From <IMAP4.psuedo.sims> Fri Nov 14 13:56:15 2008
Date: Fri, 14 Nov 2008 13:56:15 -0800 (PST)
From: Postmaster
Subject: Message from mail server       
Content-Length: 94
Mime-Version: 1.0
Status: RO
X-IMAP: 1226699775 11

Delete.
This is a system message.                                













--END+PSEUDO--

From tom.childers@sun.com Wed Nov 12 11:28:23 2008
Received: from dm-sfbay-01.sfbay.sun.com (dm-sfbay-01.SFBay.Sun.COM [129.145.155.118])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mACJSNam026047
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 12 Nov 2008 11:28:23 -0800 (PST)
Received: from sca-es-mail-1.sun.com (sca-es-mail-1.Sun.COM [192.18.43.132])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mACJSNX1039405
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 12 Nov 2008 11:28:23 -0800 (PST)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id mACJSIXJ029345
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 12 Nov 2008 11:28:18 -0800 (PST)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0KA800M01HNVMV00@fe-sfbay-10.sun.com>
 (original mail from tom.childers@sun.com) for LSARC-ext@sac.sfbay.sun.com;
 Wed, 12 Nov 2008 11:28:18 -0800 (PST)
Received: from labnis-qfe4.SFBay.Sun.COM ([75.101.10.233])
 by fe-sfbay-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0KA800L46JF07ME0@fe-sfbay-10.sun.com> for
 LSARC-ext@sac.sfbay.sun.com; Wed, 12 Nov 2008 11:28:13 -0800 (PST)
Date: Wed, 12 Nov 2008 11:27:50 -0800
From: Tom Childers <tom.childers@sun.com>
Subject: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack timeout
 11/19/2008]
In-reply-to: <491A9B6E.4070408@sun.com>
Sender: Thomas.Childers@sun.com
To: LSARC-ext@sac.sfbay.sun.com
Cc: Gilles Bellaton <Gilles.Bellaton@sun.com>,
        Barbara Kroczak <Barbara.Kroczak@sun.com>,
        Didier Simonazzi <Didier.Simonazzi@sun.com>
Message-id: <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com>
MIME-version: 1.0
X-Mailer: Apple Mail (2.928.1)
Content-type: text/plain; delsp=yes; format=flowed; charset=US-ASCII
Content-transfer-encoding: 7BIT
References: <490AC47F.9040700@sun.com>
 <62CA2FFE-CAC7-4995-B711-667D89D2D412@sun.com> <4912FB8A.8070902@sun.com>
 <D0964944-3893-4661-BBA0-EECF59EF8569@sun.com> <4918A818.1020203@sun.com>
 <6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com> <491A9B6E.4070408@sun.com>
Content-Length: 36678
Status: RO
X-Status: $$$$
X-UID: 0000000001

Both the one-pager and FOSS checklist are attached below.  Timeout is  
Nov 19, 2008.
-tdc


Template Version: @(#)onepager.txt 1.31 07/08/08 SMI

This information is Copyright 2007 Sun Microsystems

1. Introduction
1.1. Project/Component Working Name:
     OpenDS Integration in OpenSolaris

1.2. Name of Document Author/Supplier:
     Gilles Bellaton

1.3. Date of This Document:
     27/10/2008

1.4. Name of Major Document Customer(s)/Consumer(s):
     1.4.1. OpenSolaris
     1.4.2. LSARC

1.5. Email Aliases:
     1.5.2. Responsible Engineer: Gilles.Bellaton@sun.com
     1.5.4. Interest List: opends-opensolaris@sun.com

2. Project Summary
2.1. Project Description:

     OpenDS is an open source project led by Sun Microsystems,
     building a comprehensive and complete LDAPv3 based
     Directory Service. The project web site is www.opends.org
     and the developer's section hosted on opends.dev.java.net.

     The goal of this project is to integrate the current OpenDS
     technology in the OpenSolaris repository for Unbundled product.
     OpenDS will be integrated as a Binary product. The sources
     will not be bundled as they are already maintained by a
     separate community.
     The goal of this integration is to provide to OpenSolaris
     users the possibility to easily install and run OpenDS.
     This should increase adoption of both OpenDS and OpenSolaris.
     The current plan is to have integrate OpenDS 1.2 in OpenSolaris.

2.2. Risks and Assumptions:
     No known risks at this point.

3. Business Summary
3.1. Problem Area:
     OpenSolaris needs a high performance, easy to use
     Directory Server for Naming Services and other applications.
     OpenSolaris users have to go to OpenDS pages and manually
     install OpenDS zip packages in order to benefit from
     OpenDS technology.
     This project will help user desiring to use both OpenSolaris
     and OpenDS by providing a coherent packaging and a common
     repository.

3.2. Market/Requester:
     All users using both OpenSolaris and a Directory Server.

3.3. Business Justification:
     Increase adoption of both OpenDS and OpenSolaris

3.4. Competitive Analysis:
     OpenLDAP is already integrated in OpenSolaris.
     OpenDS will provide an alternate LDAPv3 compliant directory server,
     that is easier to use and manage and will offer smooth migration
     for those familiar with the Sun Directory Server Enterprise  
Edition.
     OpenDS will also integrate in other Operating Systems.

3.5. Opportunity Window/Exposure:
     OpenDS is ready to be integrated.

3.6. How will you know when you are done?:
     When SVR4/IPS packages for OpenSolaris are available.

4. Technical Description:
4.1. Details:
         Develop SVR4/IPS packages for OpenSolaris

4.2. Bug/RFE Number(s):
      None.

4.3. In Scope:
      This project will only integrate OpenDS server side.

4.4. Out of Scope:
      Since OpenSolaris already has a number of LDAP libraries
      and command lines, OpenDS LDAP commands and libraries will
      not be provided in the OpenSolaris

4.5. Interfaces:

      OpenDS main interface is LDAPv3 and is defined by a set of
      well known RFCs in the LDAP community.

      OpenDS also provides a set of admin interfaces that will
      not be changed by this project :
     /opt/opends                                  Volatile
     /opt/opends/upgrade                          Uncommitted
     /opt/opends/bin                              Uncommitted
     /opt/opends/bin/dsreplication                Uncommitted
     /opt/opends/bin/control-panel                Uncommitted
     /opt/opends/bin/dsconfig                     Uncommitted
     /opt/opends/bin/ldif-diff                    Uncommitted
     /opt/opends/bin/verify-index                 Uncommitted
     /opt/opends/bin/dbtest                       Uncommitted
     /opt/opends/bin/encode-password              Uncommitted
     /opt/opends/bin/base64                       Uncommitted
     /opt/opends/bin/rebuild-index                Uncommitted
     /opt/opends/bin/restore                      Uncommitted
     /opt/opends/bin/ldifmodify                   Uncommitted
     /opt/opends/bin/ldappasswordmodify           Uncommitted
     /opt/opends/bin/start-ds                     Uncommitted
     /opt/opends/bin/dsframework                  Uncommitted
     /opt/opends/bin/list-backends                Uncommitted
     /opt/opends/bin/manage-account               Uncommitted
     /opt/opends/bin/manage-tasks                 Uncommitted
     /opt/opends/bin/dsjavaproperties             Uncommitted
     /opt/opends/bin/export-ldif                  Uncommitted
     /opt/opends/bin/make-ldif                    Uncommitted
     /opt/opends/bin/create-rc-script             Uncommitted
     /opt/opends/bin/status                       Uncommitted
     /opt/opends/bin/ldifsearch                   Uncommitted
     /opt/opends/bin/status-panel                 Uncommitted
     /opt/opends/bin/import-ldif                  Uncommitted
     /opt/opends/bin/backup                       Uncommitted
     /opt/opends/bin/stop-ds                      Uncommitted
     /opt/opends/setup                            Uncommitted
     /opt/opends/configure                        Uncommitted
     /opt/opends/config                           Uncommitted
     /opt/opends/config/schema                    Uncommitted
     /opt/opends/config/schema/03-rfc3712.ldif    Uncommitted
     /opt/opends/config/schema/03-rfc2713.ldif    Uncommitted
     /opt/opends/config/schema/01-pwpolicy.ldif   Uncommitted
     /opt/opends/config/schema/03-uddiv3.ldif     Uncommitted
     /opt/opends/config/schema/03-rfc3112.ldif    Uncommitted
     /opt/opends/config/schema/04-rfc2307bis.ldif Uncommitted
     /opt/opends/config/schema/02-config.ldif     Uncommitted
     /opt/opends/config/schema/03-rfc2739.ldif    Uncommitted
     /opt/opends/config/schema/00-core.ldif       Uncommitted
     /opt/opends/config/schema/03-rfc2714.ldif    Uncommitted
     /opt/opends/config/schema/03-changelog.ldif  Uncommitted
     /opt/opends/config/schema/03-rfc2926.ldif    Uncommitted
     /opt/opends/config/schema/04-rfc4876.ldif    Uncommitted
     /opt/opends/config/schema/04-solaris.ldif    Uncommitted
     /var/opt/opends                              Volatile
     /var/opt/opends/bak                          Uncommitted
     /var/opt/opends/changelogDb                  Uncommitted
     /var/opt/opends/classes                      Uncommitted
     /var/opt/opends/config                       Uncommitted
     /var/opt/opends/config/MakeLDIF              Uncommitted
     /var/opt/opends/config/messages              Uncommitted
     /var/opt/opends/config/schema                Uncommitted
     /var/opt/opends/config/servicetag            Uncommitted
     /var/opt/opends/config/snmp                  Uncommitted
     /var/opt/opends/config/snmp/security         Uncommitted
     /var/opt/opends/config/upgrade               Uncommitted
     /var/opt/opends/db                           Uncommitted
     /var/opt/opends/import-tmp                   Uncommitted
     /var/opt/opends/ldif                         Uncommitted
     /var/opt/opends/lib                          Uncommitted
     /var/opt/opends/lib/extensions               Uncommitted
     /var/opt/opends/locks                        Uncommitted
     /var/opt/opends/logs                         Uncommitted
     /var/opt/opends/config/buildinfo             Uncommitted
     /var/opt/opends/config/config.ldif           Uncommitted
     /var/opt/opends/config/java.properties       Uncommitted
     /var/opt/opends/config/MakeLDIF/ 
cities                              Uncommitted
     /var/opt/opends/config/MakeLDIF/ 
example.template                    Uncommitted
     /var/opt/opends/config/MakeLDIF/ 
first.names                         Uncommitted
     /var/opt/opends/config/MakeLDIF/ 
last.names                          Uncommitted
     /var/opt/opends/config/MakeLDIF/ 
states                              Uncommitted
     /var/opt/opends/config/MakeLDIF/ 
streets                             Uncommitted
     /var/opt/opends/config/messages/account- 
disabled.template           Uncommitted
     /var/opt/opends/config/messages/account- 
enabled.template            Uncommitted
     /var/opt/opends/config/messages/account- 
expired.template            Uncommitted
     /var/opt/opends/config/messages/account-idle- 
locked.template        Uncommitted
     /var/opt/opends/config/messages/account-permanently- 
locked.template Uncommitted
     /var/opt/opends/config/messages/account-reset- 
locked.template       Uncommitted
     /var/opt/opends/config/messages/account-temporarily- 
locked.template Uncommitted
     /var/opt/opends/config/messages/account- 
unlocked.template           Uncommitted
     /var/opt/opends/config/messages/password- 
changed.template           Uncommitted
     /var/opt/opends/config/messages/password- 
expired.template           Uncommitted
     /var/opt/opends/config/messages/password- 
expiring.template          Uncommitted
     /var/opt/opends/config/messages/password- 
reset.template             Uncommitted
     /var/opt/opends/config/servicetag/ 
opends.uuids.properties           Uncommitted
     /var/opt/opends/config/ 
tools.properties                             Uncommitted
     /var/opt/opends/config/upgrade/config.ldif. 
4535                     Uncommitted
     /var/opt/opends/config/upgrade/schema.ldif. 
4535                     Uncommitted
     /var/opt/opends/config/ 
wordlist.txt                                 Uncommitted

     All the files and directories in /var/opt/ are created by the
     /opt/opends/configure command. /var/opt is only the default path,  
this can
     be changed by the user at installation time.

4.6. Doc Impact:
      OpenDS documentation is currently delivered on a wiki.
      man pages will be delivered for the main administrative interfaces
      - opends (5) overview
      - dsconfig
      - control-panel
      - dsreplication
      - configure

4.7. Admin/Config Impact:
      A new command is being developped to create the OpenDS instance
      after the packages have been added on the OS.

4.8. HA Impact:
      None.

4.9. I18N/L10N Impact:
      None.
      OpenDS is already internationalized and localized in several  
languages.

4.10. Packaging & Delivery:
      This project will deliver a new package called OpenDS whose  
content
      is described below.

      opends package content:
      basedir: /opt
      layout:
      d none opends 0755 root sys
      d none opends/bin 0755 root sys
      d none opends/config 0755 root sys
      d none opends/config/schema 0755 root sys
      d none opends/legal-notices 0755 root sys
      d none opends/lib 0755 root sys
      d none opends/lib/extensions 0755 root sys
      d none opends/tmpl_instance 0755 root sys
      d none opends/tmpl_instance/bak 0755 root sys
      d none opends/tmpl_instance/changelogDb 0755 root sys
      d none opends/tmpl_instance/classes 0755 root sys
      d none opends/tmpl_instance/config 0755 root sys
      d none opends/tmpl_instance/config/MakeLDIF 0755 root sys
      d none opends/tmpl_instance/config/messages 0755 root sys
      d none opends/tmpl_instance/config/schema 0755 root sys
      d none opends/tmpl_instance/config/servicetag 0755 root sys
      d none opends/tmpl_instance/config/snmp 0755 root sys
      d none opends/tmpl_instance/config/snmp/security 0755 root sys
      d none opends/tmpl_instance/config/upgrade 0755 root sys
      d none opends/tmpl_instance/db 0755 root sys
      d none opends/tmpl_instance/import-tmp 0755 root sys
      d none opends/tmpl_instance/ldif 0755 root sys
      d none opends/tmpl_instance/lib 0755 root sys
      d none opends/tmpl_instance/lib/extensions 0755 root sys
      d none opends/tmpl_instance/locks 0755 root sys
      d none opends/tmpl_instance/logs 0755 root sys
      f none opends/bin/backup 0755 root sys
      f none opends/bin/base64 0755 root sys
      f none opends/bin/control-panel 0755 root sys
      f none opends/bin/create-rc-script 0755 root sys
      f none opends/bin/dbtest 0755 root sys
      f none opends/bin/dsconfig 0755 root sys
      f none opends/bin/dsframework 0755 root sys
      f none opends/bin/dsjavaproperties 0755 root sys
      f none opends/bin/dsreplication 0755 root sys
      f none opends/bin/encode-password 0755 root sys
      f none opends/bin/export-ldif 0755 root sys
      f none opends/bin/import-ldif 0755 root sys
      f none opends/bin/ldappasswordmodify 0755 root sys
      f none opends/bin/ldif-diff 0755 root sys
      f none opends/bin/ldifmodify 0755 root sys
      f none opends/bin/ldifsearch 0755 root sys
      f none opends/bin/list-backends 0755 root sys
      f none opends/bin/make-ldif 0755 root sys
      f none opends/bin/manage-account 0755 root sys
      f none opends/bin/manage-tasks 0755 root sys
      f none opends/bin/rebuild-index 0755 root sys
      f none opends/bin/restore 0755 root sys
      f none opends/bin/start-ds 0755 root sys
      f none opends/bin/status 0755 root sys
      f none opends/bin/status-panel 0755 root sys
      f none opends/bin/stop-ds 0755 root sys
      f none opends/bin/verify-index 0755 root sys
      f none opends/config/schema/00-core.ldif 0644 root sys
      f none opends/config/schema/01-pwpolicy.ldif 0644 root sys
      f none opends/config/schema/02-config.ldif 0644 root sys
      f none opends/config/schema/03-changelog.ldif 0644 root sys
      f none opends/config/schema/03-rfc2713.ldif 0644 root sys
      f none opends/config/schema/03-rfc2714.ldif 0644 root sys
      f none opends/config/schema/03-rfc2739.ldif 0644 root sys
      f none opends/config/schema/03-rfc2926.ldif 0644 root sys
      f none opends/config/schema/03-rfc3112.ldif 0644 root sys
      f none opends/config/schema/03-rfc3712.ldif 0644 root sys
      f none opends/config/schema/03-uddiv3.ldif 0644 root sys
      f none opends/config/schema/04-rfc2307bis.ldif 0644 root sys
      f none opends/config/schema/04-rfc4876.ldif 0644 root sys
      f none opends/config/schema/04-solaris.ldif 0644 root sys
      f none opends/configure 0744 root sys
      f none opends/example-plugin.zip 0644 root sys
      f none opends/install.html 0644 root sys
      f none opends/install.txt 0644 root sys
      f none opends/legal-notices/BerkeleyDB-JE.LICENSE 0644 root sys
      f none opends/legal-notices/jaf.LICENSE 0644 root sys
      f none opends/legal-notices/javamail.LICENSE 0644 root sys
      f none opends/legal-notices/OpenDS.LICENSE 0644 root sys
      f none opends/lib/_client-script.sh 0755 root sys
      f none opends/lib/_mixed-script.sh 0755 root sys
      f none opends/lib/_script-util.sh 0755 root sys
      f none opends/lib/_server-script.sh 0755 root sys
      f none opends/lib/activation.jar 0644 root sys
      f none opends/lib/je.jar 0644 root sys
      f none opends/lib/mail.jar 0644 root sys
      f none opends/lib/OpenDS.jar 0644 root sys
      f none opends/lib/quicksetup.jar 0644 root sys
      f none opends/opends_logo.png 0644 root sys
      f none opends/README 0644 root sys
      f none opends/setup 0755 root sys
      f none opends/tmpl_instance/config/admin-backend.ldif 0644 root  
sys
      f none opends/tmpl_instance/config/buildinfo 0644 root sys
      f none opends/tmpl_instance/config/config.ldif 0644 root sys
      f none opends/tmpl_instance/config/java.properties 0644 root sys
      f none opends/tmpl_instance/config/MakeLDIF/cities 0644 root sys
      f none opends/tmpl_instance/config/MakeLDIF/example.template  
0644 root sys
      f none opends/tmpl_instance/config/MakeLDIF/first.names 0644  
root sys
      f none opends/tmpl_instance/config/MakeLDIF/last.names 0644 root  
sys
      f none opends/tmpl_instance/config/MakeLDIF/states 0644 root sys
      f none opends/tmpl_instance/config/MakeLDIF/streets 0644 root sys
      f none opends/tmpl_instance/config/messages/account- 
disabled.template 0644 root sys
      f none opends/tmpl_instance/config/messages/account- 
enabled.template 0644 root sys
      f none opends/tmpl_instance/config/messages/account- 
expired.template 0644 root sys
      f none opends/tmpl_instance/config/messages/account-idle- 
locked.template 0644 root sys
      f none opends/tmpl_instance/config/messages/account-permanently- 
locked.template 0644 root sys
      f none opends/tmpl_instance/config/messages/account-reset- 
locked.template 0644 root sys
      f none opends/tmpl_instance/config/messages/account-temporarily- 
locked.template 0644 root sys
      f none opends/tmpl_instance/config/messages/account- 
unlocked.template 0644 root sys
      f none opends/tmpl_instance/config/messages/password- 
changed.template 0644 root sys
      f none opends/tmpl_instance/config/messages/password- 
expired.template 0644 root sys
      f none opends/tmpl_instance/config/messages/password- 
expiring.template 0644 root sys
      f none opends/tmpl_instance/config/messages/password- 
reset.template 0644 root sys
      f none opends/tmpl_instance/config/servicetag/ 
opends.uuids.properties 0644 root sys
      f none opends/tmpl_instance/config/tools.properties 0644 root sys
      f none opends/tmpl_instance/config/upgrade/config.ldif.4535 0644  
root sys
      f none opends/tmpl_instance/config/upgrade/schema.ldif.4535 0644  
root sys
      f none opends/tmpl_instance/config/wordlist.txt 0644 root sys
      f none opends/upgrade 0755 root sys

4.11. Security Impact:
       The OpenDS components listens on the LDAP port and a port used
       for replication.
       The LDAP port is secured using the standard LDAP mechanisms  
(SASL,
       TLS and kerberos)
       The replication port is only accessible using SSL.
       The LDAP data are protected using the same access control model  
as
       the DSEE LDAP server.

