Re: URGENT! ldap_compare, passwords and NDS
| From: | Nick Talbott | Date: | Fri, 06 Oct 2000 07:52:25 +0000 |
| Subject: | Re: URGENT! ldap_compare, passwords and NDS | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-18843@lists.php.net to get a copy of this message | ||
Jamie
I've not used the Novell LDAP interface to NDS, and am not sure this may be
any help at all.
My understanding is that ldap_compare can be used with an anonymous bind to
the LDAP server. Unless there are server-side restrictions that disallow
it, an anonymous user can ask for verification that an attribute contains
the supplied value. If PHP queries the LDAP server as an anonymous user,
this would avoid you hitting the limitation of one authenticated bind per
user.
As an alternative, in the LDAP book (the Macmillan one by Tim Howes and Mark
Smith) there is a short C program that implements ldap_compare as a
stand-alone program that takes command line values and returns TRUE of
FALSE. So something else to try would be this program or a variant of it
and use one of PHP's external program execution functions to do the
validation.
If you have a moment, I'd like to know generally how successful you've been
using Novell's LDAP server. We've been using OpenLDAP for three years now
which maintains data for over 3,000 users, but we also have a big NDS tree
(Netware 4) that I'd find it very useful to be able to query, but have never
invested in the Netware LDAP server.
Regards
Nick Talbott
IT Policy and Strategy Manager, Powys County Council, UK
email nickt@powys.gov.uk
FAX +44 (0) 1597 824781
web http://www.powys.gov.uk and http://www.powysweb.co.uk
-----Original Message-----
From: Jamie Shields <J.Shields@Kingston.ac.uk>
To: php-general@lists.php.net <php-general@lists.php.net>
Date: 04 October 2000 10:54
Subject: [PHP] URGENT! ldap_compare, passwords and NDS
>Has anyone ever had any success with ldap_compare when using
>Novell's LDAP server as an interface to NDS?
>
>ldap_bind is out of the question for me as our users have a limited
>number of connections (1) and may already be logged in.
>
>ldap_unbind doesn't free up all the connection resources
>assosciated with the login (i.e. network address field in the user
>object). This result in failed logins and frustrated users/helpdesk ;-)
>
>Any help would be greatly appreciated.
>
>Jamie
>
>Jamie Shields
>
>Deputy Computing Officer
>Computer Resources Centre
>Faculty of Human Sciences
>Kingston University
>Phone: (0181) 547-2000 ex:2367
>http://humansciences.king.ac.uk
>
>--
>PHP General Mailing List (http://www.php.net/)
>To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
>For additional commands, e-mail: php-general-help@lists.php.net
>To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>