From: Howard Chu Date: Wed, 29 Apr 2009 02:41:26 +0000 (+0000) Subject: Note that host SSD must be configured for hostservice option X-Git-Tag: ACLCHECK_0~593 X-Git-Url: https://git.sur5r.net/?a=commitdiff_plain;h=8ff986b1bcbd46509a351e224518c4871b931088;p=openldap Note that host SSD must be configured for hostservice option --- diff --git a/contrib/slapd-modules/nssov/slapo-nssov.5 b/contrib/slapd-modules/nssov/slapo-nssov.5 index 416320d138..4b55db9d7b 100644 --- a/contrib/slapd-modules/nssov/slapo-nssov.5 +++ b/contrib/slapd-modules/nssov/slapo-nssov.5 @@ -155,7 +155,8 @@ The recommended approach is to use .B hostservice instead. In this case, ipHost entries must be created for all hosts being managed, and they must also have the authorizedServiceObject -class to allow authorizedService attributes to be used. +class to allow authorizedService attributes to be used. Also the +NSS host SSD must be configured so that ipHost entries can be found. Authorization is checked by performing an LDAP Compare operation looking for the PAM service name in the authorizedService attribute. .B slapd