4.12. Dependencies:
       OpenDS requires a 1.5 Java Virtual Machine.

5. Reference Documents:
       https://www.opends.org

6. Resources and Schedule:
6.1. Projected Availability:
     Dec 2008

6.2. Cost of Effort:
     A few months of work.

6.4. Product Approval Committee requested information:
     6.4.1. Consolidation or Component Name: DSEE
     6.4.7. Target RTI Date/Release:
             This project needs to be ready by Jan 2009 in order to
             integrate Open Solaris 2009.04

6.5. ARC review type: FastTrack
6.6. ARC Exposure: open
    6.6.1. Rationale: Part of OpenSolaris

7. Prototype Availability:
7.1. Prototype Availability:
     Nov 2008

7.2. Prototype Cost:
     A few weeks.






FCL--FOSS Check List
0.  Introduction
0.1 Document History
    Version   Author             Changes					Date
    0.1       John Fischer       Initial Draft					01/11/2008
    0.2       John Fischer       Modified based upon feedback from ARC  
members	01/29/2008
    0.3       John Fischer       Modified based upon feedback during  
committee 	02/12/2008
                                 review
    0.4       John Fischer       Modified based upon SAC review  
feedback	04/01/2008
    0.5	      John Fischer	 Modified based upon LSARC business meeting	 
06/10/2008
                                 adding familiarity question and mod  
dates.
    0.6       John Fischer       Modified based upon user feedback  
about        06/20/2008
                                 sections that were unanswerable.

0.2 Purpose
    Architecture review at Sun has allowed the company to evolve our  
projects
    within multiple disjoint groups while still maintaining a cohesive  
product
    line.  Each architecture review was conducted within Sun's  
control.  With
    the advent of Free Open Source Software processes the control that  
Sun as
    a company can wield has been diminished.  Now that Sun is moving  
to a more
    fluid delivery mechanism with project Indiana we need to evolve the
    architecture review process.  This document is meant to aid in the
    architecture review process.  Each new project must complete this  
check list
    to help ensure that the overall resulting product conforms to Sun  
product
    standards.  If the project deviates from these standards further  
review
    would be necessary by an architecture review committee.

    After the check list is completed the project team should be able to
    determine if a project can be automatically approved.  This will  
occur
    if all checks result in no "ARC review required" answers.  A  
committee
    member will assist the project team in filing the automatically  
approved
    fast track.  An automatically approved fast track is still  
required in order
    to record the interfaces for future reference.  If the project  
needs to
    have further review then follow the regular process for getting  
projects
    reviewed.

1.0 Project Information
1.1 Name of project/component
Sun OpenDS

1.2 Author of document
Gilles Bellaton

2.0 Project Summary
  2.1 Project Description

OpenDS is an open source community project building a free and
comprehensive next generation directory service.
OpenDS is designed to address large deployments,
to provide high performance, to be highly extensible,
and to be easy to deploy, manage and monitor.

The Directory Server is a network-accessible database that is able to
store information in a hierarchical form.
Clients may communicate with it using
standard network protocols (at present LDAP and DSML are supported)
to retrieve and update information in a variety of ways.

Initial development of OpenDS was done by Sun Microsystems, but it
is now available under the open source
Common Development and Distribution License (CDDL).

  2.2 Release binding
      What is is the release binding?
      (see http://opensolaris.org/os/community/arc/policies/release-taxonomy/)
      [ ] Major
      [X] Minor
      [ ] Patch or Micro
      [ ] Unknown -- ARC review required

  2.3 Type of project
      Is this case a Linux Familiarity project?
      [ ] Yes
      [X] No

  2.4 Originating Community
    2.4.1 Community Name
OpenDS

    2.4.2 Community Involvement
      Indicate Sun's involvement in the community
      [X] Maintainer
      [ ] Contributor
      [ ] Monitoring

      Will the project team work with the upstream community to resolve
      architectural issues of interest to Sun?
      [X] Yes
      [ ] No - briefly explain

      Will we or are we forking from the community?
      [ ] Yes - ARC review required prior to forking
      [X] No

3.0 Technical Description
  3.1 Installation & Sharable
    3.1.1S Solaris Installation - section only required for Solaris  
Software
      (see http://opensolaris.org/os/community/arc/policies/install-locations/ 
  for details)
      Does this project follow the Install Locations best practice?
      [X] Yes
      [ ] No - ARC review required

      Does this project install into /usr under [sbin|bin|lib|include| 
man|share]?
      [ ] Yes
      [X] No or N/A

      Does this project install into /opt?
      [X] Yes - explain below
      [ ] No or N/A

      Does this project install into a different directory structure?
      [ ] Yes - ARC review required
      [X] No or N/A

      Do any of the components of this project conflict with anything  
under /usr?
      (see http://opensolaris.org/os/community/arc/caselog/2007/047/  
for details)
      [ ] Yes - explain below
      [X] No

      If conflicts exist then will this project install under /usr/gnu?
      [ ] Yes
      [ ] No - ARC review required
      [X] N/A

      Is this project installing into /usr/sfw?
      [ ] Yes - ARC review required
      [X] No


    3.1.2 Share and Sharable
      Does the module include any components that are used or shared by
      other projects?
      [ ] Yes
      [X] No

      If yes are these components packaged to be shared with the other  
FOSS?
      [ ] Yes
      [ ] No - ARC review required
      [X] N/A

      Are these components already in the Solaris WOS?
      [ ] Yes
      [X] No - continue with next section (section 3.2)

      If yes are these newer versions being delivered?
      [ ] Yes
      [ ] No - ARC review required

      If yes are the newer versions replacing the existing versions?
      [ ] Yes
      [ ] No - ARC review required

  3.2 Exported Libraries
      Are libraries being delivered by this project?
      [ ] Yes
      [X] No - continue with next section (section 3.3)

      Are 64-bit versions of the libraries being delivered?
      [ ] Yes
      [ ] No - ARC review required

      Are static versions of the libraries being delivered?
      [ ] Yes - ARC review required
      [ ] No

  3.3 Services and the /etc Directory
      (see http://opensolaris.org/os/community/arc/policies/SMF-policy/)
      Does the project integrate anything into /etc/init.d or /etc/ 
rc?.d?
      [ ] Yes - ARC review required
      [X] No

      Does the project integrate any new entries into /etc/inittab or
      /etc/inetd.conf?
      [ ] Yes - ARC review required
      [X] No

      Does the project integrate any private non-public files into / 
etc/default
      or /etc/ configuration files?
      [ ] Yes - ARC review required
      [X] No

      Does the service manifests method context grant rights above that
      of the noaccess user and basic privilege set?
      [ ] Yes - ARC review required
      [X] No

  3.4 Security
    3.4.1 Secure By Default
      (see http://opensolaris.org/os/community/arc/policies/secure-by-default/ 
  for details)
      (see http://www.opensolaris.org/os/community/arc/policies/NITS-policy/ 
  for details)
      (see parts of http://opensolaris.org/os/community/arc/policies/SMF-policy/ 
  for
       addtional details)
      Are there any network services provided by this project?
      [X] Yes
      [ ] No - continue with the next section (section 3.4.2)

      Are network services enabled by default?
      [ ] Yes - ARC review required
      [X] No
      [ ] N/A

      Are network services automatically enabled by the project during  
installation?
      [ ] Yes - ARC review required
      [X] No
      [ ] N/A

      Are inbound network communications denied by default?
      [ ] Yes
      [ ] No - ARC review required
      [X] N/A

      Is inbound data checked to prevent content-based attacks?
      [X] Yes
      [ ] No - ARC review required
      [ ] N/A

      Is the outbound receiver authenticated?
      [X] Yes
      [ ] No - ARC review required
      [ ] N/A

      Is the receiver authenticated prior to receiving any sensitive  
outbound communication?
      [X] Yes
      [ ] No - ARC review required
      [ ] N/A

    3.4.2 Authorization
      (see http://opensolaris.org/os/community/arc/bestpractices/rbac-intro/ 
  and
	   http://opensolaris.org/os/community/arc/bestpractices/rbac- 
profiles/ and
	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
           for details)
      Are there any setuid/setgid privileged binaries in the project?
      [ ] Yes - ARC review required
      [X] No - continue with next section (section 3.4.3)

      If yes then are the setuid/setgid privileges handled by the use  
of roles?
      [ ] Yes
      [ ] No - ARC review required

    3.4.3 Auditing
      (see http://opensolaris.org/os/community/arc/policies/audit-policy/ 
  for details)
      (see http://opensolaris.org/os/community/arc/caselog/2003/397  
for details)
      Does this component contain administrative or security enforcing  
software?
      [ ] Yes - ARC review required
      [X] No - continue to next section (section 3.4.4)

      (see http://opensolaris.org/os/community/arc/caselog/2003/397  
for details)
      Do the components create audit logs detailing what took place  
including what event
      took place, who was involved, when the event took place?
      [ ] Yes - ARC contract and Audit project team review required
      [ ] No - ARC review required


    3.4.4 Authentication
      (see http://opensolaris.org/os/community/arc/policies/PAM/)
      Do the components contain any authentication code?
      [X] Yes
      [ ] No - continue to next section (section 3.4.5)

      If yes do the components use PAM (plugable authentication  
modules) for authentication?
      [ ] Yes
      [X] No - ARC review required

      If yes is a single PAM session maintained during authentication?
      [ ] Yes
      [ ] No - ARC review required

      If yes are the components sufficiently privileged to allow the  
requested
      operations (authentication, password change, process credential  
manipulation,
      audit state initialization)?
      [ ] Yes - briefly describe below
      [ ] No - ARC review required

    3.4.5 Passwords
      (see http://opensolaris.org/os/community/arc/bestpractices/passwords-cli/ 
  and
           http://opensolaris.org/os/community/arc/bestpractices/passwords-files/ 
  for details)
      Do any of the components for the project deal with passwords?
      [X] Yes
      [ ] No - continue to next section (section 3.4.6)

      If yes are these passwords entered via the CLI or environment?
      [X] Yes - ARC review required
      [ ] No

      Are passwords stored within the file system for the component?
      [X] Yes
      [ ] No - continue to next section (section 3.4.6)

      If yes are the permissions on the file such to protect exposing  
the password(s)?
      [X] Yes
      [ ] No - ARC review required

    3.4.6 General Security Questions
      (see http://opensolaris.org/os/community/arc/bestpractices/security-questions/ 
  for details)
      Are there any network protocols used by this project?
      [X] Yes
      [ ] No - continue with the next section (section 3.5)

      Do the components use standard network protocols?
      [X] Yes
      [ ] No - ARC review required

      Do network services for the project make decisions based upon  
user, host or
      service identities?
      [X] Yes - explain below
      Access control information can make decisions based on host  
identity

      [ ] No
      [ ] N/A

      Do the components make use of secret information during  
authentication and/or
      authorization?
      [X] Yes - explain below
      LDAP protocol includes BIND operation that can use a password.
      [ ] No
      [ ] N/A

  3.5 Networking
      Do the components access the network?
      [X] Yes
      [ ] No - continue with the next section (section 3.6)

      If yes do the components support IPv6?
      [X] Yes
      [ ] No - ARC review required

  3.6 Core Solaris Components
      Do the components of this project compete with or duplicate core
      Solaris components?
      [ ] Yes - ARC review required
      [X] No

      Examples of Core Solaris Components include but are not limited  
to:

        Secure By Default
        Authorizations
        PAM -- Plugable Authentication Module
        Privilege
        PRM -- Process Rights Management -- Privilege
        Audit
        xVm -- Virtualization
        zones / Solaris Containers
        PRM -- Process Rights Management
        RBAC -- Role Based Access Control
        TX / Trusted Extensions
        ZFS
        SMF -- Service Management Facility
        FMA -- Fault Management Architecture
        SCF -- Smart Card Facility
        IPsec

4.0 Interfaces
  (see http://www.opensolaris.org/os/community/arc/policies/interface-taxonomy/ 
  for details)
  4.1 Exported Interfaces

    Interface Name		Classification      Comments
    --------------------------- -------------------  
---------------------------
    LDAP 				committed           LDAP is defined by a set of RFC
                                            most of them supported by  
Sun OpenDS
    DSML                committed
    SNMP                committed
    JMX                 Uncommitted         Sun OpenDS monitoring is  
possible
                                            using JMX. While JMX  
protocol is stable
                                            the monitored object are  
still evolving.
    dsconfig CLI        Uncommitted         dsconfig is the command  
line used
                                            for configuration
    administration      Uncommitted         Sun OpenDS use a set of  
Shell scripts
    scripts                                 for administartive purpose
                                            (start/stop, backup, ...)

  4.2 Imported Interfaces

    Interface Name		Classification       Comments
    --------------------------- --------------------  
--------------------------
    Java SE 1.5                              I'm not sure about the
                                             Classification of Java SE  
1.5


  Brief Interface Classifications - See Appendix C for definitions
    Volatile - interfaces are fluid and will follow a rapidly changing  
community
    Uncommitted - interfaces are still evolving in the community and  
might follow
		  the community
    Committed - interfaces are stable in the community
    Project Private - no review required, just document in table
    Contracted (interface modifier) - further review required

Appendix A - References
  1.  Solaris Installation Locations Policy
      http://opensolaris.org/os/community/arc/policies/install- 
locations/
  2.  /usr/gnu Installation ARC case
      http://opensolaris.org/os/community/arc/caselog/2007/047/
  3.  Secure By Default Policy
      http://opensolaris.org/os/community/arc/policies/secure-by- 
default/
  4.  Network Install Time Securityuy Policy
      http://www.opensolaris.org/os/community/arc/policies/NITS-policy/
  5.  Adding RBAC Authorizations Policy
      http://opensolaris.org/os/community/arc/bestpractices/rbac-auths/
  6.  When to use setuid -vs- RBAC roles and profiles
      http://opensolaris.org/os/community/arc/bestpractices/rbac- 
intro/ and
  7.  Building RBAC Rights Profiles
      http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
  8.  Solaris Audit Policy
      http://opensolaris.org/os/community/arc/policies/audit-policy/
  9.  Security questionaire
      http://opensolaris.org/os/community/arc/bestpractices/security-questions/
  10. Interface Taxonomy
      http://www.opensolaris.org/os/community/arc/policies/interface-taxonomy/
  11. Plugable Authentication Modules -- PAM
      http://opensolaris.org/os/community/arc/policies/PAM/
  12. Reusable Passwords In Command Line Arguments and Environment  
Variables
      http://opensolaris.org/os/community/arc/bestpractices/passwords-cli/
  13. Storing Reusable Passwords on a Filesystem
      http://opensolaris.org/os/community/arc/bestpractices/passwords-files/
  14. Release Taxonomy
      http://opensolaris.org/os/community/arc/policies/release-taxonomy/
  15. Service Management Facility (SMF) usage
      http://opensolaris.org/os/community/arc/policies/SMF-policy/


Appendix B - Suggested case materials
  1. man pages
  2. SMF manifests
  3. links to contracts

Appendix C - Definitions
Submitter
     an agent responsible for creation of an ARC project along with the
     materials describing that project.
Owner
     the ARC agent responsible for shepherding the case through review
     and ensuring a formal opinion is written where required.
Maintainer
     an agent responsible for releasing new versions of a program,  
typically
     the "main" contributor or person incharge of making Architectural
     decisions for the project
Contributor
     an agent who make contributions to a project, typically has a  
voice in
     making Architectural decisions for the project
Monitoring
     an agent who is only following the changes made in the community  
and
     has no Architectural input into the project
Volatile*
    interfaces that are very fluid and typically follow the originating
    community.  Typically these interfaces can not be imported by other
    projects.
Uncommitted*
    interfaces that are still evolving but will most likely be present  
from
    release to release.
Committed*
    interfaces that are stable and with Sun guaranteeing some level of
    compatibility from release to release.
Project Private*
    interfaces that are exposed only to or intended to be used only by
    the project being reviewed.  These interfaces can not be imported by
    other projects.
Not-An-Interface*
    components that are not interfaces.
Contracted* (interface modifier) - ARC review of Contract required
    interfaces that do not allow another project to import can be

*Note: see http://opensolaris.org/os/community/arc/policies/interface-taxonomy/ 
  for details


From Darren.Moffat@Sun.COM Thu Nov 13 01:51:58 2008
Received: from dm-sfbay-01.sfbay.sun.com (dm-sfbay-01.SFBay.Sun.COM [129.145.155.118])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAD9pwXj028425
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 13 Nov 2008 01:51:58 -0800 (PST)
Received: from gmp-eb-inf-2.sun.com (gmp-eb-inf-2.EU.Sun.COM [192.18.6.24])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mAD9pvFx052174
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 13 Nov 2008 01:51:58 -0800 (PST)
Received: from fe-emea-09.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id mAD9pvFs017334
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 13 Nov 2008 09:51:57 GMT
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0KA900C01MVPF600@fe-emea-09.sun.com>
 (original mail from Darren.Moffat@Sun.COM) for LSARC-ext@sac.sfbay.sun.com;
 Thu, 13 Nov 2008 09:51:56 +0000 (GMT)
Received: from [129.156.173.21] by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0KA900GLWNEJRC10@fe-emea-09.sun.com> for
 LSARC-ext@sac.sfbay.sun.com; Thu, 13 Nov 2008 09:51:55 +0000 (GMT)
Date: Thu, 13 Nov 2008 09:51:55 +0000
From: Darren J Moffat <Darren.Moffat@Sun.COM>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
 timeout	11/19/2008]
In-reply-to: <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com>
Sender: Darren.Moffat@Sun.COM
To: Tom Childers <tom.childers@Sun.COM>
Cc: LSARC-ext@sac.sfbay.sun.com, Barbara Kroczak <Barbara.Kroczak@Sun.COM>,
        Gilles Bellaton <Gilles.Bellaton@Sun.COM>,
        Didier Simonazzi <Didier.Simonazzi@Sun.COM>
Message-id: <491BF8BB.3050200@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
References: <490AC47F.9040700@sun.com>
 <62CA2FFE-CAC7-4995-B711-667D89D2D412@sun.com> <4912FB8A.8070902@sun.com>
 <D0964944-3893-4661-BBA0-EECF59EF8569@sun.com> <4918A818.1020203@sun.com>
 <6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com> <491A9B6E.4070408@sun.com>
 <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com>
User-Agent: Thunderbird 2.0.0.16 (X11/20080922)
Content-Length: 910
Status: RO
X-Status: $$$$
X-UID: 0000000002

The "into OpenSolaris" and an install location of /opt/opends are 
incompatible.  If the intention is delivery as part of OpenSolaris then 
surely it should be installed in an integrated rather than unbundled 
location ?

