This page (revision-1) was last changed on 29-Nov-2024 16:16 by UnknownAuthor

Only authorized users are allowed to rename pages.

Only authorized users are allowed to delete pages.

Page revision history

Version Date Modified Size Author Changes ... Change note

Page References

Incoming links Outgoing links

Version management

Difference between version and

At line 1 added 52 lines
!!! Overview
!! [Group], [groupOfUniqueNames], [groupOfNames]
Generally we find these three "names" used for [{$pagename}] Names.
! What is the difference?
For the difference of [groupOfUniqueNames vs groupOfNames] is pretty clear.
For the difference between [groupOfUniqueNames vs groupOfNames] and [Group], it is more difficult.
Some [LDAP Server Implementations] will alias [Group] to [groupOfNames]. Usually, [groupOfUniqueNames] will be a separate and distinct name.
* [EDirectory] does alais all three as group.
* [Microsoft Active Directory] has implemented their own [Group] with a separate [OID|1.2.840.113556.1.5.8]. [Microsoft Active Directory] does also provide the "standard" [groupOfUniqueNames].
! Summary of [{$pagename}]s
%%zebra-table
%%sortable
%%table-filter
||Name|[OID]|[Member Attribute]|Comments
|[group|Group-AD]|[1.2.840.113556.1.5.8]|[member]|Specific to [Active Directory Groups]
|[groupOfNames]|[2.5.6.9]|[member]|Generic
|[groupOfUniqueNames]|[2.5.6.17]|[uniqueMember]|Generic (Also in [Active Directory Groups])
/%
/%
/%
!! [DynamicGroups] and [Static groups]
Generally [{$pagename}]s are:
* [DynamicGroups]
* [Static groups]
* [Virtual static groups] - Some [LDAP Server Implementations] groups can be [Virtual static groups] (ie both).
!! [Groups Are Bad]
We have never understood the fascination with groups within [LDAP]. We find they serve little purpose from an [LDAP] perspective.
!! [Active Directory Groups]
[Microsoft Active Directory] implements their own [Group] which has some [interesting facets|Active Directory Groups]
!! [Groups Edirectory]
[eDirectory] has some [interesting facets|Groups Edirectory]
!! [Group Fix Tool]
Our [Group Fix Tool] for [eDirectory] will correct the [groupMembership] from an existing [member] attribute on the group.
!! [PosixGroup]
The [PosixGroup] is used for [POSIX] group implementations and is used with [PAM_LDAP]
!! [groupOfEntries]
This object class allows groups to be empty. In all other respects [groupOfEntries] behaves like the [groupOfNames] object class.
!! More Information
There might be more information for this subject on one of the following:
[{ReferringPagesPlugin before='*' after='\n' }]