mhardin@symas.com wrote:
Sorry for the out-of-sequence reply. I'll test and let you know what I find.
No problem. Note that if this is the cause of this issue, and, in any case, if you have some "range" attributes in your response, you still have an issue with those values. It seems that, in the spirit of OpenLDAP software, we could be relatively liberal in accepting those values provided we are able to consolidate them in a single entry with no ranges. Apparently, what the proxies could do is:
- whenever a range is obtained in a response - iteratively query the server again for the same entry, - requesting only that attribute for the next block of vals - incrementally build the set of values - return the consolidated entry
This MUST be configurable, and documented as a nasty, expensive and unnecessary hack.
p.
Ing. Pierangelo Masarati OpenLDAP Core Team
SysNet s.r.l. via Dossi, 8 - 27100 Pavia - ITALIA http://www.sys-net.it ----------------------------------- Office: +39 02 23998309 Mobile: +39 333 4963172 Fax: +39 0382 476497 Email: ando@sys-net.it -----------------------------------