What is the SMF service FMRI and what SMF method credential does it run 
with?

What are the steps required to make this OpenDS delivery usable as the 
LDAP backend for the OpenSolaris nsswitch ?  Where is this documented on 
how to do it ?  Are all the required LDIF/schema files delivered or are 
they reusing ones already in Solaris (including for the Solaris RBAC 
databases - the package map seems to hint at this).

All of the above are the minimum things I'd expect given the 
"Integration into OpenSolaris".  I can maybe live with /opt/opends as 
the install location but the lack of an SMF service and easy way to make 
it the nsswitch LDAP target I can not.

--
Darren J Moffat

From Gilles.Bellaton@Sun.COM Thu Nov 13 03:48:04 2008
Received: from dm-sfbay-02.sfbay.sun.com (dm-sfbay-02.SFBay.Sun.COM [129.146.11.31])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mADBlwFY000774
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 13 Nov 2008 03:48:04 -0800 (PST)
Received: from gmp-eb-inf-2.sun.com (gmp-eb-inf-2.EU.Sun.COM [192.18.6.24])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mADBlwMV061389
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 13 Nov 2008 03:47:58 -0800 (PST)
Received: from fe-emea-09.sun.com (gmp-eb-lb-2-fe3.eu.sun.com [192.18.6.12])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id mADBlq6F008787
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 13 Nov 2008 11:47:52 GMT
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0KA900G01RZ68C00@fe-emea-09.sun.com>
 (original mail from Gilles.Bellaton@Sun.COM) for LSARC-ext@sac.sfbay.sun.com;
 Thu, 13 Nov 2008 11:47:52 +0000 (GMT)
Received: from [129.157.192.61] by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0KA900IZCSRKNJ60@fe-emea-09.sun.com> for
 LSARC-ext@sac.sfbay.sun.com; Thu, 13 Nov 2008 11:47:45 +0000 (GMT)
Date: Thu, 13 Nov 2008 12:47:44 +0100
From: Gilles Bellaton <Gilles.Bellaton@Sun.COM>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
 timeout	11/19/2008]
In-reply-to: <491BF8BB.3050200@Sun.COM>
Sender: Gilles.Bellaton@Sun.COM
To: Darren J Moffat <Darren.Moffat@Sun.COM>
Cc: Tom Childers <tom.childers@Sun.COM>, LSARC-ext@sac.sfbay.sun.com,
        Barbara Kroczak <Barbara.Kroczak@Sun.COM>,
        Didier Simonazzi <Didier.Simonazzi@Sun.COM>,
        Carole Hebrard <Carole.Hebrard@Sun.COM>,
        Ludovic Poitou <Ludovic.Poitou@Sun.COM>
Message-id: <491C13E0.5010502@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
References: <490AC47F.9040700@sun.com>
 <62CA2FFE-CAC7-4995-B711-667D89D2D412@sun.com> <4912FB8A.8070902@sun.com>
 <D0964944-3893-4661-BBA0-EECF59EF8569@sun.com> <4918A818.1020203@sun.com>
 <6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com> <491A9B6E.4070408@sun.com>
 <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM>
User-Agent: Thunderbird 2.0.0.17 (X11/20080925)
Content-Length: 1509
Status: RO
X-Status: $$$$
X-UID: 0000000003

I'm adding Carole and Ludo in copy as they will be able to answer more 
precisely than me
to your questions.

> The "into OpenSolaris" and an install location of /opt/opends are 
> incompatible.  If the intention is delivery as part of OpenSolaris 
> then surely it should be installed in an integrated rather than 
> unbundled location ?
Our intention is to deliver in the non WOS of OpenSOlaris as described 
here :
http://wikihome.sfbay.sun.com/spe-re/Wiki.jsp?page=Indiana_docks
So in a way similar to netbeans and glassfish

We were thinking that /opt would be the appropriate location for such a 
delivery.
>
> What is the SMF service FMRI and what SMF method credential does it 
> run with?
Carole, can you help me on this ?
>
> What are the steps required to make this OpenDS delivery usable as the 
> LDAP backend for the OpenSolaris nsswitch ?  Where is this documented 
> on how to do it ?  Are all the required LDIF/schema files delivered or 
> are they reusing ones already in Solaris (including for the Solaris 
> RBAC databases - the package map seems to hint at this).
The procedure to use OpenDS as a naming service as been described here.
The OpenDS package delivers all the necessary schema files.

Gilles

>
> All of the above are the minimum things I'd expect given the 
> "Integration into OpenSolaris".  I can maybe live with /opt/opends as 
> the install location but the lack of an SMF service and easy way to 
> make it the nsswitch LDAP target I can not.
>
> -- 
> Darren J Moffat


From ro@techfak.uni-bielefeld.de Thu Nov 13 03:53:35 2008
Received: from dm-sfbay-02.sfbay.sun.com (dm-sfbay-02.SFBay.Sun.COM [129.146.11.31])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mADBrYVW000899
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 13 Nov 2008 03:53:35 -0800 (PST)
Received: from sca-ea-mail-4.sun.com (sca-ea-mail-4.Sun.COM [192.18.43.22])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mADBrYwp063030
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 13 Nov 2008 03:53:34 -0800 (PST)
Received: from relay22.sun.com (relay22.sun.com [192.12.251.34] (may be forged))
	by sca-ea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id mADBrXSK007861
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 13 Nov 2008 11:53:33 GMT
Received: from mms25es.mms.us.syntegra.com ([150.143.232.90] [150.143.232.90]) by relay22i.sun.com with ESMTP id BT-MMP-1118351 for LSARC-ext@sac.sfbay.sun.com; Thu, 13 Nov 2008 11:53:33 Z
Received: from relay22.sun.com (relay22.sun.com [192.12.251.34]) by mms25es.mms.us.syntegra.com with ESMTP id BT-MMP-3424224 for LSARC-ext@sac.sfbay.sun.com; Thu, 13 Nov 2008 11:53:32 Z
Received: from smarthost.TechFak.Uni-Bielefeld.DE ([129.70.137.17] [129.70.137.17]) by relay22i.sun.com with ESMTP id BT-MMP-34333072 for LSARC-ext@sac.sfbay.sun.com; Thu, 13 Nov 2008 11:53:32 Z
Received: from manam.TechFak.Uni-Bielefeld.DE (manam.TechFak.Uni-Bielefeld.DE [129.70.137.47])
	(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
	(No client certificate requested)
	by smarthost.TechFak.Uni-Bielefeld.DE (Postfix) with ESMTP id 43D6A4834E;
	Thu, 13 Nov 2008 12:53:31 +0100 (CET)
Sender: ro@techfak.uni-bielefeld.de
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Tom Childers <tom.childers@sun.com>,
        Barbara Kroczak <Barbara.Kroczak@sun.com>, LSARC-ext@sac.sfbay.sun.com,
        Didier Simonazzi <Didier.Simonazzi@sun.com>,
        Gilles Bellaton <Gilles.Bellaton@sun.com>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack 	timeout	11/19/2008]
References: <490AC47F.9040700@sun.com> <62CA2FFE-CAC7-4995-B711-667D89D2D412@sun.com> <4912FB8A.8070902@sun.com> <D0964944-3893-4661-BBA0-EECF59EF8569@sun.com> <4918A818.1020203@sun.com> <6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com> <491A9B6E.4070408@sun.com> <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM>
From: Rainer Orth <ro@techfak.uni-bielefeld.de>
Date: 13 Nov 2008 12:53:30 +0100
In-Reply-To: Darren J Moffat's message of "Thu, 13 Nov 2008 09:51:55 +0000"
Message-ID: <yddskpvlu4l.fsf@manam.TechFak.Uni-Bielefeld.DE>
Lines: 17
X-Brightmail-Tracker: AAAAAA==
X-Mailer: Gnus v5.6.44/Emacs 19.34
X-Antispam: No, score=0.0/5.0, scanned in 0.687sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
MIME-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Length: 674
Status: RO
X-Status: $$$$
X-UID: 0000000004

Darren J Moffat <Darren.Moffat@Sun.COM> writes:

> All of the above are the minimum things I'd expect given the 
> "Integration into OpenSolaris".  I can maybe live with /opt/opends as 
> the install location but the lack of an SMF service and easy way to make 
> it the nsswitch LDAP target I can not.

Besides, that should be /opt/SUNWopends to follow existing practice
(although I agree that full integration is certainly strongly preferable).
I don't think this case can singlehandedly create a differing precedent
here.

	Rainer

-- 
-----------------------------------------------------------------------------
Rainer Orth, Faculty of Technology, Bielefeld University

From Ludovic.Poitou@Sun.COM Thu Nov 13 04:10:28 2008
Received: from dm-sfbay-02.sfbay.sun.com (dm-sfbay-02.SFBay.Sun.COM [129.146.11.31])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mADCASUu001553
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 13 Nov 2008 04:10:28 -0800 (PST)
Received: from gmp-eb-inf-2.sun.com (gmp-eb-inf-2.EU.Sun.COM [192.18.6.24])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mADCARre003871
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 13 Nov 2008 04:10:27 -0800 (PST)
Received: from fe-emea-10.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id mADCALl1012411
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 13 Nov 2008 12:10:22 GMT
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0KA900101TBE2500@fe-emea-10.sun.com>
 (original mail from Ludovic.Poitou@Sun.COM) for LSARC-ext@sac.sfbay.sun.com;
 Thu, 13 Nov 2008 12:10:21 +0000 (GMT)
Received: from dhcp-egnb07-211-104.France.Sun.COM ([129.157.211.104])
 by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0KA900DR9TT6X3D0@fe-emea-10.sun.com> for
 LSARC-ext@sac.sfbay.sun.com; Thu, 13 Nov 2008 12:10:18 +0000 (GMT)
Date: Thu, 13 Nov 2008 13:10:18 +0100
From: Ludovic Poitou <Ludovic.Poitou@Sun.COM>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
 timeout	11/19/2008]
In-reply-to: <491C13E0.5010502@sun.com>
Sender: Ludovic.Poitou@Sun.COM
To: Gilles Bellaton <Gilles.Bellaton@Sun.COM>
Cc: Darren J Moffat <Darren.Moffat@Sun.COM>,
        Tom Childers <tom.childers@Sun.COM>, LSARC-ext@sac.sfbay.sun.com,
        Barbara Kroczak <Barbara.Kroczak@Sun.COM>,
        Didier Simonazzi <Didier.Simonazzi@Sun.COM>,
        Carole Hebrard <Carole.Hebrard@Sun.COM>
Message-id: <A4340510-EF2F-4736-9FAB-76B4B76CE90D@Sun.COM>
MIME-version: 1.0
X-Mailer: Apple Mail (2.929.2)
Content-type: text/plain; delsp=yes; format=flowed; charset=US-ASCII
Content-transfer-encoding: 7BIT
References: <490AC47F.9040700@sun.com>
 <62CA2FFE-CAC7-4995-B711-667D89D2D412@sun.com> <4912FB8A.8070902@sun.com>
 <D0964944-3893-4661-BBA0-EECF59EF8569@sun.com> <4918A818.1020203@sun.com>
 <6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com> <491A9B6E.4070408@sun.com>
 <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM>
 <491C13E0.5010502@sun.com>
Content-Length: 3675
Status: RO
X-Status: $$$$
X-UID: 0000000005

Darren,

On Nov 13, 2008, at 12:47 PM, Gilles Bellaton wrote:

> I'm adding Carole and Ludo in copy as they will be able to answer  
> more precisely than me
> to your questions.
>
>> The "into OpenSolaris" and an install location of /opt/opends are  
>> incompatible.  If the intention is delivery as part of OpenSolaris  
>> then surely it should be installed in an integrated rather than  
>> unbundled location ?
> Our intention is to deliver in the non WOS of OpenSOlaris as  
> described here :
> http://wikihome.sfbay.sun.com/spe-re/Wiki.jsp?page=Indiana_docks
> So in a way similar to netbeans and glassfish
>
> We were thinking that /opt would be the appropriate location for  
> such a delivery.
>>
>> What is the SMF service FMRI and what SMF method credential does it  
>> run with?
> Carole, can you help me on this ?

The FMRI as of today is planned as "network/ldap/opends". Feedback and  
alternate suggestions are welcome. I have little experience with the  
best practices for FMRI.

After package installation, the Administrator must run a command to  
specify the location of the Database, the user and group for running  
the instance. If the user "opends" and group "opends" exist on the  
system, they will be proposed by default.

The SMF method credentials would then be as below :


<method_credential user='opends'
                                        group='opends'
                                         
privileges='basic,net_privaddr,sys_resource,!proc_info,!file_link_any'
                                         
limit_privileges='basic,net_privaddr,sys_resource,!proc_info,! 
file_link_any' />


>
>>
>> What are the steps required to make this OpenDS delivery usable as  
>> the LDAP backend for the OpenSolaris nsswitch ?  Where is this  
>> documented on how to do it ?  Are all the required LDIF/schema  
>> files delivered or are they reusing ones already in Solaris  
>> (including for the Solaris RBAC databases - the package map seems  
>> to hint at this).

Could you point me to the schema files that are delivered in Solaris  
(OpenSolaris) for example for Solaris RBAC databases ?
The only reference to LDAP schema I could find was Kerberos and the  
Solaris schema part of the idsconfig code.

The intend of the OpenDS project is to deliver the schema files  
required so that OpenDS requires as little configuration as possible  
(still  need to populate the server with DIT structure, content and  
access controls).

Regards,

Ludovic.

>>
> The procedure to use OpenDS as a naming service as been described  
> here.
> The OpenDS package delivers all the necessary schema files.
>
> Gilles
>
>>
>> All of the above are the minimum things I'd expect given the  
>> "Integration into OpenSolaris".  I can maybe live with /opt/opends  
>> as the install location but the lack of an SMF service and easy way  
>> to make it the nsswitch LDAP target I can not.
>>
>> -- 
>> Darren J Moffat
>

Ludovic Poitou                                    Sun Microsystems Inc.
OpenDS Community Lead               Directory Services
http://blogs.sun.com/Ludo/         Grenoble Engineering Center - France





From Darren.Moffat@Sun.COM Thu Nov 13 04:27:56 2008
Received: from dm-sfbay-01.sfbay.sun.com (dm-sfbay-01.SFBay.Sun.COM [129.145.155.118])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mADCRuRA001688
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 13 Nov 2008 04:27:56 -0800 (PST)
Received: from gmp-eb-inf-1.sun.com (gmp-eb-inf-1.EU.Sun.COM [192.18.6.21])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mADCRtlq047991
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 13 Nov 2008 04:27:55 -0800 (PST)
Received: from fe-emea-09.sun.com (gmp-eb-lb-2-fe2.eu.sun.com [192.18.6.11])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id mADCRnmA013962
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 13 Nov 2008 12:27:50 GMT
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0KA900301U3ES900@fe-emea-09.sun.com>
 (original mail from Darren.Moffat@Sun.COM) for LSARC-ext@sac.sfbay.sun.com;
 Thu, 13 Nov 2008 12:27:49 +0000 (GMT)
Received: from [129.156.173.21] by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0KA900G9HUM7RCC0@fe-emea-09.sun.com> for
 LSARC-ext@sac.sfbay.sun.com; Thu, 13 Nov 2008 12:27:45 +0000 (GMT)
Date: Thu, 13 Nov 2008 12:27:43 +0000
From: Darren J Moffat <Darren.Moffat@Sun.COM>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
 timeout	11/19/2008]
In-reply-to: <A4340510-EF2F-4736-9FAB-76B4B76CE90D@Sun.COM>
Sender: Darren.Moffat@Sun.COM
To: Ludovic Poitou <Ludovic.Poitou@Sun.COM>
Cc: Gilles Bellaton <Gilles.Bellaton@Sun.COM>,
        Tom Childers <tom.childers@Sun.COM>, LSARC-ext@sac.sfbay.sun.com,
        Barbara Kroczak <Barbara.Kroczak@Sun.COM>,
        Didier Simonazzi <Didier.Simonazzi@Sun.COM>,
        Carole Hebrard <Carole.Hebrard@Sun.COM>
Message-id: <491C1D3F.2020405@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
References: <490AC47F.9040700@sun.com>
 <62CA2FFE-CAC7-4995-B711-667D89D2D412@sun.com> <4912FB8A.8070902@sun.com>
 <D0964944-3893-4661-BBA0-EECF59EF8569@sun.com> <4918A818.1020203@sun.com>
 <6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com> <491A9B6E.4070408@sun.com>
 <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM>
 <491C13E0.5010502@sun.com> <A4340510-EF2F-4736-9FAB-76B4B76CE90D@Sun.COM>
User-Agent: Thunderbird 2.0.0.16 (X11/20080922)
Content-Length: 3264
Status: RO
X-Status: $$$$
X-UID: 0000000006

Ludovic Poitou wrote:
> Darren,
> 
> On Nov 13, 2008, at 12:47 PM, Gilles Bellaton wrote:
> 
>> I'm adding Carole and Ludo in copy as they will be able to answer more 
>> precisely than me
>> to your questions.
>>
>>> The "into OpenSolaris" and an install location of /opt/opends are 
>>> incompatible.  If the intention is delivery as part of OpenSolaris 
>>> then surely it should be installed in an integrated rather than 
>>> unbundled location ?
>> Our intention is to deliver in the non WOS of OpenSOlaris as described 
>> here :
>> http://wikihome.sfbay.sun.com/spe-re/Wiki.jsp?page=Indiana_docks
>> So in a way similar to netbeans and glassfish

>> We were thinking that /opt would be the appropriate location for such 
>> a delivery.

