On Wed, Sep 07, 2016 at 11:10:30PM +0200, MegaBrutal wrote:
I also figured that memberOf would need groupOfNames groups, while I
need posixGroup type groups. I evaluated the possibility to use
groupOfNames, but it lacks the necessary gidNumber attribute which is
a requirement for Unix groups.
This is the key issue.
A draft schema known as "rfc2307bis" exists, which replaces (!) the
published RFC2037 schema with one compatible with groupOfNames.
A published solution to this problem does not currently exist. In the
past year there have been some discussions on the ldapext list. You
can find the archives of that list at:
https://www.ietf.org/mailman/listinfo/ldapext