Re: mod_authnz_ldap and env vars?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi Richard,

On 29/09/2007, Richard N. Fogle <rich@xxxxxxxxxxxx> wrote:
> Is there a way to acquire the group via code, like a server
> environment variable (e.g., like REMOTE_USER) of the group authorized
> by a require ldap-group (or any group)?  This would be extremely

I agree that it would be wonderful if something like "REMOTE_GROUP"
existed (as long as it's clear how multiple-group membership is
expressed). For administrators, I agree that the job is best done in
Apache (plus its LDAP caching can be used). Personally, I have patched
mod_auth_ldap.c as you suggested, so that the group matched by
'Require group' is added to the environment. This has been running
quite well. And what a relief it's been!! It is not quite as useful as
enumerating _all_ the groups that the principal belongs to, so any of
our applications that need this are still required to do their own
LDAP queries. Maybe this is not alwaysw so bad, since it means that
Apache does not waste time enumerating everybody's entire group
membership for every web hit! Overall, your request seems entirely
possible, but I have not contributed a patch back to Apache yet.

James.

---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx
   "   from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx
For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx


[Index of Archives]     [Open SSH Users]     [Linux ACPI]     [Linux Kernel]     [Linux Laptop]     [Kernel Newbies]     [Security]     [Netfilter]     [Bugtraq]     [Squid]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Samba]     [Video 4 Linux]     [Device Mapper]

  Powered by Linux