Maybe but why should OpenDS be in /opt when PSARC/2008/507 approved 
OpenLDAP for integration in /usr (with /usr/lib/openldap/ for the server 
parts) ?

They way the binaries are integrated into the RE doc is not really an 
architectural issue, where it is installed is.

This makes OpenLDAP a more "first class" citizen then OpenDS which seems 
a little ironic to me.

>>> What is the SMF service FMRI and what SMF method credential does it 
>>> run with?
>> Carole, can you help me on this ?
> 
> The FMRI as of today is planned as "network/ldap/opends". Feedback and 
> alternate suggestions are welcome. I have little experience with the 
> best practices for FMRI.

svc:/network/ldap/server:opends

This follows the same model as we use for http where ldap/server is the 
service the use wants and opends is the software that provides a 
particular instance of it.  It also follows the precedent for LDAP 
servers that is effectively setin PSARC/2008/507

This allows for:

svc:/network/ldap/server:openldap (Already defined in PSARC/2008/507)
svc:/network/ldap/server:sunjavaenterprisedirectoryserver :-)

> After package installation, the Administrator must run a command to 
> specify the location of the Database, the user and group for running the 
> instance. If the user "opends" and group "opends" exist on the system, 
> they will be proposed by default.

Can't we have preconfigured defaults for all of that so that all that is 
required is enabling the service ?  I believe that is the situation for 
the OpenLDAP server.

Is this project proposing to add "opends" user and group ids to the 
default Solaris config ?

Given that PSARC/2008/507 already proposed adding "openldap" user and 
group but has not yet delivered I think it may be prudent to change that 
case and this one to use an "ldap" user and group rather than each 
having their own uid and gid.  This is similar to what has already been 
done for web servers, all of them that we ship are defaulted to use the 
"webservd" user account not each having their own.

> The SMF method credentials would then be as below :
> 
> 
> <method_credential user='opends'
>                                        group='opends'
>                                        
> privileges='basic,net_privaddr,sys_resource,!proc_info,!file_link_any'
>                                        
> limit_privileges='basic,net_privaddr,sys_resource,!proc_info,!file_link_any' 
> />

Looks good, modulo the above issue on the user/group names.

-- 
Darren J Moffat

From Darren.Moffat@Sun.COM Thu Nov 13 04:33:42 2008
Received: from dm-sfbay-01.sfbay.sun.com (dm-sfbay-01.SFBay.Sun.COM [129.145.155.118])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mADCXgaw001827
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 13 Nov 2008 04:33:42 -0800 (PST)
Received: from gmp-eb-inf-2.sun.com (gmp-eb-inf-2.EU.Sun.COM [192.18.6.24])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mADCXfAt050527
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 13 Nov 2008 04:33:42 -0800 (PST)
Received: from fe-emea-10.sun.com (gmp-eb-lb-2-fe3.eu.sun.com [192.18.6.12])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id mADCXaXD016281
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 13 Nov 2008 12:33:36 GMT
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0KA900D01UPZII00@fe-emea-10.sun.com>
 (original mail from Darren.Moffat@Sun.COM) for LSARC-ext@sac.sfbay.sun.com;
 Thu, 13 Nov 2008 12:33:36 +0000 (GMT)
Received: from [129.156.173.21] by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0KA900IB3UVMSV90@fe-emea-10.sun.com> for
 LSARC-ext@sac.sfbay.sun.com; Thu, 13 Nov 2008 12:33:23 +0000 (GMT)
Date: Thu, 13 Nov 2008 12:33:22 +0000
From: Darren J Moffat <Darren.Moffat@Sun.COM>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
 timeout	11/19/2008]
In-reply-to: <A4340510-EF2F-4736-9FAB-76B4B76CE90D@Sun.COM>
Sender: Darren.Moffat@Sun.COM
To: Ludovic Poitou <Ludovic.Poitou@Sun.COM>
Cc: Gilles Bellaton <Gilles.Bellaton@Sun.COM>,
        Tom Childers <tom.childers@Sun.COM>, LSARC-ext@sac.sfbay.sun.com,
        Barbara Kroczak <Barbara.Kroczak@Sun.COM>,
        Didier Simonazzi <Didier.Simonazzi@Sun.COM>,
        Carole Hebrard <Carole.Hebrard@Sun.COM>
Message-id: <491C1E92.8020505@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
References: <490AC47F.9040700@sun.com>
 <62CA2FFE-CAC7-4995-B711-667D89D2D412@sun.com> <4912FB8A.8070902@sun.com>
 <D0964944-3893-4661-BBA0-EECF59EF8569@sun.com> <4918A818.1020203@sun.com>
 <6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com> <491A9B6E.4070408@sun.com>
 <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM>
 <491C13E0.5010502@sun.com> <A4340510-EF2F-4736-9FAB-76B4B76CE90D@Sun.COM>
User-Agent: Thunderbird 2.0.0.16 (X11/20080922)
Content-Length: 2724
Status: RO
X-Status: $$$$
X-UID: 0000000007

Ludovic Poitou wrote:
> Darren,
> 
> On Nov 13, 2008, at 12:47 PM, Gilles Bellaton wrote:
> 
>> I'm adding Carole and Ludo in copy as they will be able to answer more 
>> precisely than me
>> to your questions.
>>
>>> The "into OpenSolaris" and an install location of /opt/opends are 
>>> incompatible.  If the intention is delivery as part of OpenSolaris 
>>> then surely it should be installed in an integrated rather than 
>>> unbundled location ?
>> Our intention is to deliver in the non WOS of OpenSOlaris as described 
>> here :
>> http://wikihome.sfbay.sun.com/spe-re/Wiki.jsp?page=Indiana_docks
>> So in a way similar to netbeans and glassfish
>>
>> We were thinking that /opt would be the appropriate location for such 
>> a delivery.
>>>
>>> What is the SMF service FMRI and what SMF method credential does it 
>>> run with?
>> Carole, can you help me on this ?
> 
> The FMRI as of today is planned as "network/ldap/opends". Feedback and 
> alternate suggestions are welcome. I have little experience with the 
> best practices for FMRI.
> 
> After package installation, the Administrator must run a command to 
> specify the location of the Database, the user and group for running the 
> instance. If the user "opends" and group "opends" exist on the system, 
> they will be proposed by default.
> 
> The SMF method credentials would then be as below :
> 
> 
> <method_credential user='opends'
>                                        group='opends'
>                                        
> privileges='basic,net_privaddr,sys_resource,!proc_info,!file_link_any'
>                                        
> limit_privileges='basic,net_privaddr,sys_resource,!proc_info,!file_link_any' 
> />
> 
> 
>>
>>>
>>> What are the steps required to make this OpenDS delivery usable as 
>>> the LDAP backend for the OpenSolaris nsswitch ?  Where is this 
>>> documented on how to do it ?  Are all the required LDIF/schema files 
>>> delivered or are they reusing ones already in Solaris (including for 
>>> the Solaris RBAC databases - the package map seems to hint at this).
> 
> Could you point me to the schema files that are delivered in Solaris 
> (OpenSolaris) for example for Solaris RBAC databases ?
> The only reference to LDAP schema I could find was Kerberos and the 
> Solaris schema part of the idsconfig code.

/usr/share/lib/ldif/

The legacy idsconfig is sadly the only place that the ldif for the 
Solaris RBAC databases is shipped at the moment.

> The intend of the OpenDS project is to deliver the schema files required 
> so that OpenDS requires as little configuration as possible (still  need 
> to populate the server with DIT structure, content and access controls).

Great.

-- 
Darren J Moffat

From Ludovic.Poitou@Sun.COM Thu Nov 13 06:09:54 2008
Received: from dm-sfbay-01.sfbay.sun.com (dm-sfbay-01.SFBay.Sun.COM [129.145.155.118])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mADE9sAs005271
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 13 Nov 2008 06:09:54 -0800 (PST)
Received: from gmp-eb-inf-1.sun.com (gmp-eb-inf-1.EU.Sun.COM [192.18.6.21])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mADE9r7Y025794
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 13 Nov 2008 06:09:54 -0800 (PST)
Received: from fe-emea-09.sun.com (gmp-eb-lb-2-fe3.eu.sun.com [192.18.6.12])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id mADE9mKH002754
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 13 Nov 2008 14:09:48 GMT
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0KA900F01YREKO00@fe-emea-09.sun.com>
 (original mail from Ludovic.Poitou@Sun.COM) for LSARC-ext@sac.sfbay.sun.com;
 Thu, 13 Nov 2008 14:09:48 +0000 (GMT)
Received: from dhcp-egnb07-211-104.France.Sun.COM ([129.157.211.104])
 by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0KA900C85ZBZPW80@fe-emea-09.sun.com> for
 LSARC-ext@sac.sfbay.sun.com; Thu, 13 Nov 2008 14:09:36 +0000 (GMT)
Date: Thu, 13 Nov 2008 15:09:36 +0100
From: Ludovic Poitou <Ludovic.Poitou@Sun.COM>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
 timeout	11/19/2008]
In-reply-to: <491C1E92.8020505@Sun.COM>
Sender: Ludovic.Poitou@Sun.COM
To: Darren J Moffat <Darren.Moffat@Sun.COM>
Cc: Gilles Bellaton <Gilles.Bellaton@Sun.COM>,
        Tom Childers <tom.childers@Sun.COM>, LSARC-ext@sac.sfbay.sun.com,
        Barbara Kroczak <Barbara.Kroczak@Sun.COM>,
        Didier Simonazzi <Didier.Simonazzi@Sun.COM>,
        Carole Hebrard <Carole.Hebrard@Sun.COM>
Message-id: <2997D6D4-B420-4CDD-9B5F-F3D30E819B83@Sun.COM>
MIME-version: 1.0
X-Mailer: Apple Mail (2.929.2)
Content-type: text/plain; delsp=yes; format=flowed; charset=US-ASCII
Content-transfer-encoding: 7BIT
References: <490AC47F.9040700@sun.com>
 <62CA2FFE-CAC7-4995-B711-667D89D2D412@sun.com> <4912FB8A.8070902@sun.com>
 <D0964944-3893-4661-BBA0-EECF59EF8569@sun.com> <4918A818.1020203@sun.com>
 <6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com> <491A9B6E.4070408@sun.com>
 <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM>
 <491C13E0.5010502@sun.com> <A4340510-EF2F-4736-9FAB-76B4B76CE90D@Sun.COM>
 <491C1E92.8020505@Sun.COM>
Content-Length: 4074
Status: RO
X-Status: $$$$
X-UID: 0000000008


On Nov 13, 2008, at 1:33 PM, Darren J Moffat wrote:

> Ludovic Poitou wrote:
>> Darren,
>> On Nov 13, 2008, at 12:47 PM, Gilles Bellaton wrote:
>>> I'm adding Carole and Ludo in copy as they will be able to answer  
>>> more precisely than me
>>> to your questions.
>>>
>>>> The "into OpenSolaris" and an install location of /opt/opends are  
>>>> incompatible.  If the intention is delivery as part of  
>>>> OpenSolaris then surely it should be installed in an integrated  
>>>> rather than unbundled location ?
>>> Our intention is to deliver in the non WOS of OpenSOlaris as  
>>> described here :
>>> http://wikihome.sfbay.sun.com/spe-re/Wiki.jsp?page=Indiana_docks
>>> So in a way similar to netbeans and glassfish
>>>
>>> We were thinking that /opt would be the appropriate location for  
>>> such a delivery.
>>>>
>>>> What is the SMF service FMRI and what SMF method credential does  
>>>> it run with?
>>> Carole, can you help me on this ?
>> The FMRI as of today is planned as "network/ldap/opends". Feedback  
>> and alternate suggestions are welcome. I have little experience  
>> with the best practices for FMRI.
>> After package installation, the Administrator must run a command to  
>> specify the location of the Database, the user and group for  
>> running the instance. If the user "opends" and group "opends" exist  
>> on the system, they will be proposed by default.
>> The SMF method credentials would then be as below :
>> <method_credential user='opends'
>>                                       group='opends'
>>                                        
>> privileges='basic,net_privaddr,sys_resource,!proc_info,! 
>> file_link_any'
>>                                        
>> limit_privileges='basic,net_privaddr,sys_resource,!proc_info,! 
>> file_link_any' />
>>>
>>>>
>>>> What are the steps required to make this OpenDS delivery usable  
>>>> as the LDAP backend for the OpenSolaris nsswitch ?  Where is this  
>>>> documented on how to do it ?  Are all the required LDIF/schema  
>>>> files delivered or are they reusing ones already in Solaris  
>>>> (including for the Solaris RBAC databases - the package map seems  
>>>> to hint at this).
>> Could you point me to the schema files that are delivered in  
>> Solaris (OpenSolaris) for example for Solaris RBAC databases ?
>> The only reference to LDAP schema I could find was Kerberos and the  
>> Solaris schema part of the idsconfig code.
>
> /usr/share/lib/ldif/

Where can I browse a source repository that shows /usr/share/lib/ldif ?
It's not in my OpenSolaris installation and I can browse such  
directory from OpenSolaris.org OpenGrok.


>
>
> The legacy idsconfig is sadly the only place that the ldif for the  
> Solaris RBAC databases is shipped at the moment.

Sadly, the OIDs for some schema referenced in idsconfig and in  
Solaris / OpenSolaris documentation do not match the OIDs registered  
from the Sun LDAP Schema Registry (especially Solaris Trusted  
Extensions ones) :-(
I'm trying to re-conciliate both without too much impact on customers.

Ludovic.

>
>
>> The intend of the OpenDS project is to deliver the schema files  
>> required so that OpenDS requires as little configuration as  
>> possible (still  need to populate the server with DIT structure,  
>> content and access controls).
>
> Great.
>
> -- 
> Darren J Moffat

Ludovic Poitou                                    Sun Microsystems Inc.
OpenDS Community Lead               Directory Services
http://blogs.sun.com/Ludo/         Grenoble Engineering Center - France





From carlsonj@phorcys.east.sun.com Thu Nov 13 06:31:35 2008
Received: from phorcys.east.sun.com (phorcys.East.Sun.COM [129.148.174.143])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mADEVY9Z005942
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 13 Nov 2008 06:31:34 -0800 (PST)
Received: from phorcys.east.sun.com (localhost [127.0.0.1])
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id mADEVYIb023854;
	Thu, 13 Nov 2008 09:31:34 -0500 (EST)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3/Submit) id mADEVXX5023851;
	Thu, 13 Nov 2008 09:31:33 -0500 (EST)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Message-ID: <18716.14917.907419.605178@gargle.gargle.HOWL>
Date: Thu, 13 Nov 2008 09:31:33 -0500
From: James Carlson <james.d.carlson@sun.com>
To: Gilles Bellaton <Gilles.Bellaton@sun.com>
Cc: Darren J Moffat <Darren.Moffat@sun.com>,
        Barbara Kroczak <Barbara.Kroczak@sun.com>, LSARC-ext@sac.sfbay.sun.com,
        Tom Childers <tom.childers@sun.com>,
        Carole Hebrard <Carole.Hebrard@sun.com>,
        Ludovic Poitou <Ludovic.Poitou@sun.com>,
        Didier Simonazzi <Didier.Simonazzi@sun.com>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
	timeout	11/19/2008]
In-Reply-To: <491C13E0.5010502@sun.com>
References: <490AC47F.9040700@sun.com>
	<62CA2FFE-CAC7-4995-B711-667D89D2D412@sun.com>
	<4912FB8A.8070902@sun.com>
	<D0964944-3893-4661-BBA0-EECF59EF8569@sun.com>
	<4918A818.1020203@sun.com>
	<6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com>
	<491A9B6E.4070408@sun.com>
	<EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com>
	<491BF8BB.3050200@Sun.COM>
	<491C13E0.5010502@sun.com>
X-Mailer: VM 7.01 under Emacs 21.3.1
Content-Length: 1434
Status: RO
X-Status: $$$$
X-UID: 0000000009

Gilles Bellaton writes:
> Our intention is to deliver in the non WOS of OpenSOlaris as described 
> here :
> http://wikihome.sfbay.sun.com/spe-re/Wiki.jsp?page=Indiana_docks
> So in a way similar to netbeans and glassfish
> 
> We were thinking that /opt would be the appropriate location for such a 
> delivery.

There's an interesting architectural question underneath this.  At one
point in time, /opt was used for Sun-delivered projects (even possibly
co-packaged or bundled ones) where there was an expectation that there
could be more than one such implementation, and that users might have
to choose which one they want.

That's what exiled the compilers to /opt; not just that it was once a
separate paid-for product, but that you could get Solaris compilers
from multiple places/vendors.

Now that we're mainstreaming FOSS stuff directly into /usr, do the old
rules about /opt still apply?  Do any rules about that old segregation
still apply?

I suspect that the same arguments that work for the old, abandoned
/usr/sfw experiment may well apply to things that would have been
rightly destined to /opt.  Unfortunately, we don't have precedent for
this.

Should /usr prepare for /opt refugees as well?

-- 
James Carlson, Solaris Networking              <james.d.carlson@sun.com>
Sun Microsystems / 35 Network Drive        71.232W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.496N   Fax +1 781 442 1677

From Gilles.Bellaton@Sun.COM Fri Nov 14 00:27:45 2008
Received: from dm-sfbay-01.sfbay.sun.com (dm-sfbay-01.SFBay.Sun.COM [129.145.155.118])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAE8RjsF023952
	for <LSARC-ext@sac.sfbay.sun.com>; Fri, 14 Nov 2008 00:27:45 -0800 (PST)
Received: from gmp-eb-inf-2.sun.com (gmp-eb-inf-2.EU.Sun.COM [192.18.6.24])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mAE8RiGd022152
	for <LSARC-ext@sac.sfbay.sun.com>; Fri, 14 Nov 2008 00:27:44 -0800 (PST)
Received: from fe-emea-10.sun.com (gmp-eb-lb-2-fe3.eu.sun.com [192.18.6.12])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id mAE8RcFe011703
	for <LSARC-ext@sac.sfbay.sun.com>; Fri, 14 Nov 2008 08:27:38 GMT
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0KAB00201E17GO00@fe-emea-10.sun.com>
 (original mail from Gilles.Bellaton@Sun.COM) for LSARC-ext@sac.sfbay.sun.com;
 Fri, 14 Nov 2008 08:27:38 +0000 (GMT)
Received: from [129.157.192.61] by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0KAB00KV0E604K20@fe-emea-10.sun.com> for
 LSARC-ext@sac.sfbay.sun.com; Fri, 14 Nov 2008 08:27:37 +0000 (GMT)
Date: Fri, 14 Nov 2008 09:27:36 +0100
From: Gilles Bellaton <Gilles.Bellaton@Sun.COM>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
 timeout	11/19/2008]
In-reply-to: <18716.14917.907419.605178@gargle.gargle.HOWL>
Sender: Gilles.Bellaton@Sun.COM
To: James Carlson <James.D.Carlson@Sun.COM>
Cc: Darren J Moffat <Darren.Moffat@Sun.COM>,
        Barbara Kroczak <Barbara.Kroczak@Sun.COM>, LSARC-ext@sac.sfbay.sun.com,
        Tom Childers <tom.childers@Sun.COM>,
        Carole Hebrard <Carole.Hebrard@Sun.COM>,
        Ludovic Poitou <Ludovic.Poitou@Sun.COM>,
        Didier Simonazzi <Didier.Simonazzi@Sun.COM>
Message-id: <491D3678.2030908@sun.com>
MIME-version: 1.0
Content-type: multipart/alternative;
 boundary="Boundary_(ID_DRtXXw49a/PJJV+vOQhByg)"
References: <490AC47F.9040700@sun.com>
 <62CA2FFE-CAC7-4995-B711-667D89D2D412@sun.com> <4912FB8A.8070902@sun.com>
 <D0964944-3893-4661-BBA0-EECF59EF8569@sun.com> <4918A818.1020203@sun.com>
 <6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com> <491A9B6E.4070408@sun.com>
 <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM>
 <491C13E0.5010502@sun.com> <18716.14917.907419.605178@gargle.gargle.HOWL>
User-Agent: Thunderbird 2.0.0.17 (X11/20080925)
Content-Length: 3823
Status: RO
X-Status: $$$$
X-UID: 0000000010

This is a multi-part message in MIME format.

