Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 11 Jan 2007 12:18:50 -0500
From:      Mike Meyer <mwm-keyword-freebsdhackers2.e313df@mired.org>
To:        Vulpes Velox <v.velox@vvelox.net>
Cc:        hackers@freebsd.org
Subject:   Re: LDAP integration
Message-ID:  <17830.29050.791321.480369@bhuda.mired.org>
In-Reply-To: <20070111035549.7c11a450@vixen42>
References:  <60737.24.71.119.183.1168496463.squirrel@webmail.sd73.bc.ca> <45A5EA3B.9020000@datalinktech.com.au> <20070111035549.7c11a450@vixen42>

next in thread | previous in thread | raw e-mail | index | archive | help
In <20070111035549.7c11a450@vixen42>, Vulpes Velox <v.velox@vvelox.net> typed:
> LDAP is nice organizing across many systems, but if you are just
> dealing with one computer it is complete over kill for any thing.

In that situation, it's not merely overkill, it's may actually be a
bad idea. Can you say "AIX SDR"? How about "Windows registry"?

Those system both took the approach of putting all the configuration
information in a central database. This creates problems because the
tools needed to examine/fix the config database require a complex
environment - at least compared to a statically linked copy of
ed. LDAP may not be so bad, but it still makes me nervous.

On the other hand, if you've got a flock of boxes to manage, having a
way to tell the rc subsystem "Go read config values from this LDAP
server" seems like a very attractive alternative.

	<mike
-- 
Mike Meyer <mwm@mired.org>		http://www.mired.org/consulting.html
Independent Network/Unix/Perforce consultant, email for more information.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?17830.29050.791321.480369>