[LUGOS] LDAP problemz...

Gregor Ibic gregor.ibic at intelicom.si
Wed Oct 9 12:31:13 CEST 2002


Ocitno je v ldapsearch-u omejitev, da ti kdo ne DOS-a Ldap server.

Userji pa najverjetneje ne ldapsearch-ajo ampak uporabljajo kaksne GUI.
Si probal s tem GUI-om?

LP,
Gregor


Intelicom d.o.o.
Security software company
http://www.intelicom.si
email: info at intelicom.si
tel.: ++386 5 6309 158
fax.: ++386 5 6279 355

-----Original Message-----
From: Tadej Slemc [mailto:tadej at security.eu.org]
Sent: Wednesday, October 09, 2002 12:26 PM
To: lugos-list at lugos.si
Subject: [LUGOS] LDAP problemz...


Zivjo

Imam ene probleme z dostopom do ldap baze:

izvlecek iz slapd.conf:

database        ldbm
suffix          "ou=Visitors, o=domena.si"
rootdn          "cn=Manager, ou=Visitors, o=domena.si"
rootpw          secret
directory       /var/lib/ldap
index   mknickname,objectClass  eq
#access to dn="o=domena.si"
#       by dn="uid=userread,ou=admin,o=isp"  read
#       by dn="uid=userwrite,ou=admin,o=isp"  write
#       by dn="uid=useradmin,ou=admin,o=isp" write
#       by * none
access to * by * write

database        ldbm
suffix          "ou=admin, o=isp"
rootdn          "cn=Manager, ou=admin, o=isp"
rootpw          secret
directory       /var/lib/ldap/isp
index   objectClass     eq


v bazi iamm priblizno 21.000 zapisov

ce poizkusam z
ldapsearch -x -u -b "ou=visitors,o=domena.si" "objectclass=*" -D
"cn=Manager,ou=visitors,o=domena.si" -w secret

dobim popolnoma vse rezultate in na koncu 
# search result
search: 2
result: 0 Success

ce pa poizkusim npr z:
ldapsearch -x -u -b "ou=visitors,o=domena.si"
"objectclass=*" -D "uid=useradmin,ou=admin,o=isp" -w secret

pa dobim 501 zapis (isto ce te zapise nadomestim s popolnoma novimi) in na
oncu se:
# search result
search: 2
result: 4 Size limit exceeded

Isto ce to naredim s katerimkoli userjem ki ni Manager v
ou=visitors,o=domena.si.

Kaj naj naredim da ne bom dobival 'result: 4 Size limit exceeded'

Uporabljam pa OpenLDAP 2.0.23-4

LP

Tadej Slemc






More information about the lugos-list mailing list