--Boundary_(ID_DRtXXw49a/PJJV+vOQhByg)
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT

James Carlson wrote:
> Gilles Bellaton writes:
>   
>> Our intention is to deliver in the non WOS of OpenSOlaris as described 
>> here :
>> http://wikihome.sfbay.sun.com/spe-re/Wiki.jsp?page=Indiana_docks
>> So in a way similar to netbeans and glassfish
>>
>> We were thinking that /opt would be the appropriate location for such a 
>> delivery.
>>     
>
> There's an interesting architectural question underneath this.  At one
> point in time, /opt was used for Sun-delivered projects (even possibly
> co-packaged or bundled ones) where there was an expectation that there
> could be more than one such implementation, and that users might have
> to choose which one they want.
>
> That's what exiled the compilers to /opt; not just that it was once a
> separate paid-for product, but that you could get Solaris compilers
> from multiple places/vendors.
>
> Now that we're mainstreaming FOSS stuff directly into /usr, do the old
> rules about /opt still apply?  Do any rules about that old segregation
> still apply?
>
> I suspect that the same arguments that work for the old, abandoned
> /usr/sfw experiment may well apply to things that would have been
> rightly destined to /opt.  Unfortunately, we don't have precedent for
> this.
>
> Should /usr prepare for /opt refugees as well?
>
>   
This looks a generic question to me that may need to be handled outside 
of this case.

As for OpenDS, I believe we can adapt quickly and move to /usr if this 
is the direction
that is chosen.

Gilles

--Boundary_(ID_DRtXXw49a/PJJV+vOQhByg)
Content-type: text/html; charset=ISO-8859-1
Content-transfer-encoding: 7BIT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
  <meta content="text/html;charset=ISO-8859-1" http-equiv="Content-Type">
</head>
<body bgcolor="#ffffff" text="#000000">
James Carlson wrote:
<blockquote cite="mid:18716.14917.907419.605178@gargle.gargle.HOWL"
 type="cite">
  <pre wrap="">Gilles Bellaton writes:
  </pre>
  <blockquote type="cite">
    <pre wrap="">Our intention is to deliver in the non WOS of OpenSOlaris as described 
here :
<a class="moz-txt-link-freetext" href="http://wikihome.sfbay.sun.com/spe-re/Wiki.jsp?page=Indiana_docks">http://wikihome.sfbay.sun.com/spe-re/Wiki.jsp?page=Indiana_docks</a>
So in a way similar to netbeans and glassfish

We were thinking that /opt would be the appropriate location for such a 
delivery.
    </pre>
  </blockquote>
  <pre wrap=""><!---->
There's an interesting architectural question underneath this.  At one
point in time, /opt was used for Sun-delivered projects (even possibly
co-packaged or bundled ones) where there was an expectation that there
could be more than one such implementation, and that users might have
to choose which one they want.

That's what exiled the compilers to /opt; not just that it was once a
separate paid-for product, but that you could get Solaris compilers
from multiple places/vendors.

Now that we're mainstreaming FOSS stuff directly into /usr, do the old
rules about /opt still apply?  Do any rules about that old segregation
still apply?

I suspect that the same arguments that work for the old, abandoned
/usr/sfw experiment may well apply to things that would have been
rightly destined to /opt.  Unfortunately, we don't have precedent for
this.

Should /usr prepare for /opt refugees as well?

  </pre>
</blockquote>
This looks a generic question to me that may need to be handled outside
of this case.<br>
<br>
As for OpenDS, I believe we can adapt quickly and move to /usr if this
is the direction <br>
that is chosen.<br>
<br>
Gilles<br>
</body>
</html>

--Boundary_(ID_DRtXXw49a/PJJV+vOQhByg)--

From Ludovic.Poitou@Sun.COM Fri Nov 14 01:06:45 2008
Received: from dm-sfbay-02.sfbay.sun.com (dm-sfbay-02.SFBay.Sun.COM [129.146.11.31])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAE96jNJ025184
	for <LSARC-ext@sac.sfbay.sun.com>; Fri, 14 Nov 2008 01:06:45 -0800 (PST)
Received: from gmp-eb-inf-1.sun.com (gmp-eb-inf-1.EU.Sun.COM [192.18.6.21])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mAE96i0B002953
	for <LSARC-ext@sac.sfbay.sun.com>; Fri, 14 Nov 2008 01:06:45 -0800 (PST)
Received: from fe-emea-10.sun.com (gmp-eb-lb-2-fe3.eu.sun.com [192.18.6.12])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id mAE96dQe002261
	for <LSARC-ext@sac.sfbay.sun.com>; Fri, 14 Nov 2008 09:06:39 GMT
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0KAB00F01EECN000@fe-emea-10.sun.com>
 (original mail from Ludovic.Poitou@Sun.COM) for LSARC-ext@sac.sfbay.sun.com;
 Fri, 14 Nov 2008 09:06:39 +0000 (GMT)
Received: from dhcp-egnb07-211-104.France.Sun.COM ([129.157.211.104])
 by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0KAB00FMUFYD3Z40@fe-emea-10.sun.com> for
 LSARC-ext@sac.sfbay.sun.com; Fri, 14 Nov 2008 09:06:14 +0000 (GMT)
Date: Fri, 14 Nov 2008 10:06:12 +0100
From: Ludovic Poitou <Ludovic.Poitou@Sun.COM>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
 timeout	11/19/2008]
In-reply-to: <491C1D3F.2020405@Sun.COM>
Sender: Ludovic.Poitou@Sun.COM
To: Darren J Moffat <Darren.Moffat@Sun.COM>
Cc: Gilles Bellaton <Gilles.Bellaton@Sun.COM>,
        Tom Childers <tom.childers@Sun.COM>, LSARC-ext@sac.sfbay.sun.com,
        Barbara Kroczak <Barbara.Kroczak@Sun.COM>,
        Didier Simonazzi <Didier.Simonazzi@Sun.COM>,
        Carole Hebrard <Carole.Hebrard@Sun.COM>
Message-id: <8785B34D-39EC-42C3-ADDC-E121089C2264@Sun.COM>
MIME-version: 1.0
X-Mailer: Apple Mail (2.929.2)
Content-type: text/plain; delsp=yes; format=flowed; charset=US-ASCII
Content-transfer-encoding: 7BIT
References: <490AC47F.9040700@sun.com>
 <62CA2FFE-CAC7-4995-B711-667D89D2D412@sun.com> <4912FB8A.8070902@sun.com>
 <D0964944-3893-4661-BBA0-EECF59EF8569@sun.com> <4918A818.1020203@sun.com>
 <6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com> <491A9B6E.4070408@sun.com>
 <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM>
 <491C13E0.5010502@sun.com> <A4340510-EF2F-4736-9FAB-76B4B76CE90D@Sun.COM>
 <491C1D3F.2020405@Sun.COM>
Content-Length: 4854
Status: RO
X-Status: $$$$
X-UID: 0000000011


On Nov 13, 2008, at 1:27 PM, Darren J Moffat wrote:

> Ludovic Poitou wrote:
>> Darren,
>> On Nov 13, 2008, at 12:47 PM, Gilles Bellaton wrote:
>>> I'm adding Carole and Ludo in copy as they will be able to answer  
>>> more precisely than me
>>> to your questions.
>>>
>>>> The "into OpenSolaris" and an install location of /opt/opends are  
>>>> incompatible.  If the intention is delivery as part of  
>>>> OpenSolaris then surely it should be installed in an integrated  
>>>> rather than unbundled location ?
>>> Our intention is to deliver in the non WOS of OpenSOlaris as  
>>> described here :
>>> http://wikihome.sfbay.sun.com/spe-re/Wiki.jsp?page=Indiana_docks
>>> So in a way similar to netbeans and glassfish
>
>>> We were thinking that /opt would be the appropriate location for  
>>> such a delivery.
>
> Maybe but why should OpenDS be in /opt when PSARC/2008/507 approved  
> OpenLDAP for integration in /usr (with /usr/lib/openldap/ for the  
> server parts) ?
>
> They way the binaries are integrated into the RE doc is not really  
> an architectural issue, where it is installed is.
>
> This makes OpenLDAP a more "first class" citizen then OpenDS which  
> seems a little ironic to me.
>
>>>> What is the SMF service FMRI and what SMF method credential does  
>>>> it run with?
>>> Carole, can you help me on this ?
>> The FMRI as of today is planned as "network/ldap/opends". Feedback  
>> and alternate suggestions are welcome. I have little experience  
>> with the best practices for FMRI.
>
> svc:/network/ldap/server:opends
>
> This follows the same model as we use for http where ldap/server is  
> the service the use wants and opends is the software that provides a  
> particular instance of it.  It also follows the precedent for LDAP  
> servers that is effectively setin PSARC/2008/507
>
> This allows for:
>
> svc:/network/ldap/server:openldap (Already defined in PSARC/2008/507)
> svc:/network/ldap/server:sunjavaenterprisedirectoryserver :-)
>
>> After package installation, the Administrator must run a command to  
>> specify the location of the Database, the user and group for  
>> running the instance. If the user "opends" and group "opends" exist  
>> on the system, they will be proposed by default.
>
> Can't we have preconfigured defaults for all of that so that all  
> that is required is enabling the service ?  I believe that is the  
> situation for the OpenLDAP server.

In our experience, customers always have to do some initial  
configuration before enabling the service. The mandatory setup phase  
of OpenDS is a major added value over OpenLDAP, as it provides a  
better simple user experience.

>
>
> Is this project proposing to add "opends" user and group ids to the  
> default Solaris config ?

No, we're not proposing to add "opends" user and group ids.
We plan on documenting how to run OpenDS as non root, which privileges  
are required and suggest "opends" ids.

>
>
> Given that PSARC/2008/507 already proposed adding "openldap" user  
> and group but has not yet delivered I think it may be prudent to  
> change that case and this one to use an "ldap" user and group rather  
> than each having their own uid and gid.

I would be fine with using an "ldap" user and group if it exists to  
the default Solaris config.
I thought that PSARC/2008/507 gave up the idea of adding a specific  
user. If they change and deliver an "ldap" user, we will definitely  
leverage it.


Ludovic.



> This is similar to what has already been done for web servers, all  
> of them that we ship are defaulted to use the "webservd" user  
> account not each having their own.
>
>> The SMF method credentials would then be as below :
>> <method_credential user='opends'
>>                                       group='opends'
>>                                        
>> privileges='basic,net_privaddr,sys_resource,!proc_info,! 
>> file_link_any'
>>                                        
>> limit_privileges='basic,net_privaddr,sys_resource,!proc_info,! 
>> file_link_any' />
>
> Looks good, modulo the above issue on the user/group names.
>
> -- 
> Darren J Moffat

Ludovic Poitou                                    Sun Microsystems Inc.
OpenDS Community Lead               Directory Services
http://blogs.sun.com/Ludo/         Grenoble Engineering Center - France





From tom.childers@sun.com Mon Nov 17 10:51:50 2008
Received: from dm-sfbay-01.sfbay.sun.com (dm-sfbay-01.SFBay.Sun.COM [129.145.155.118])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAHIpnG7017787
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 17 Nov 2008 10:51:50 -0800 (PST)
Received: from sca-es-mail-1.sun.com (sca-es-mail-1.Sun.COM [192.18.43.132])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mAHIpns5022711
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 17 Nov 2008 10:51:49 -0800 (PST)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id mAHIpidY021181
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 17 Nov 2008 10:51:44 -0800 (PST)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0KAH00A01PXV5900@fe-sfbay-10.sun.com>
 (original mail from tom.childers@sun.com) for LSARC-ext@sac.sfbay.sun.com;
 Mon, 17 Nov 2008 10:51:44 -0800 (PST)
Received: from labnis-qfe4.SFBay.Sun.COM ([75.101.10.233])
 by fe-sfbay-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0KAH00CHKR1X4VB0@fe-sfbay-10.sun.com> for
 LSARC-ext@sac.sfbay.sun.com; Mon, 17 Nov 2008 10:51:33 -0800 (PST)
Date: Mon, 17 Nov 2008 10:51:31 -0800
From: Tom Childers <tom.childers@sun.com>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
 timeout	11/19/2008]
In-reply-to: <8785B34D-39EC-42C3-ADDC-E121089C2264@Sun.COM>
Sender: Thomas.Childers@sun.com
To: LSARC-ext@sac.sfbay.sun.com
Cc: Gilles Bellaton <Gilles.Bellaton@sun.com>,
        Barbara Kroczak <Barbara.Kroczak@sun.com>,
        Didier Simonazzi <Didier.Simonazzi@sun.com>,
        Carole Hebrard <Carole.Hebrard@sun.com>
Message-id: <DC7339B7-477D-400F-B122-18AB724E6D0B@sun.com>
MIME-version: 1.0
X-Mailer: Apple Mail (2.929.2)
Content-type: text/plain; delsp=yes; format=flowed; charset=US-ASCII
Content-transfer-encoding: 7BIT
References: <490AC47F.9040700@sun.com>
 <62CA2FFE-CAC7-4995-B711-667D89D2D412@sun.com> <4912FB8A.8070902@sun.com>
 <D0964944-3893-4661-BBA0-EECF59EF8569@sun.com> <4918A818.1020203@sun.com>
 <6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com> <491A9B6E.4070408@sun.com>
 <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM>
 <491C13E0.5010502@sun.com> <A4340510-EF2F-4736-9FAB-76B4B76CE90D@Sun.COM>
 <491C1D3F.2020405@Sun.COM> <8785B34D-39EC-42C3-ADDC-E121089C2264@Sun.COM>
Status: RO
Content-Length: 5938

Everyone,

The timer on this case expires on Wednesday.  Going through this  
discussion, I want to confirm two recommended changes, and resolve a  
naming headache they create:

1. Move the OpenDS componentry from /opt to /usr, consistent with  
OpenLDAP and other FOSS products.

2. Update the documentation to recommend installation under user and  
group "ldap", instead of "opends".

(1) needs clarification. If we follow the OpenLDAP example, then we  
will be putting executables in /usr/bin and /usr/lib/opends. This will  
cause problems in /usr/bin, since they have executables called
	backup
	status
	manage-tasks

etc.  Should the project team propose new names for the executables?   
(OpenLDAP prefixes all their executables with "oldap".)

I'm assuming that nothing needs to go into /usr/sbin, even though  
OpenLDAP puts components there.
-tdc


On Nov 14, 2008, at 1:06 AM, Ludovic Poitou wrote:

>
> On Nov 13, 2008, at 1:27 PM, Darren J Moffat wrote:
>
>> Ludovic Poitou wrote:
>>> Darren,
>>> On Nov 13, 2008, at 12:47 PM, Gilles Bellaton wrote:
>>>> I'm adding Carole and Ludo in copy as they will be able to answer  
>>>> more precisely than me
>>>> to your questions.
>>>>
>>>>> The "into OpenSolaris" and an install location of /opt/opends  
>>>>> are incompatible.  If the intention is delivery as part of  
>>>>> OpenSolaris then surely it should be installed in an integrated  
>>>>> rather than unbundled location ?
>>>> Our intention is to deliver in the non WOS of OpenSOlaris as  
>>>> described here :
>>>> http://wikihome.sfbay.sun.com/spe-re/Wiki.jsp?page=Indiana_docks
>>>> So in a way similar to netbeans and glassfish
>>
>>>> We were thinking that /opt would be the appropriate location for  
>>>> such a delivery.
>>
>> Maybe but why should OpenDS be in /opt when PSARC/2008/507 approved  
>> OpenLDAP for integration in /usr (with /usr/lib/openldap/ for the  
>> server parts) ?
>>
>> They way the binaries are integrated into the RE doc is not really  
>> an architectural issue, where it is installed is.
>>
>> This makes OpenLDAP a more "first class" citizen then OpenDS which  
>> seems a little ironic to me.
>>
>>>>> What is the SMF service FMRI and what SMF method credential does  
>>>>> it run with?
>>>> Carole, can you help me on this ?
>>> The FMRI as of today is planned as "network/ldap/opends". Feedback  
>>> and alternate suggestions are welcome. I have little experience  
>>> with the best practices for FMRI.
>>
>> svc:/network/ldap/server:opends
>>
>> This follows the same model as we use for http where ldap/server is  
>> the service the use wants and opends is the software that provides  
>> a particular instance of it.  It also follows the precedent for  
>> LDAP servers that is effectively setin PSARC/2008/507
>>
>> This allows for:
>>
>> svc:/network/ldap/server:openldap (Already defined in PSARC/2008/507)
>> svc:/network/ldap/server:sunjavaenterprisedirectoryserver :-)
>>
>>> After package installation, the Administrator must run a command  
>>> to specify the location of the Database, the user and group for  
>>> running the instance. If the user "opends" and group "opends"  
>>> exist on the system, they will be proposed by default.
>>
>> Can't we have preconfigured defaults for all of that so that all  
>> that is required is enabling the service ?  I believe that is the  
>> situation for the OpenLDAP server.
>
> In our experience, customers always have to do some initial  
> configuration before enabling the service. The mandatory setup phase  
> of OpenDS is a major added value over OpenLDAP, as it provides a  
> better simple user experience.
>
>>
>>
>> Is this project proposing to add "opends" user and group ids to the  
>> default Solaris config ?
>
> No, we're not proposing to add "opends" user and group ids.
> We plan on documenting how to run OpenDS as non root, which  
> privileges are required and suggest "opends" ids.
>
>>
>>
>> Given that PSARC/2008/507 already proposed adding "openldap" user  
>> and group but has not yet delivered I think it may be prudent to  
>> change that case and this one to use an "ldap" user and group  
>> rather than each having their own uid and gid.
>
> I would be fine with using an "ldap" user and group if it exists to  
> the default Solaris config.
> I thought that PSARC/2008/507 gave up the idea of adding a specific  
> user. If they change and deliver an "ldap" user, we will definitely  
> leverage it.
>
>
> Ludovic.
>
>
>
>> This is similar to what has already been done for web servers, all  
>> of them that we ship are defaulted to use the "webservd" user  
>> account not each having their own.
>>
>>> The SMF method credentials would then be as below :
>>> <method_credential user='opends'
>>>                                      group='opends'
>>>                                       
>>> privileges='basic,net_privaddr,sys_resource,!proc_info,! 
>>> file_link_any'
>>>                                       
>>> limit_privileges='basic,net_privaddr,sys_resource,!proc_info,! 
>>> file_link_any' />
>>
>> Looks good, modulo the above issue on the user/group names.
>>
>> -- 
>> Darren J Moffat
>
> Ludovic Poitou                                    Sun Microsystems  
> Inc.
> OpenDS Community Lead               Directory Services
> http://blogs.sun.com/Ludo/         Grenoble Engineering Center -  
> France
>
>
>
>


