nufw-users
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Nufw-users] openldap configuration


From: Francesco Varano
Subject: [Nufw-users] openldap configuration
Date: Wed, 11 Feb 2009 11:38:43 +0100

Dear all,
 i'm having some troubles configuring ldap acls with openldap server.
 
 i installed nuface and configured everything following the docs, but
i'm having some problems with ldap indexes.

 If i do not use index i find plenty of these messages
in /var/log/syslog:

slapd[2418]: <= bdb_inequality_candidates: (SrcIPStart) not indexed 
slapd[2418]: <= bdb_inequality_candidates: (SrcIPEnd) not indexed 
slapd[2418]: <= bdb_inequality_candidates: (DstIPStart) not indexed 
slapd[2418]: <= bdb_inequality_candidates: (DstIPEnd) not indexed 
slapd[2418]: <= bdb_equality_candidates: (Proto) not indexed 
slapd[2418]: <= bdb_inequality_candidates: (DstPortStart) not indexed 
slapd[2418]: <= bdb_inequality_candidates: (DstPortEnd) not indexed 
slapd[2418]: <= bdb_equality_candidates: (InDev) not indexed 
slapd[2418]: <= bdb_inequality_candidates: (SrcIPStart) not indexed 
slapd[2418]: <= bdb_inequality_candidates: (SrcIPEnd) not indexed 
slapd[2418]: <= bdb_inequality_candidates: (DstIPStart) not indexed 
slapd[2418]: <= bdb_inequality_candidates: (DstIPEnd) not indexed 
slapd[2418]: <= bdb_equality_candidates: (Proto) not indexed 
slapd[2418]: <= bdb_inequality_candidates: (DstPortStart) not indexed 
slapd[2418]: <= bdb_inequality_candidates: (DstPortEnd) not indexed 
slapd[2418]: <= bdb_equality_candidates: (InDev) not indexed

else, if i define indexes in /etc/ldap/slapd.conf as suggested:

index OsName,OsRelease,OsVersion,AppSig,AppName pres,eq
index SrcIPStart,SrcIPEnd,DstIPStart,DstIPEnd pres,eq
index Proto,SrcPortStart,SrcPortEnd,DstPortStart,DstPortEnd pres,eq
index SrcPort,DstPort pres,eq

then alcs defined with nuface will not match.

Where am i wrong?

Thank you in advance for your help,
Best regards,
Francesco






reply via email to

[Prev in Thread] Current Thread [Next in Thread]