Re: LDAP configuration (Was: What do you want to do)

[Petter Reinholdtsen]
> Skolelinux is working on automatic LDAP configuration.  Authentication
> is already working, and we plan to enable LDAP on the email server and
> web services as well.  We ran into a more serious problem when we
> discovered that NSS-LDAP don't support netgroups.  We need netgroups.
> Another problem is the fact that the LDAP packages in Woody do not use
> SSL.  SSL is needed to avoid sending unencrypted passwords over the
> net.  A third problem is that it is impossible to umount /usr/ when
> using nss-ldap.  libldap is in /usr/lib/. :-(

The third problem is solved by replacing bash with ash as /bin/sh.

But I believe there is another problem lurking in the shadows.  I'm
told that automatic failover from one LDAP server to another to not
work in the OpenLDAP libraries.  Anyone know more?