From Darren.Moffat@Sun.COM Mon Nov 17 11:08:56 2008
Received: from dm-sfbay-01.sfbay.sun.com (dm-sfbay-01.SFBay.Sun.COM [129.145.155.118])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAHJ8uPS018816
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 17 Nov 2008 11:08:56 -0800 (PST)
Received: from gmp-eb-inf-1.sun.com (gmp-eb-inf-1.EU.Sun.COM [192.18.6.21])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mAHJ8tKm035248
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 17 Nov 2008 11:08:56 -0800 (PST)
Received: from fe-emea-10.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id mAHJ8nAN027309
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 17 Nov 2008 19:08:50 GMT
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0KAH00501ROWI500@fe-emea-10.sun.com>
 (original mail from Darren.Moffat@Sun.COM) for LSARC-ext@sac.sfbay.sun.com;
 Mon, 17 Nov 2008 19:08:49 +0000 (GMT)
Received: from [129.156.173.21] by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0KAH003FJRU76JA0@fe-emea-10.sun.com> for
 LSARC-ext@sac.sfbay.sun.com; Mon, 17 Nov 2008 19:08:32 +0000 (GMT)
Date: Mon, 17 Nov 2008 19:08:31 +0000
From: Darren J Moffat <Darren.Moffat@Sun.COM>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
 timeout	11/19/2008]
In-reply-to: <DC7339B7-477D-400F-B122-18AB724E6D0B@sun.com>
Sender: Darren.Moffat@Sun.COM
To: Tom Childers <tom.childers@Sun.COM>
Cc: LSARC-ext@sac.sfbay.sun.com, Barbara Kroczak <Barbara.Kroczak@Sun.COM>,
        Gilles Bellaton <Gilles.Bellaton@Sun.COM>,
        Carole Hebrard <Carole.Hebrard@Sun.COM>,
        Didier Simonazzi <Didier.Simonazzi@Sun.COM>
Message-id: <4921C12F.4010601@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
References: <490AC47F.9040700@sun.com>
 <62CA2FFE-CAC7-4995-B711-667D89D2D412@sun.com> <4912FB8A.8070902@sun.com>
 <D0964944-3893-4661-BBA0-EECF59EF8569@sun.com> <4918A818.1020203@sun.com>
 <6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com> <491A9B6E.4070408@sun.com>
 <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM>
 <491C13E0.5010502@sun.com> <A4340510-EF2F-4736-9FAB-76B4B76CE90D@Sun.COM>
 <491C1D3F.2020405@Sun.COM> <8785B34D-39EC-42C3-ADDC-E121089C2264@Sun.COM>
 <DC7339B7-477D-400F-B122-18AB724E6D0B@sun.com>
User-Agent: Thunderbird 2.0.0.16 (X11/20080922)
Status: RO
Content-Length: 1153

Tom Childers wrote:
> Everyone,
> 
> The timer on this case expires on Wednesday.  Going through this  
> discussion, I want to confirm two recommended changes, and resolve a  
> naming headache they create:
> 
> 1. Move the OpenDS componentry from /opt to /usr, consistent with  
> OpenLDAP and other FOSS products.
> 
> 2. Update the documentation to recommend installation under user and  
> group "ldap", instead of "opends".
> 
> (1) needs clarification. If we follow the OpenLDAP example, then we  
> will be putting executables in /usr/bin and /usr/lib/opends. This will  
> cause problems in /usr/bin, since they have executables called
> 	backup
> 	status
> 	manage-tasks

Either put them in /usr/lib/opends/bin/

Or prefix them with opends.

Or make an opends command and put just that in /usr/bin and all the real 
commands are in /usr/lib/opends/bin/ but appear as subcommands of opends.

> etc.  Should the project team propose new names for the executables?   
> (OpenLDAP prefixes all their executables with "oldap".)

Acutally the prefix is openldap not oldap because the later can be 
confused as meaning "old ap"


-- 
Darren J Moffat

From Ludovic.Poitou@Sun.COM Mon Nov 17 11:27:18 2008
Received: from dm-sfbay-01.sfbay.sun.com (dm-sfbay-01.SFBay.Sun.COM [129.145.155.118])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAHJRIKm018952
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 17 Nov 2008 11:27:18 -0800 (PST)
Received: from gmp-eb-inf-1.sun.com (gmp-eb-inf-1.EU.Sun.COM [192.18.6.21])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mAHJRHSR048327
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 17 Nov 2008 11:27:17 -0800 (PST)
Received: from fe-emea-09.sun.com (gmp-eb-lb-2-fe2.eu.sun.com [192.18.6.11])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id mAHJRBXL029275
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 17 Nov 2008 19:27:11 GMT
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0KAH00301SIQE000@fe-emea-09.sun.com>
 (original mail from Ludovic.Poitou@Sun.COM) for LSARC-ext@sac.sfbay.sun.com;
 Mon, 17 Nov 2008 19:27:11 +0000 (GMT)
Received: from [130.129.29.185] by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0KAH0061JSP98B00@fe-emea-09.sun.com> for
 LSARC-ext@sac.sfbay.sun.com; Mon, 17 Nov 2008 19:27:11 +0000 (GMT)
Date: Mon, 17 Nov 2008 20:27:09 +0100
From: Ludovic Poitou <Ludovic.Poitou@Sun.COM>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
 timeout	11/19/2008]
In-reply-to: <4921C12F.4010601@Sun.COM>
Sender: Ludovic.Poitou@Sun.COM
To: Darren J Moffat <Darren.Moffat@Sun.COM>
Cc: Tom Childers <tom.childers@Sun.COM>, LSARC-ext@sac.sfbay.sun.com,
        Barbara Kroczak <Barbara.Kroczak@Sun.COM>,
        Gilles Bellaton <Gilles.Bellaton@Sun.COM>,
        Carole Hebrard <Carole.Hebrard@Sun.COM>,
        Didier Simonazzi <Didier.Simonazzi@Sun.COM>
Message-id: <02B37F02-3405-4C80-A3A6-4D6E07E3981E@sun.com>
MIME-version: 1.0
X-Mailer: Apple Mail (2.929.2)
Content-type: text/plain; delsp=yes; format=flowed; charset=US-ASCII
Content-transfer-encoding: 7BIT
References: <490AC47F.9040700@sun.com>
 <62CA2FFE-CAC7-4995-B711-667D89D2D412@sun.com> <4912FB8A.8070902@sun.com>
 <D0964944-3893-4661-BBA0-EECF59EF8569@sun.com> <4918A818.1020203@sun.com>
 <6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com> <491A9B6E.4070408@sun.com>
 <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM>
 <491C13E0.5010502@sun.com> <A4340510-EF2F-4736-9FAB-76B4B76CE90D@Sun.COM>
 <491C1D3F.2020405@Sun.COM> <8785B34D-39EC-42C3-ADDC-E121089C2264@Sun.COM>
 <DC7339B7-477D-400F-B122-18AB724E6D0B@sun.com> <4921C12F.4010601@Sun.COM>
Status: RO
Content-Length: 2369


On Nov 17, 2008, at 8:08 PM, Darren J Moffat wrote:

> Tom Childers wrote:
>> Everyone,
>> The timer on this case expires on Wednesday.  Going through this   
>> discussion, I want to confirm two recommended changes, and resolve  
>> a  naming headache they create:
>> 1. Move the OpenDS componentry from /opt to /usr, consistent with   
>> OpenLDAP and other FOSS products.

Ok. We will do this.

>>
>> 2. Update the documentation to recommend installation under user  
>> and  group "ldap", instead of "opends".

Ok.
Will the "ldap" user exist in OpenSolaris by default ?
If not, this case is not requesting the user and group ids to be  
created. Who will request it ?

>>
>> (1) needs clarification. If we follow the OpenLDAP example, then  
>> we  will be putting executables in /usr/bin and /usr/lib/opends.  
>> This will  cause problems in /usr/bin, since they have executables  
>> called
>> 	backup
>> 	status
>> 	manage-tasks
>
> Either put them in /usr/lib/opends/bin/
>
We will do this.

> Or prefix them with opends.

A naive question : Would it be ok to keep the bin commands as is in / 
usr/lib/opends/bin and creates links prefixed with opends in the /usr/ 
bin directory ?


Ludovic.
>
>
> Or make an opends command and put just that in /usr/bin and all the  
> real commands are in /usr/lib/opends/bin/ but appear as subcommands  
> of opends.
>
>> etc.  Should the project team propose new names for the  
>> executables?   (OpenLDAP prefixes all their executables with  
>> "oldap".)
>
> Acutally the prefix is openldap not oldap because the later can be  
> confused as meaning "old ap"
>
>
> -- 
> Darren J Moffat

Ludovic Poitou                                    Sun Microsystems Inc.
OpenDS Community Lead               Directory Services
http://blogs.sun.com/Ludo/         Grenoble Engineering Center - France





From Nicolas.Williams@sun.com Mon Nov 17 12:39:14 2008
Received: from binky.Central.Sun.COM (binky.Central.Sun.COM [129.153.128.104])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAHKdETb020369
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 17 Nov 2008 12:39:14 -0800 (PST)
Received: from binky.central.sun.com (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3) with ESMTP id mAHKcY9N118075;
	Mon, 17 Nov 2008 14:38:34 -0600 (CST)
Received: (from nw141292@localhost)
	by binky.central.sun.com (8.14.3+Sun/8.14.3/Submit) id mAHKcYC1118074;
	Mon, 17 Nov 2008 14:38:34 -0600 (CST)
X-Authentication-Warning: binky.central.sun.com: nw141292 set sender to Nicolas.Williams@sun.com using -f
Date: Mon, 17 Nov 2008 14:38:34 -0600
From: Nicolas Williams <Nicolas.Williams@sun.com>
To: Ludovic Poitou <Ludovic.Poitou@sun.com>
Cc: Darren J Moffat <Darren.Moffat@sun.com>,
        Barbara Kroczak <Barbara.Kroczak@sun.com>, LSARC-ext@sac.sfbay.sun.com,
        Gilles Bellaton <Gilles.Bellaton@sun.com>,
        Tom Childers <tom.childers@sun.com>,
        Carole Hebrard <Carole.Hebrard@sun.com>,
        Didier Simonazzi <Didier.Simonazzi@sun.com>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack timeout	11/19/2008]
Message-ID: <20081117203834.GG111792@Sun.COM>
References: <491A9B6E.4070408@sun.com> <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM> <491C13E0.5010502@sun.com> <A4340510-EF2F-4736-9FAB-76B4B76CE90D@Sun.COM> <491C1D3F.2020405@Sun.COM> <8785B34D-39EC-42C3-ADDC-E121089C2264@Sun.COM> <DC7339B7-477D-400F-B122-18AB724E6D0B@sun.com> <4921C12F.4010601@Sun.COM> <02B37F02-3405-4C80-A3A6-4D6E07E3981E@sun.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <02B37F02-3405-4C80-A3A6-4D6E07E3981E@sun.com>
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 666

On Mon, Nov 17, 2008 at 08:27:09PM +0100, Ludovic Poitou wrote:
> On Nov 17, 2008, at 8:08 PM, Darren J Moffat wrote:
> > Tom Childers wrote:
> >> 2. Update the documentation to recommend installation under user  
> >> and  group "ldap", instead of "opends".
> 
> Ok.
> Will the "ldap" user exist in OpenSolaris by default ?
> If not, this case is not requesting the user and group ids to be  
> created. Who will request it ?

Cc'ing Doug Leavitt, who did the OpenLDAP integration into SFW.

Doug,

There's been some discussion of having the user/group used by OpenLDAP
and OpenDS being shared, and that it'd be better to rename them.

What do you think?

Nico
-- 

From Nicolas.Williams@sun.com Mon Nov 17 12:39:45 2008
Received: from binky.Central.Sun.COM (binky.Central.Sun.COM [129.153.128.104])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAHKdjK7020383
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 17 Nov 2008 12:39:45 -0800 (PST)
Received: from binky.central.sun.com (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3) with ESMTP id mAHKd6CZ118082;
	Mon, 17 Nov 2008 14:39:06 -0600 (CST)
Received: (from nw141292@localhost)
	by binky.central.sun.com (8.14.3+Sun/8.14.3/Submit) id mAHKd6WQ118081;
	Mon, 17 Nov 2008 14:39:06 -0600 (CST)
X-Authentication-Warning: binky.central.sun.com: nw141292 set sender to Nicolas.Williams@sun.com using -f
Date: Mon, 17 Nov 2008 14:39:06 -0600
From: Nicolas Williams <Nicolas.Williams@sun.com>
To: Ludovic Poitou <Ludovic.Poitou@sun.com>
Cc: Darren J Moffat <Darren.Moffat@sun.com>,
        Barbara Kroczak <Barbara.Kroczak@sun.com>, LSARC-ext@sac.sfbay.sun.com,
        Gilles Bellaton <Gilles.Bellaton@sun.com>,
        Tom Childers <tom.childers@sun.com>,
        Carole Hebrard <Carole.Hebrard@sun.com>,
        Didier Simonazzi <Didier.Simonazzi@sun.com>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack timeout	11/19/2008]
Message-ID: <20081117203905.GB102926@Sun.COM>
References: <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM> <491C13E0.5010502@sun.com> <A4340510-EF2F-4736-9FAB-76B4B76CE90D@Sun.COM> <491C1D3F.2020405@Sun.COM> <8785B34D-39EC-42C3-ADDC-E121089C2264@Sun.COM> <DC7339B7-477D-400F-B122-18AB724E6D0B@sun.com> <4921C12F.4010601@Sun.COM> <02B37F02-3405-4C80-A3A6-4D6E07E3981E@sun.com> <20081117203834.GG111792@Sun.COM>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <20081117203834.GG111792@Sun.COM>
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 115

> Cc'ing Doug Leavitt, who did the OpenLDAP integration into SFW.

Argh.  Sent too soon.  I'll bounce Doug a copy.

From Nicolas.Williams@sun.com Mon Nov 17 12:42:25 2008
Received: from binky.Central.Sun.COM (binky.Central.Sun.COM [129.153.128.104])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAHKgP0R020464
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 17 Nov 2008 12:42:25 -0800 (PST)
Received: from binky.central.sun.com (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3) with ESMTP id mAHKfkh8118098;
	Mon, 17 Nov 2008 14:41:46 -0600 (CST)
Received: (from nw141292@localhost)
	by binky.central.sun.com (8.14.3+Sun/8.14.3/Submit) id mAHKfkj1118097;
	Mon, 17 Nov 2008 14:41:46 -0600 (CST)
X-Authentication-Warning: binky.central.sun.com: nw141292 set sender to Nicolas.Williams@sun.com using -f
Date: Mon, 17 Nov 2008 14:41:45 -0600
From: Nicolas Williams <Nicolas.Williams@sun.com>
To: Gilles Bellaton <Gilles.Bellaton@sun.com>
Cc: James Carlson <James.D.Carlson@sun.com>,
        Barbara Kroczak <Barbara.Kroczak@sun.com>, LSARC-ext@sac.sfbay.sun.com,
        Darren J Moffat <Darren.Moffat@sun.com>,
        Tom Childers <tom.childers@sun.com>,
        Carole Hebrard <Carole.Hebrard@sun.com>,
        Ludovic Poitou <Ludovic.Poitou@sun.com>,
        Didier Simonazzi <Didier.Simonazzi@sun.com>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack timeout	11/19/2008]
Message-ID: <20081117204145.GH111792@Sun.COM>
References: <4912FB8A.8070902@sun.com> <D0964944-3893-4661-BBA0-EECF59EF8569@sun.com> <4918A818.1020203@sun.com> <6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com> <491A9B6E.4070408@sun.com> <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM> <491C13E0.5010502@sun.com> <18716.14917.907419.605178@gargle.gargle.HOWL> <491D3678.2030908@sun.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <491D3678.2030908@sun.com>
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 466

On Fri, Nov 14, 2008 at 09:27:36AM +0100, Gilles Bellaton wrote:
> James Carlson wrote:
> >Should /usr prepare for /opt refugees as well?

For anything bundled with Solaris or to be put in OpenSolaris release
repos, IMO: yes.

> This looks a generic question to me that may need to be handled
> outside of this case.

Agreed.

> As for OpenDS, I believe we can adapt quickly and move to /usr if this
> is the direction that is chosen.

Please choose that.

Nico
-- 

From carlsonj@phorcys.east.sun.com Mon Nov 17 12:51:05 2008
Received: from phorcys.east.sun.com (phorcys.East.Sun.COM [129.148.174.143])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAHKp47C020840
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 17 Nov 2008 12:51:04 -0800 (PST)
Received: from phorcys.east.sun.com (localhost [127.0.0.1])
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id mAHKp4Rc011204;
	Mon, 17 Nov 2008 15:51:04 -0500 (EST)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3/Submit) id mAHKp3EY011201;
	Mon, 17 Nov 2008 15:51:03 -0500 (EST)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Message-ID: <18721.55607.960074.52341@gargle.gargle.HOWL>
Date: Mon, 17 Nov 2008 15:51:03 -0500
From: James Carlson <james.d.carlson@sun.com>
To: Nicolas Williams <Nicolas.Williams@sun.com>
Cc: Gilles Bellaton <Gilles.Bellaton@sun.com>,
        Barbara Kroczak <Barbara.Kroczak@sun.com>, LSARC-ext@sac.sfbay.sun.com,
        Tom Childers <tom.childers@sun.com>,
        Carole Hebrard <Carole.Hebrard@sun.com>,
        Ludovic Poitou <Ludovic.Poitou@sun.com>,
        Didier Simonazzi <Didier.Simonazzi@sun.com>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
	timeout	11/19/2008]
In-Reply-To: <20081117204145.GH111792@Sun.COM>
References: <4912FB8A.8070902@sun.com>
	<D0964944-3893-4661-BBA0-EECF59EF8569@sun.com>
	<4918A818.1020203@sun.com>
	<6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com>
	<491A9B6E.4070408@sun.com>
	<EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com>
	<491BF8BB.3050200@Sun.COM>
	<491C13E0.5010502@sun.com>
	<18716.14917.907419.605178@gargle.gargle.HOWL>
	<491D3678.2030908@sun.com>
	<20081117204145.GH111792@Sun.COM>
X-Mailer: VM 7.01 under Emacs 21.3.1
Status: RO
Content-Length: 841

Nicolas Williams writes:
> On Fri, Nov 14, 2008 at 09:27:36AM +0100, Gilles Bellaton wrote:
> > James Carlson wrote:
> > >Should /usr prepare for /opt refugees as well?
> 
> For anything bundled with Solaris or to be put in OpenSolaris release
> repos, IMO: yes.

