On Sat, Sep 26, 2026 at 10:39:42PM +0700, Max Nikulin wrote:
> On 25/09/2026 1:01 pm, tomas wrote:
> > Yes, LDAP is... particular. But a referral (which might be just a part
> > of a response) may point to another server (well, "DSA", in LDAP parlance,
> > but it is a sequence of one or more URLs). So a complete answer may be
> > composed of bits and pieces gathered over more than one server.
> > 
> > Still no idea whether that "counts" (as I tried to express that above).
> 
> As a person familiar to LDAP, you are in better position to answer.

Uh-oh. I think you're overstimating me: I've wrestled with LDAP here
and there, that's all. And never in the libnss context.

> Can you
> imagine realistic configuration when query in some category/service/database
> (alternative words used for the same term in man pages) needs more than one
> request to LDAP servers, some request mail fail, and incomplete result still
> may be useful? (Similar to failed A DNS request when IPv6 addresses from
> AAAA request is enough if IPv6 is fully supported on the machine.) Have a
> look into getent(1) or nsswitch.conf(5) for inspiration.
> 
> An example may be added to Vincent's bug to show that impact is not limited
> to "hosts".

Tough question: for that one would have to understand what libnss_ldap
does and whether incomplete (in the LDAP sense) replies are relevant to
it. For me, that's far beyond the "one afternoon project" :-)

Cheers and thanks for your insights.
-- 
tomás

Attachment: signature.asc
Description: PGP signature

Reply via email to