Closed Bug 371283 Opened 18 years ago Closed 18 years ago

Partitioning LDAP to allow creation of restricted accounts

Categories

(mozilla.org Graveyard :: Server Operations, task)

task
Not set
normal

Tracking

(Not tracked)

RESOLVED WONTFIX

People

(Reporter: clouserw, Assigned: justin)

Details

I've talked to Aravind about partitioning LDAP a couple of times, but never in an "official" capacity. Since a lot of people have asked me for an answer, and since it would solve a lot of our CMS issues, I'm posting this bug to drop a paper trail that I can point people to when they ask me for details. So, to recap our past conversations: Our goal would be to allow us to add ldap accounts for localizers from within a CMS. We wondered if we could partition LDAP so certain users could add LDAP accounts, but only for that small partition (the partition representing localizers, in this case). This would let us: - Add localizer accounts to LDAP on the fly from the CMS - Restrict the people adding the LDAP accounts to only that partition - Restrict the accounts that were created in that partition from accessing other stuff (intranet, etc.) - Ability to disable/delete accounts from that partition (if this isn't possible, we can handle that on the CMS side) Does this sound doable with our LDAP server, or are we treading on the impossible?
/me whispers "Despot v2 is the answer to everything!" (bug 353463)
OS: Other → All
This sounds like something to discuss at our triage meeting on Tuesday...
Assignee: server-ops → aravind
We are waiting to see if this is needed after our Thursday meeting about the CMS. Will comment back here after we have more info.
Assignee: aravind → justin
Don't need this for the CMS as IT will create tickets. Closing this WONTFIX.
Status: NEW → RESOLVED
Closed: 18 years ago
Resolution: --- → WONTFIX
s/tickets/accounts/
Product: mozilla.org → mozilla.org Graveyard
You need to log in before you can comment on or make changes to this bug.