[36888] in Kerberos

home help back first fref pref prev next nref lref last post

RE: ldap backend - krbPrincipalName substring search

daemon@ATHENA.MIT.EDU (Paul B. Henson)
Mon Apr 6 18:09:37 2015

From: "Paul B. Henson" <henson@acm.org>
To: "=?iso-8859-1?Q?'Michael_Str=F6der'?=" <michael@stroeder.com>,
        <kerberos@mit.edu>
In-Reply-To: <55228E5F.7090703@stroeder.com>
Date: Mon, 6 Apr 2015 15:09:14 -0700
Message-ID: <149801d070b6$52f98f30$f8ecad90$@acm.org>
MIME-Version: 1.0
Content-Language: en-us
Content-Type: text/plain; charset="iso-8859-1"
Errors-To: kerberos-bounces@mit.edu
Content-Transfer-Encoding: 8bit

> From: Michael Ströder
> Sent: Monday, April 06, 2015 6:47 AM
> 
> 1. Make sure to be aware of this schema declaration bug:
> http://krbdev.mit.edu/rt/Ticket/Display.html?id=8150

Hmm, looks like Greg just replied to that bug? What is the expected failure?
Would the index be ignored and entries be found, but at the cost of a full
scan? Or would the index be invalid and result in the entries not being
found at all?

> 2. OpenLDAP's "not indexed" messages do not mean that you should enable
> indexing without first analyzing the search request sent.

Understood; part of my analysis is figuring out what Kerberos functionality
might avail of that index :).

Thanks…


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos


home help back first fref pref prev next nref lref last post