OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: particular configuration with LDAP

From: Victoriano Giralt (victorianouma.es)
Date: Mon Feb 04 2008 - 03:47:15 CST


-----BEGIN PGP SIGNED MESSAGE-----
Hash: RIPEMD160

Giovanni Mancuso wrote:
|> The problem is that i don't know the company of the domain, but i can
|> know it only with a search ldap.
|> In this case i should make two search ldap.
|> First to get a base DN of the company. and second (binding on comany
|> DN) to get the domains of the company. Is correct??
|> I know that postfix is not able to make it. Is correct?
|> How can I fix? Any ideas?
Giovanni, I'm not sure it can easily be done with Postfix alone, but it
could be easy with a policy server. Inside that said server, I'd do:

1) get the dn of the sending domain off the LDAP
2) cut the dn after the domain o attribute
3) do a search for the destination domain under the tree under that dn
4) return OK (or DUNNO if you want more checks applied)
~ if the search gets a result or REJECT if not.

just my .02 euro
- --
Victoriano Giralt
Systems Manager
Central Computing Facility
University of Malaga
SPAIN
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFHpt8iV6+mDjj1PTgRA/ulAKC7SY63UiV69Dxt7+vgbHXtKLbVpwCdEIyj
r0ZvrhuRay3B4hTtOk7CTxo=
=1191
-----END PGP SIGNATURE-----