Monday, April 28, 2008

OpenLDAP - no dynamic groups

A simple solution to this problem is in the use of dynamic groups. One small problem though, a dynamic group is only a concept and, technically speaking, cannot be modeled in OpenLDAP, eTrust and IBM Directory Server. Therefore, dynamic groups functionality must be built into the application security architecture.
Gavin Henry said...

Wrong, you can easily do Dynamic Groups in OpenLDAP, both in the directory and for use in ACLs.