I think I agree, but it's a precedent-setting change of policy, and
clearly worth a review.

> > This looks a generic question to me that may need to be handled
> > outside of this case.
> 
> Agreed.

Maybe ... it's a little odd to be applying new precedent without
having first adopted it.  Do we even all agree that /opt needs to be
migrated to /usr?

-- 
James Carlson, Solaris Networking              <james.d.carlson@sun.com>
Sun Microsystems / 35 Network Drive        71.232W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.496N   Fax +1 781 442 1677

From Nicolas.Williams@sun.com Mon Nov 17 13:24:33 2008
Received: from binky.Central.Sun.COM (binky.Central.Sun.COM [129.153.128.104])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAHLOWri022310
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 17 Nov 2008 13:24:32 -0800 (PST)
Received: from binky.central.sun.com (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3) with ESMTP id mAHLNqYB118140;
	Mon, 17 Nov 2008 15:23:52 -0600 (CST)
Received: (from nw141292@localhost)
	by binky.central.sun.com (8.14.3+Sun/8.14.3/Submit) id mAHLNqeM118139;
	Mon, 17 Nov 2008 15:23:52 -0600 (CST)
X-Authentication-Warning: binky.central.sun.com: nw141292 set sender to Nicolas.Williams@sun.com using -f
Date: Mon, 17 Nov 2008 15:23:52 -0600
From: Nicolas Williams <Nicolas.Williams@sun.com>
To: James Carlson <James.D.Carlson@sun.com>
Cc: Gilles Bellaton <Gilles.Bellaton@sun.com>,
        Barbara Kroczak <Barbara.Kroczak@sun.com>, LSARC-ext@sac.sfbay.sun.com,
        Tom Childers <tom.childers@sun.com>,
        Carole Hebrard <Carole.Hebrard@sun.com>,
        Ludovic Poitou <Ludovic.Poitou@sun.com>,
        Didier Simonazzi <Didier.Simonazzi@sun.com>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack timeout	11/19/2008]
Message-ID: <20081117212352.GJ111792@Sun.COM>
References: <4918A818.1020203@sun.com> <6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com> <491A9B6E.4070408@sun.com> <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM> <491C13E0.5010502@sun.com> <18716.14917.907419.605178@gargle.gargle.HOWL> <491D3678.2030908@sun.com> <20081117204145.GH111792@Sun.COM> <18721.55607.960074.52341@gargle.gargle.HOWL>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <18721.55607.960074.52341@gargle.gargle.HOWL>
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 1274

On Mon, Nov 17, 2008 at 03:51:03PM -0500, James Carlson wrote:
> Nicolas Williams writes:
> > On Fri, Nov 14, 2008 at 09:27:36AM +0100, Gilles Bellaton wrote:
> > > James Carlson wrote:
> > > >Should /usr prepare for /opt refugees as well?
> > 
> > For anything bundled with Solaris or to be put in OpenSolaris release
> > repos, IMO: yes.
> 
> I think I agree, but it's a precedent-setting change of policy, and
> clearly worth a review.

Didn't the iDS cases effectively set precedent?  If it goes into the
WOS, then it doesn't belong in /opt.  Ah!  But is OpenDS going into the
WOS?  Is there a WOS to speak of anymore?  (Yes, there is, but it's on
its last legs.)

So the arrival of IPS and the end of Nevada WOS as suck necessitates a
new precedent no?

What is "unbundled" software if it goes into a /release IPS pkg
repository?  Is a /release IPS pkg repository the new "WOS"?  If so then
no new precedent should be needed, right?

> > > This looks a generic question to me that may need to be handled
> > > outside of this case.
> > 
> > Agreed.
> 
> Maybe ... it's a little odd to be applying new precedent without
> having first adopted it.  Do we even all agree that /opt needs to be
> migrated to /usr?

But perhaps there is such precedent; see above.

Nico
-- 

From Darren.Moffat@Sun.COM Tue Nov 18 03:40:02 2008
Received: from dm-sfbay-01.sfbay.sun.com (dm-sfbay-01.SFBay.Sun.COM [129.145.155.118])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAIBe2ME022297
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 18 Nov 2008 03:40:02 -0800 (PST)
Received: from gmp-eb-inf-2.sun.com (gmp-eb-inf-2.EU.Sun.COM [192.18.6.24])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mAIBe2Zj053338
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 18 Nov 2008 03:40:02 -0800 (PST)
Received: from fe-emea-10.sun.com (gmp-eb-lb-2-fe2.eu.sun.com [192.18.6.11])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id mAIBduML003572
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 18 Nov 2008 11:39:56 GMT
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0KAI00001ZOI3200@fe-emea-10.sun.com>
 (original mail from Darren.Moffat@Sun.COM) for LSARC-ext@sac.sfbay.sun.com;
 Tue, 18 Nov 2008 11:39:56 +0000 (GMT)
Received: from [129.156.173.21] by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0KAJ007YS1Q75NE0@fe-emea-10.sun.com> for
 LSARC-ext@sac.sfbay.sun.com; Tue, 18 Nov 2008 11:39:44 +0000 (GMT)
Date: Tue, 18 Nov 2008 11:39:43 +0000
From: Darren J Moffat <Darren.Moffat@Sun.COM>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
 timeout	11/19/2008]
In-reply-to: <02B37F02-3405-4C80-A3A6-4D6E07E3981E@sun.com>
Sender: Darren.Moffat@Sun.COM
To: Ludovic Poitou <Ludovic.Poitou@Sun.COM>
Cc: Tom Childers <tom.childers@Sun.COM>, LSARC-ext@sac.sfbay.sun.com,
        Barbara Kroczak <Barbara.Kroczak@Sun.COM>,
        Gilles Bellaton <Gilles.Bellaton@Sun.COM>,
        Carole Hebrard <Carole.Hebrard@Sun.COM>,
        Didier Simonazzi <Didier.Simonazzi@Sun.COM>
Message-id: <4922A97F.6000206@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
References: <490AC47F.9040700@sun.com>
 <62CA2FFE-CAC7-4995-B711-667D89D2D412@sun.com> <4912FB8A.8070902@sun.com>
 <D0964944-3893-4661-BBA0-EECF59EF8569@sun.com> <4918A818.1020203@sun.com>
 <6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com> <491A9B6E.4070408@sun.com>
 <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM>
 <491C13E0.5010502@sun.com> <A4340510-EF2F-4736-9FAB-76B4B76CE90D@Sun.COM>
 <491C1D3F.2020405@Sun.COM> <8785B34D-39EC-42C3-ADDC-E121089C2264@Sun.COM>
 <DC7339B7-477D-400F-B122-18AB724E6D0B@sun.com> <4921C12F.4010601@Sun.COM>
 <02B37F02-3405-4C80-A3A6-4D6E07E3981E@sun.com>
User-Agent: Thunderbird 2.0.0.16 (X11/20080922)
Status: RO
Content-Length: 951

Ludovic Poitou wrote:
> 
> On Nov 17, 2008, at 8:08 PM, Darren J Moffat wrote:
> 
>> Tom Childers wrote:
>>> Everyone,
>>> The timer on this case expires on Wednesday.  Going through this  
>>> discussion, I want to confirm two recommended changes, and resolve a  
>>> naming headache they create:
>>> 1. Move the OpenDS componentry from /opt to /usr, consistent with  
>>> OpenLDAP and other FOSS products.
> 
> Ok. We will do this.
> 
>>>
>>> 2. Update the documentation to recommend installation under user and  
>>> group "ldap", instead of "opends".
> 
> Ok.
> Will the "ldap" user exist in OpenSolaris by default ?
> If not, this case is not requesting the user and group ids to be 
> created. Who will request it ?

I was requesting that this case create it AND that the OpenLDAP case be 
modified to use "ldap" user and group rather than "openldap".  The 
project team should agree on this with the OpenLDAP project team.

-- 
Darren J Moffat

From Gilles.Bellaton@Sun.COM Tue Nov 18 08:36:50 2008
Received: from dm-sfbay-01.sfbay.sun.com (dm-sfbay-01.SFBay.Sun.COM [129.145.155.118])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAIGaoaE028398
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 18 Nov 2008 08:36:50 -0800 (PST)
Received: from gmp-eb-inf-2.sun.com (gmp-eb-inf-2.EU.Sun.COM [192.18.6.24])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mAIGan7R015683
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 18 Nov 2008 08:36:50 -0800 (PST)
Received: from fe-emea-09.sun.com (gmp-eb-lb-2-fe3.eu.sun.com [192.18.6.12])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id mAIGaiQY002092
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 18 Nov 2008 16:36:44 GMT
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0KAJ00B01EB5KU00@fe-emea-09.sun.com>
 (original mail from Gilles.Bellaton@Sun.COM) for LSARC-ext@sac.sfbay.sun.com;
 Tue, 18 Nov 2008 16:36:44 +0000 (GMT)
Received: from [129.157.192.61] by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0KAJ001DPFGXVT50@fe-emea-09.sun.com> for
 LSARC-ext@sac.sfbay.sun.com; Tue, 18 Nov 2008 16:36:34 +0000 (GMT)
Date: Tue, 18 Nov 2008 17:36:33 +0100
From: Gilles Bellaton <Gilles.Bellaton@Sun.COM>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
 timeout	11/19/2008]
In-reply-to: <4921C12F.4010601@Sun.COM>
Sender: Gilles.Bellaton@Sun.COM
To: Darren J Moffat <Darren.Moffat@Sun.COM>
Cc: Tom Childers <tom.childers@Sun.COM>, LSARC-ext@sac.sfbay.sun.com,
        Barbara Kroczak <Barbara.Kroczak@Sun.COM>,
        Carole Hebrard <Carole.Hebrard@Sun.COM>,
        Didier Simonazzi <Didier.Simonazzi@Sun.COM>
Message-id: <4922EF11.8060106@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
References: <490AC47F.9040700@sun.com>
 <62CA2FFE-CAC7-4995-B711-667D89D2D412@sun.com> <4912FB8A.8070902@sun.com>
 <D0964944-3893-4661-BBA0-EECF59EF8569@sun.com> <4918A818.1020203@sun.com>
 <6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com> <491A9B6E.4070408@sun.com>
 <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM>
 <491C13E0.5010502@sun.com> <A4340510-EF2F-4736-9FAB-76B4B76CE90D@Sun.COM>
 <491C1D3F.2020405@Sun.COM> <8785B34D-39EC-42C3-ADDC-E121089C2264@Sun.COM>
 <DC7339B7-477D-400F-B122-18AB724E6D0B@sun.com> <4921C12F.4010601@Sun.COM>
User-Agent: Thunderbird 2.0.0.17 (X11/20080925)
Status: RO
Content-Length: 1538


Putting executables in /usr/bin and /usr/lib add some complexity and 
requires to rename many executables.
Since those executables are already shipped and used by opends users 
this either create compatibility

would it be acceptable to simply put everything under /usr/opends and 
ask administrator to run
the commands from /usr/opends/bin ?

Gilles



> Tom Childers wrote:
>> Everyone,
>>
>> The timer on this case expires on Wednesday.  Going through this  
>> discussion, I want to confirm two recommended changes, and resolve a  
>> naming headache they create:
>>
>> 1. Move the OpenDS componentry from /opt to /usr, consistent with  
>> OpenLDAP and other FOSS products.
>>
>> 2. Update the documentation to recommend installation under user and  
>> group "ldap", instead of "opends".
>>
>> (1) needs clarification. If we follow the OpenLDAP example, then we  
>> will be putting executables in /usr/bin and /usr/lib/opends. This 
>> will  cause problems in /usr/bin, since they have executables called
>>     backup
>>     status
>>     manage-tasks
>
> Either put them in /usr/lib/opends/bin/
>
> Or prefix them with opends.
>
> Or make an opends command and put just that in /usr/bin and all the 
> real commands are in /usr/lib/opends/bin/ but appear as subcommands of 
> opends.
>
>> etc.  Should the project team propose new names for the 
>> executables?   (OpenLDAP prefixes all their executables with "oldap".)
>
> Acutally the prefix is openldap not oldap because the later can be 
> confused as meaning "old ap"
>
>


From Jyri.Virkki@sun.com Tue Nov 18 20:34:52 2008
Received: from dm-sfbay-01.sfbay.sun.com (dm-sfbay-01.SFBay.Sun.COM [129.145.155.118])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAJ4Yq2I022668
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 18 Nov 2008 20:34:52 -0800 (PST)
Received: from brmea-mail-4.sun.com (brmea-mail-4.Sun.COM [192.18.98.36])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mAJ4YppW027797
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 18 Nov 2008 20:34:52 -0800 (PST)
Received: from dm-usca15-11.red.iplanet.com (host-185-56-18-192.iplanet.com [192.18.56.185] (may be forged))
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id mAJ4Ypwo028712;
	Wed, 19 Nov 2008 04:34:51 GMT
Received: from buye.red.iplanet.com (buye [192.18.65.224])
	by dm-usca15-11.red.iplanet.com (8.11.7p1+Sun/8.11.7/IPLANET,v1.2) with ESMTP id mAJ4Ynm05357;
	Tue, 18 Nov 2008 20:34:49 -0800 (PST)
Received: from buye.red.iplanet.com (localhost [127.0.0.1])
	by buye.red.iplanet.com (8.13.7+Sun/8.13.7) with ESMTP id mAJ4YncG013607;
	Tue, 18 Nov 2008 20:34:49 -0800 (PST)
Received: (from jyri@localhost)
	by buye.red.iplanet.com (8.13.7+Sun/8.13.7/Submit) id mAJ4YnL5013606;
	Tue, 18 Nov 2008 20:34:49 -0800 (PST)
Date: Tue, 18 Nov 2008 20:34:49 -0800
From: Jyri Virkki <Jyri.Virkki@sun.com>
To: James Carlson <James.D.Carlson@sun.com>
Cc: Nicolas Williams <Nicolas.Williams@sun.com>,
        Gilles Bellaton <Gilles.Bellaton@sun.com>,
        Barbara Kroczak <Barbara.Kroczak@sun.com>, LSARC-ext@sac.sfbay.sun.com,
        Carole Hebrard <Carole.Hebrard@sun.com>,
        Ludovic Poitou <Ludovic.Poitou@sun.com>,
        Didier Simonazzi <Didier.Simonazzi@sun.com>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack timeout 11/19/2008]
Message-ID: <20081119043449.GS29832@sun.com>
References: <4918A818.1020203@sun.com> <6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com> <491A9B6E.4070408@sun.com> <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM> <491C13E0.5010502@sun.com> <18716.14917.907419.605178@gargle.gargle.HOWL> <491D3678.2030908@sun.com> <20081117204145.GH111792@Sun.COM> <18721.55607.960074.52341@gargle.gargle.HOWL>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <18721.55607.960074.52341@gargle.gargle.HOWL>
User-Agent: Mutt/1.5.11
Status: RO
Content-Length: 981

James Carlson wrote:
>
> > > >Should /usr prepare for /opt refugees as well?
> > 
> > For anything bundled with Solaris or to be put in OpenSolaris release
> > repos, IMO: yes.
> 
> I think I agree, but it's a precedent-setting change of policy, and
> clearly worth a review.

I'm curious what is the perceived change here?

Usage of /opt and /usr is already in filesystem(5) so nothing new.

> Maybe ... it's a little odd to be applying new precedent without
> having first adopted it.  Do we even all agree that /opt needs to be
> migrated to /usr?

If some application used to be unbundled application package
(therefore, in /opt) and decides to become an integrated package it
naturally now belongs in /usr. Both are consistent with filesystem(5).

If the proposal was to do away with /opt and migrate it to /usr then
sure, that'd be quite the new precedent to discuss! I don't think that
was the case here though.


-- 
Jyri J. Virkki - jyri.virkki@sun.com - Sun Microsystems

From Jyri.Virkki@sun.com Tue Nov 18 20:40:26 2008
Received: from dm-sfbay-02.sfbay.sun.com (dm-sfbay-02.SFBay.Sun.COM [129.146.11.31])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAJ4eQQb022703
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 18 Nov 2008 20:40:26 -0800 (PST)
Received: from brmea-mail-2.sun.com (brmea-mail-2.Sun.COM [192.18.98.43])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mAJ4eQk2014596
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 18 Nov 2008 20:40:26 -0800 (PST)
Received: from dm-usca19-13.red.iplanet.com (host-179-56-18-192.iplanet.com [192.18.56.179] (may be forged))
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id mAJ4ePHe001962;
	Wed, 19 Nov 2008 04:40:25 GMT
Received: from buye.red.iplanet.com (buye [192.18.65.224])
	by dm-usca19-13.red.iplanet.com (8.11.7p1+Sun/8.11.7/IPLANET,v1.2) with ESMTP id mAJ4ePs09821;
	Tue, 18 Nov 2008 20:40:25 -0800 (PST)
Received: from buye.red.iplanet.com (localhost [127.0.0.1])
	by buye.red.iplanet.com (8.13.7+Sun/8.13.7) with ESMTP id mAJ4eODB013658;
	Tue, 18 Nov 2008 20:40:24 -0800 (PST)
Received: (from jyri@localhost)
	by buye.red.iplanet.com (8.13.7+Sun/8.13.7/Submit) id mAJ4eO1r013657;
	Tue, 18 Nov 2008 20:40:24 -0800 (PST)
Date: Tue, 18 Nov 2008 20:40:24 -0800
From: Jyri Virkki <Jyri.Virkki@sun.com>
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Tom Childers <tom.childers@sun.com>, LSARC-ext@sac.sfbay.sun.com,
        Barbara Kroczak <Barbara.Kroczak@sun.com>,
        Gilles Bellaton <Gilles.Bellaton@sun.com>,
        Carole Hebrard <Carole.Hebrard@sun.com>,
        Didier Simonazzi <Didier.Simonazzi@sun.com>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack timeout	11/19/2008]
Message-ID: <20081119044024.GT29832@sun.com>
References: <6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com> <491A9B6E.4070408@sun.com> <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM> <491C13E0.5010502@sun.com> <A4340510-EF2F-4736-9FAB-76B4B76CE90D@Sun.COM> <491C1D3F.2020405@Sun.COM> <8785B34D-39EC-42C3-ADDC-E121089C2264@Sun.COM> <DC7339B7-477D-400F-B122-18AB724E6D0B@sun.com> <4921C12F.4010601@Sun.COM>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <4921C12F.4010601@Sun.COM>
User-Agent: Mutt/1.5.11
Status: RO
Content-Length: 767

Darren J Moffat wrote:
>
> >(1) needs clarification. If we follow the OpenLDAP example, then we  
> >will be putting executables in /usr/bin and /usr/lib/opends. This will  
> >cause problems in /usr/bin, since they have executables called
> >	backup
> >	status
> >	manage-tasks
> 
> Either put them in /usr/lib/opends/bin/

That does not sounds right.  /usr/lib/*/bin?

