Russell Coker wrote:
The other is to include the UID but not the user-name
in the dn, as
the dn MUST be unique an attempt to add a second object with the
same UID will fail at the LDAP protocol level.
Is this allowed by the RFC2307 / RFC2307bis schemas?
Otherwise, I have no strong objection to that approach.
UIDs are 32bit nowadays. So there will still be a lot
of spare space.
On linux, at least. IIRC I ran into problems with negative UIDs when
backing up to opensolaris[0]. Other than that, I agree.
[0] whatever the hell this is -- osol9 IIRC:
SunOS zhug 5.11 snv_111b i86pc i386 i86pc Solaris