Re: LDAP auth

From: "Magnus Hagander" <mha(at)sollentuna(dot)net>
To: "Tom Lane" <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: <pgsql-patches(at)postgresql(dot)org>
Subject: Re: LDAP auth
Date: 2006-03-05 20:11:00
Message-ID: 6BCB9D8A16AC4241919521715F4D8BCEA0F831@algol.sollentuna.se
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers pgsql-patches

> Awhile back, "Magnus Hagander" <mha(at)sollentuna(dot)net> wrote:
> > This patch adds native LDAP auth, for those platforms that
> don't have
> > PAM (such as Win32, but also unixen without PAM). On Unix, uses
> > OpenLDAP. On win32, uses the builin WinLDAP library.
>
> Is this patch still live, or do you want to withdraw it in
> light of the recent discussions about using libcurl?

I'm unsure wether libcurl does what we'd need, but I haven't looked into
the details (I did a very quick check on the web, but was unable to
quickly find what I was looking for).

Specifically, we want to just do an LDAP bind and not actually fetch
anything. Though I guess we could fetch the base DN without taking a lot
of performance...

Also, I'm unsure if they'll run with winldap on windows or add an extra
library dependence on openldap (which will cause problems when using
ldaps in windows, since you need a completely separate set of
certificates and stuff imported into openldap instead of using what
Windows alreayd set up for you). Their FAQ says they require openldap,
but a quick google shows maybe they don't.

Was there ever a decision in "the libcurl thread"? If we're going to
pull in libcurl as a dependency anyway, it would deifnitly be worthwhile
checking if we can use it here as well, if nothing else then just to get
rid of the configure steps. But if we don't use it elsewhere, I don't
see any reason to add an extra dependency.

//Magnus

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Markus Bertheau 2006-03-05 20:14:52 pg.conf re-reading in signal handler or at next return to main loop?
Previous Message Tom Lane 2006-03-05 19:13:04 Remove vestigial UNION JOIN support?

Browse pgsql-patches by date

  From Date Subject
Next Message Tom Lane 2006-03-05 20:20:43 Re: [PATCHES] LDAP auth
Previous Message Bruce Momjian 2006-03-05 17:47:38 Re: TODO item: remove postmaster -o option