as possible. If I were just worried about eDirectory then I&apos;d simply use the &lt;i&gt;Revision&lt;/i&gt; attribute because it is incremented each time there is a change. Then I noticed that both OpenLDAP and eDirectory include the operational attribute &lt;i&gt;modifyTimestamp&lt;/i&gt; which seems like exactly what I needed... at first glance.&lt;br&gt;
&lt;br&gt;
The problem is with eDirectory, partitions, and replicas. The server I connect to will only hold a sub-reference of a partition with multiple read-write replicas. Thus, if I modify an object and then immediately read the &lt;i&gt;modifyTimestamp&lt;/i&gt; back then I&apos;m not guaranteed that I&apos;ll hit the same replica for both operations (and I might get the old timestamp instead of the new one).&lt;br&gt;
&lt;br&gt;
Couple solutions I&apos;ve come up with: (1) just fudge the value in my software by 30 seconds, but then I&apos;m relying on the fact that my machine has a synced time with the tree. (2) Sleep in my software for 30 seconds and then read the value out, but I hate to add extra delay, especially since it may be perceptable to the user. (3) Loop over a search until I get the updated timestamp. (4) Force the administrator to point my software at a single LDAP server holding a read-write replica, but then I lose redundancy.&lt;br&gt;
&lt;br&gt;
I just wish OpenLDAP had an equivalent to the Counter syntax. Any developers out there have a good solution to this? Or should I just hack in one of 1-4 above? I want to write robust software, but I&apos;m torn on what to do.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2005:site.19734</guid>
	<pubDate>Thu, 09 Jun 2005 19:56:54 -0800</pubDate>
	<category>ldap</category>
	<category>polling</category>
	<dc:creator>sbutler</dc:creator>
	</item>
	<item>
	<title>Apache, LDAP, ActiveDirectory</title>
	<link>http://ask.metafilter.com/11397/Apache%2DLDAP%2DActiveDirectory</link>	
	<description>&lt;strong&gt;Apache, LDAP, ActiveDirectory and You:&lt;/strong&gt; I have an &lt;a href=&quot;http://projects.edgewall.com/trac&quot;&gt;application&lt;/a&gt; running on Apache. I would like to restrict access to the folder(s) it runs in by authenticating users against our Windows ActiveDirectory server, but I&apos;m having trouble crafting the right URL. I have &lt;a href=&quot;http://httpd.apache.org/docs-2.0/mod/mod_auth_ldap.html&quot;&gt;mod_auth_ldap&lt;/a&gt; up and running and I&apos;m blocking access to a given folder with a &lt;Location&gt; block in my httpd2.conf file. I&apos;m providing a AuthLDAPBindDN and password combo in that block and providing a URL to the AD/LDAP server. It looks something like this:&lt;br&gt;
&lt;br&gt;
 AuthLDAPURL ldap://location.company.com:389/&lt;br&gt;
&lt;br&gt;
and I&apos;ve tried any number of things after that. I don&apos;t really understand how to form the rest of the URL to tell it &quot;search this AD server for the name the user provides inside the Users subtree.&quot; I&apos;ve tried using a Windows utility called &quot;ldp.exe&quot; to form queries, but it&apos;s less than helpful. It provides some feedback, but doesn&apos;t let you build actual URLs, forcing you to use its form inputs. I tried connecting with Thunderbird&apos;s address book as it provides a bit more of a &quot;raw&quot; interface, but I couldn&apos;t even connect with that.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2004:site.11397</guid>
	<pubDate>Mon, 01 Nov 2004 15:13:25 -0800</pubDate>
	<category>activedirectory</category>
	<category>apache</category>
	<category>ldap</category>
	<category>security</category>
	<dc:creator>yerfatma</dc:creator>
	</item>
	<item>
	<title>Multiple contact lists are driving me crazy!</title>
	<link>http://ask.metafilter.com/10203/Multiple%2Dcontact%2Dlists%2Dare%2Ddriving%2Dme%2Dcrazy</link>	
	<description>If you use IMAP to access your mail from multiple computers, how do you deal with the different contact lists?  I have out-of-sync lists everywhere and it&apos;s driving me crazy.</description>
	<guid isPermaLink="false">tag:ask.metafilter.com,2004:site.10203</guid>
	<pubDate>Wed, 15 Sep 2004 08:58:21 -0800</pubDate>
	<category>addressbooks</category>
	<category>imap</category>
	<category>ldap</category>
	<dc:creator>smackfu</dc:creator>
	</item>
	
	</channel>
</rss>

