dendrobatesI am thinking of making changes to the slapd package.  Adding password policy support, and configuring the suffix and perhaps some other things at during package config.03:35
dendrobatesAnyone have any ideas?03:35
dendrobatesplease, not everyone at once.03:48
robertjdendrobates: you mean storing those values in debconf?03:50
shawarmadendrobates: We already do the suffix config stuff?03:51
dendrobatesshawarma: for some reason I am only prompted for the manager password.  but I saw the suffix stuff in the template file.03:52
shawarmadendrobates: Probably a priority thing.03:53
shawarmadendrobates: debconf questions have different priorities. We only has questions of high or critical priority.03:53
shawarmadendrobates: Possibly the suffix questions have lower priority.03:53
dendrobatesshawarma: I see, however that makes the created db need to be recreated in almost every case.03:54
shawarmadendrobates: Yup.03:54
dendrobateswhich makes asking the manager password useless, because it will get wiped out.03:55
dendrobatesI thought03:55
dendrobatesI thought I could use pam_ldap as an example, it does quite a bit more.03:56
=== robertj is still in the ignore-openldap and wait for fds or samba to mature
dendrobatesrobertj: as an actual ldap admin, what would you like to see in a default setup? Are you currently using openldap?03:57
robertjdendrobates: I am currently not although I did run a directory with a few thousand objects until just this year03:58
dendrobatesThere have been some major improvements in openldap, that should not be overlooked.03:58
robertjI'd like to see a default setup that just-works with no-questions asked, and a GtkAssistant (destructive is OK) for more advanced use cases03:58
dendrobatesand I don't completely trust redhat to do the right thing with fds.03:59
dendrobatesI do agree that fds is more enterprise ready.04:00
dendrobatesor at least sun one was.04:00
robertjdendrobates: for most users, I don't think they really care what their base is04:00
robertjthey just want an ou=Users,dc=local and thats fine for them04:00
dendrobatesrobertj: if they don't care, do they even need ldap?04:01
robertjdendrobates: sure they do, they want to do roaming user profiles and all the other stuff they can do on MS Server 2003 with a gui04:01
robertjI see debconf kinda in the middle, and maybe not very useful04:01
robertjreally advanced users will just bust out vim anyway04:02
robertjso that basically leaves debconf for preseeding and intermediate users04:02
dendrobatestrue, but I've seen even seasoned admins that seem to have a mind block when it comes to directory services.04:02
robertjdendrobates: I mean directory admins specifically04:03
robertjif they are web guys, and they need an ldap for their new web app to auth of off, then they probably want to install the package, install the addon, and have it just work04:03
robertjdc=local is just fine for those folks04:03
dendrobatesI would like to see pam_ldap and nss_ldap be given a url/hostname, and autoconfigure themselves, prompting when necessary.04:04
robertjdendrobates: that would be nice, those are more useful because they are sensible to preseed04:05
robertjthe actual slapd, don't see much benefit there04:05
dendrobatesI will look into GtkAssistant.  I have never used it.  The real benefit I see with slapd would be configuring certain modules.04:06