Expecting users to add /usr/lib/... to their PATH is odd.

There are no 'bin' directories under /usr/lib/- today so this would be
a first.

# pwd  
/usr/lib
# find . -type d -name dir
# 

/usr/$application/[bin|sbin|...] is what is being commonly done today
for apps which have a lot of content which doesn't cleanly dump in
/usr/bin


-- 
Jyri J. Virkki - jyri.virkki@sun.com - Sun Microsystems

From Gilles.Bellaton@Sun.COM Wed Nov 19 00:58:34 2008
Received: from dm-sfbay-01.sfbay.sun.com (dm-sfbay-01.SFBay.Sun.COM [129.145.155.118])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAJ8wJGx005620
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 19 Nov 2008 00:58:34 -0800 (PST)
Received: from gmp-eb-inf-1.sun.com (gmp-eb-inf-1.EU.Sun.COM [192.18.6.21])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mAJ8wD7B003655
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 19 Nov 2008 00:58:14 -0800 (PST)
Received: from fe-emea-10.sun.com (gmp-eb-lb-2-fe3.eu.sun.com [192.18.6.12])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id mAJ8w8OJ024728
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 19 Nov 2008 08:58:08 GMT
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0KAK00M01OWIW300@fe-emea-10.sun.com>
 (original mail from Gilles.Bellaton@Sun.COM) for LSARC-ext@sac.sfbay.sun.com;
 Wed, 19 Nov 2008 08:58:07 +0000 (GMT)
Received: from [129.157.192.61] by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0KAK00E3OOWUYJ20@fe-emea-10.sun.com> for
 LSARC-ext@sac.sfbay.sun.com; Wed, 19 Nov 2008 08:58:07 +0000 (GMT)
Date: Wed, 19 Nov 2008 09:58:06 +0100
From: Gilles Bellaton <Gilles.Bellaton@Sun.COM>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
 timeout 11/19/2008]
In-reply-to: <20081119043449.GS29832@sun.com>
Sender: Gilles.Bellaton@Sun.COM
To: LSARC-ext@sac.sfbay.sun.com, Tom Childers <tom.childers@Sun.COM>
Cc: Jyri Virkki <Jyri.Virkki@Sun.COM>, James Carlson <James.D.Carlson@Sun.COM>,
        Nicolas Williams <Nicolas.Williams@Sun.COM>,
        Barbara Kroczak <Barbara.Kroczak@Sun.COM>,
        Carole Hebrard <Carole.Hebrard@Sun.COM>,
        Ludovic Poitou <Ludovic.Poitou@Sun.COM>,
        Didier Simonazzi <Didier.Simonazzi@Sun.COM>,
        Darren J Moffat <Darren.Moffat@Sun.COM>
Message-id: <4923D51E.6050604@sun.com>
MIME-version: 1.0
Content-type: multipart/mixed; boundary="Boundary_(ID_Gz5mjL9vVEzm7XK8KguY7g)"
References: <4918A818.1020203@sun.com>
 <6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com> <491A9B6E.4070408@sun.com>
 <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM>
 <491C13E0.5010502@sun.com> <18716.14917.907419.605178@gargle.gargle.HOWL>
 <491D3678.2030908@sun.com> <20081117204145.GH111792@Sun.COM>
 <18721.55607.960074.52341@gargle.gargle.HOWL> <20081119043449.GS29832@sun.com>
User-Agent: Thunderbird 2.0.0.17 (X11/20080925)
Status: RO
Content-Length: 35967

This is a multi-part message in MIME format.

--Boundary_(ID_Gz5mjL9vVEzm7XK8KguY7g)
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT

Hi all,

Please find a new proposal for OpenDS Integration into OpenSolaris 
integrating
(I hope) most of the comments.

- OpenDS now install in /usr
- OpenDS now delivers SMF manifest
- OpenDS now use ldap user
- OpenDS delivers schema files used by OpenSolaris Naming services.


Gilles

--Boundary_(ID_Gz5mjL9vVEzm7XK8KguY7g)
Content-type: text/plain; name=openDSOpenSolaris2.txt
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=openDSOpenSolaris2.txt

Template Version: @(#)onepager.txt 1.31 07/08/08 SMI

This information is Copyright 2007 Sun Microsystems

1. Introduction
   1.1. Project/Component Working Name:
        OpenDS Integration in OpenSolaris

   1.2. Name of Document Author/Supplier:
        Gilles Bellaton

   1.3. Date of This Document:
        19/11/2008

   1.4. Name of Major Document Customer(s)/Consumer(s):
        1.4.1. OpenSolaris
        1.4.2. LSARC

   1.5. Email Aliases:
        1.5.2. Responsible Engineer: Gilles.Bellaton@sun.com
        1.5.4. Interest List: opends-opensolaris@sun.com

2. Project Summary
   2.1. Project Description:

        OpenDS is an open source project led by Sun Microsystems,
        building a comprehensive and complete LDAPv3 based
        Directory Service. The project web site is www.opends.org
        and the developer's section hosted on opends.dev.java.net.

        The goal of this project is to integrate the current OpenDS
        technology in the OpenSolaris repository for Unbundled product.
        OpenDS will be integrated as a Binary product. The sources
        will not be bundled as they are already maintained by a 
        separate community.
        The goal of this integration is to provide to OpenSolaris 
        users the possibility to easily install and run OpenDS.
        This should increase adoption of both OpenDS and OpenSolaris.
        The current plan is to have integrate OpenDS 1.2 in OpenSolaris.

   2.2. Risks and Assumptions:
        No known risks at this point.

3. Business Summary
   3.1. Problem Area:
        OpenSolaris needs a high performance, easy to use 
        Directory Server for Naming Services and other applications.
        OpenSolaris users have to go to OpenDS pages and manually
        install OpenDS zip packages in order to benefit from
        OpenDS technology. 
        This project will help user desiring to use both OpenSolaris
        and OpenDS by providing a coherent packaging and a common
        repository.

   3.2. Market/Requester:
        All users using both OpenSolaris and a Directory Server.

   3.3. Business Justification:
        Increase adoption of both OpenDS and OpenSolaris

   3.4. Competitive Analysis:
        OpenLDAP is already integrated in OpenSolaris.
        OpenDS will provide an alternate LDAPv3 compliant directory server,
        that is easier to use and manage and will offer smooth migration
        for those familiar with the Sun Directory Server Enterprise Edition.
        OpenDS will also integrate in other Operating Systems.

   3.5. Opportunity Window/Exposure:
        OpenDS is ready to be integrated.

   3.6. How will you know when you are done?:
        When SVR4/IPS packages for OpenSolaris are available.

4. Technical Description:
    4.1. Details:
            Develop SVR4/IPS packages for OpenSolaris

    4.2. Bug/RFE Number(s):
         None.

    4.3. In Scope:
         This project will only integrate OpenDS server side.

    4.4. Out of Scope:
         Since OpenSolaris already has a number of LDAP libraries
         and command lines, OpenDS LDAP commands and libraries will
         not be provided in the OpenSolaris 

    4.5. Interfaces:

         OpenDS main interface is LDAPv3 and is defined by a set of
         well known RFCs in the LDAP community.

         OpenDS also provides a set of admin interfaces that will
         not be changed by this project :

        /usr/opends                                  Volatile
        /usr/opends/upgrade                          Uncommitted
        /usr/opends/bin                              Uncommitted
        /usr/opends/bin/dsreplication                Uncommitted
        /usr/opends/bin/control-panel                Uncommitted
        /usr/opends/bin/dsconfig                     Uncommitted
        /usr/opends/bin/ldif-diff                    Uncommitted
        /usr/opends/bin/verify-index                 Uncommitted
        /usr/opends/bin/dbtest                       Uncommitted
        /usr/opends/bin/encode-password              Uncommitted
        /usr/opends/bin/base64                       Uncommitted
        /usr/opends/bin/rebuild-index                Uncommitted
        /usr/opends/bin/restore                      Uncommitted
        /usr/opends/bin/ldifmodify                   Uncommitted
        /usr/opends/bin/ldappasswordmodify           Uncommitted
        /usr/opends/bin/start-ds                     Uncommitted
        /usr/opends/bin/dsframework                  Uncommitted
        /usr/opends/bin/list-backends                Uncommitted
        /usr/opends/bin/manage-account               Uncommitted
        /usr/opends/bin/manage-tasks                 Uncommitted
        /usr/opends/bin/dsjavaproperties             Uncommitted
        /usr/opends/bin/export-ldif                  Uncommitted
        /usr/opends/bin/make-ldif                    Uncommitted
        /usr/opends/bin/create-rc-script             Uncommitted
        /usr/opends/bin/status                       Uncommitted
        /usr/opends/bin/ldifsearch                   Uncommitted
        /usr/opends/bin/status-panel                 Uncommitted
        /usr/opends/bin/import-ldif                  Uncommitted
        /usr/opends/bin/backup                       Uncommitted
        /usr/opends/bin/stop-ds                      Uncommitted
        /usr/opends/setup                            Uncommitted
        /usr/opends/configure                        Uncommitted
        /usr/opends/config                           Uncommitted
        /usr/opends/config/schema                    Uncommitted
        /usr/opends/config/schema/03-rfc3712.ldif    Uncommitted
        /usr/opends/config/schema/03-rfc2713.ldif    Uncommitted
        /usr/opends/config/schema/01-pwpolicy.ldif   Uncommitted
        /usr/opends/config/schema/03-uddiv3.ldif     Uncommitted
        /usr/opends/config/schema/03-rfc3112.ldif    Uncommitted
        /usr/opends/config/schema/04-rfc2307bis.ldif Uncommitted
        /usr/opends/config/schema/02-config.ldif     Uncommitted
        /usr/opends/config/schema/03-rfc2739.ldif    Uncommitted
        /usr/opends/config/schema/00-core.ldif       Uncommitted
        /usr/opends/config/schema/03-rfc2714.ldif    Uncommitted
        /usr/opends/config/schema/03-changelog.ldif  Uncommitted
        /usr/opends/config/schema/03-rfc2926.ldif    Uncommitted
        /usr/opends/config/schema/04-rfc4876.ldif    Uncommitted
        /usr/opends/config/schema/04-solaris.ldif    Uncommitted
        /var/opends                              Volatile
        /var/opends/bak                          Uncommitted
        /var/opends/changelogDb                  Uncommitted
        /var/opends/classes                      Uncommitted
        /var/opends/config                       Uncommitted
        /var/opends/config/MakeLDIF              Uncommitted
        /var/opends/config/messages              Uncommitted
        /var/opends/config/schema                Uncommitted
        /var/opends/config/servicetag            Uncommitted
        /var/opends/config/snmp                  Uncommitted
        /var/opends/config/snmp/security         Uncommitted
        /var/opends/config/upgrade               Uncommitted
        /var/opends/db                           Uncommitted
        /var/opends/import-tmp                   Uncommitted
        /var/opends/ldif                         Uncommitted
        /var/opends/lib                          Uncommitted
        /var/opends/lib/extensions               Uncommitted
        /var/opends/locks                        Uncommitted
        /var/opends/logs                         Uncommitted
        /var/opends/config/buildinfo             Uncommitted
        /var/opends/config/config.ldif           Uncommitted
        /var/opends/config/java.properties       Uncommitted
        /var/opends/config/MakeLDIF/cities                              Uncommitted
        /var/opends/config/MakeLDIF/example.template                    Uncommitted
        /var/opends/config/MakeLDIF/first.names                         Uncommitted
        /var/opends/config/MakeLDIF/last.names                          Uncommitted
        /var/opends/config/MakeLDIF/states                              Uncommitted
        /var/opends/config/MakeLDIF/streets                             Uncommitted
        /var/opends/config/messages/account-disabled.template           Uncommitted
        /var/opends/config/messages/account-enabled.template            Uncommitted
        /var/opends/config/messages/account-expired.template            Uncommitted
        /var/opends/config/messages/account-idle-locked.template        Uncommitted
        /var/opends/config/messages/account-permanently-locked.template Uncommitted
        /var/opends/config/messages/account-reset-locked.template       Uncommitted
        /var/opends/config/messages/account-temporarily-locked.template Uncommitted
        /var/opends/config/messages/account-unlocked.template           Uncommitted
        /var/opends/config/messages/password-changed.template           Uncommitted
        /var/opends/config/messages/password-expired.template           Uncommitted
        /var/opends/config/messages/password-expiring.template          Uncommitted
        /var/opends/config/messages/password-reset.template             Uncommitted
        /var/opends/config/servicetag/opends.uuids.properties           Uncommitted
        /var/opends/config/tools.properties                             Uncommitted
        /var/opends/config/upgrade/config.ldif.4535                     Uncommitted
        /var/opends/config/upgrade/schema.ldif.4535                     Uncommitted
        /var/opends/config/wordlist.txt                                 Uncommitted

        All the files and directories in /var/opends/ are created by the
        /usr/opends/configure command. /var/opends is the default path, it can
        be changed by the user at installation time.

    4.6. Doc Impact:
         OpenDS documentation is currently delivered on a wiki.
         man pages will be delivered for the main administrative interfaces
         - opends (5) overview
         - dsconfig
         - control-panel
         - dsreplication
         - configure

    4.7. Admin/Config Impact:
         A new command is being developped to create the OpenDS instance 
         after the packages have been added on the OS.

    4.8. HA Impact:
         None.

    4.9. I18N/L10N Impact:
         None. 
         OpenDS is already internationalized and localized in several languages.

    4.10. Packaging & Delivery:
         This project will deliver a new package called OpenDS whose content 
         is described below.
 
         opends package content:
         basedir: /usr
         layout:
         d none opends 0755 root sys
         d none opends/bin 0755 root sys
         d none opends/config 0755 root sys
         d none opends/config/schema 0755 root sys
         d none opends/legal-notices 0755 root sys
         d none opends/lib 0755 root sys
         d none opends/lib/extensions 0755 root sys
         d none opends/tmpl_instance 0755 root sys
         d none opends/tmpl_instance/bak 0755 root sys
         d none opends/tmpl_instance/changelogDb 0755 root sys
         d none opends/tmpl_instance/classes 0755 root sys
         d none opends/tmpl_instance/config 0755 root sys
         d none opends/tmpl_instance/config/MakeLDIF 0755 root sys
         d none opends/tmpl_instance/config/messages 0755 root sys
         d none opends/tmpl_instance/config/schema 0755 root sys
         d none opends/tmpl_instance/config/servicetag 0755 root sys
         d none opends/tmpl_instance/config/snmp 0755 root sys
         d none opends/tmpl_instance/config/snmp/security 0755 root sys
         d none opends/tmpl_instance/config/upgrade 0755 root sys
         d none opends/tmpl_instance/db 0755 root sys
         d none opends/tmpl_instance/import-tmp 0755 root sys
         d none opends/tmpl_instance/ldif 0755 root sys
         d none opends/tmpl_instance/lib 0755 root sys
         d none opends/tmpl_instance/lib/extensions 0755 root sys
         d none opends/tmpl_instance/locks 0755 root sys
         d none opends/tmpl_instance/logs 0755 root sys
         f none opends/bin/backup 0755 root sys
         f none opends/bin/base64 0755 root sys
         f none opends/bin/control-panel 0755 root sys
         f none opends/bin/create-rc-script 0755 root sys
         f none opends/bin/dbtest 0755 root sys
         f none opends/bin/dsconfig 0755 root sys
         f none opends/bin/dsframework 0755 root sys
         f none opends/bin/dsjavaproperties 0755 root sys
         f none opends/bin/dsreplication 0755 root sys
         f none opends/bin/encode-password 0755 root sys
         f none opends/bin/export-ldif 0755 root sys
         f none opends/bin/import-ldif 0755 root sys
         f none opends/bin/ldappasswordmodify 0755 root sys
         f none opends/bin/ldif-diff 0755 root sys
         f none opends/bin/ldifmodify 0755 root sys
         f none opends/bin/ldifsearch 0755 root sys
         f none opends/bin/list-backends 0755 root sys
         f none opends/bin/make-ldif 0755 root sys
         f none opends/bin/manage-account 0755 root sys
         f none opends/bin/manage-tasks 0755 root sys
         f none opends/bin/rebuild-index 0755 root sys
         f none opends/bin/restore 0755 root sys
         f none opends/bin/start-ds 0755 root sys
         f none opends/bin/status 0755 root sys
         f none opends/bin/status-panel 0755 root sys
         f none opends/bin/stop-ds 0755 root sys
         f none opends/bin/verify-index 0755 root sys
         f none opends/config/schema/00-core.ldif 0644 root sys
         f none opends/config/schema/01-pwpolicy.ldif 0644 root sys
         f none opends/config/schema/02-config.ldif 0644 root sys
         f none opends/config/schema/03-changelog.ldif 0644 root sys
         f none opends/config/schema/03-rfc2713.ldif 0644 root sys
         f none opends/config/schema/03-rfc2714.ldif 0644 root sys
         f none opends/config/schema/03-rfc2739.ldif 0644 root sys
         f none opends/config/schema/03-rfc2926.ldif 0644 root sys
         f none opends/config/schema/03-rfc3112.ldif 0644 root sys
         f none opends/config/schema/03-rfc3712.ldif 0644 root sys
         f none opends/config/schema/03-uddiv3.ldif 0644 root sys
         f none opends/config/schema/04-rfc2307bis.ldif 0644 root sys
         f none opends/config/schema/04-rfc4876.ldif 0644 root sys
         f none opends/config/schema/04-solaris.ldif 0644 root sys
         f none opends/configure 0744 root sys
         f none opends/example-plugin.zip 0644 root sys
         f none opends/install.html 0644 root sys
         f none opends/install.txt 0644 root sys
         f none opends/legal-notices/BerkeleyDB-JE.LICENSE 0644 root sys
         f none opends/legal-notices/jaf.LICENSE 0644 root sys
         f none opends/legal-notices/javamail.LICENSE 0644 root sys
         f none opends/legal-notices/OpenDS.LICENSE 0644 root sys
         f none opends/lib/_client-script.sh 0755 root sys
         f none opends/lib/_mixed-script.sh 0755 root sys
         f none opends/lib/_script-util.sh 0755 root sys
         f none opends/lib/_server-script.sh 0755 root sys
         f none opends/lib/activation.jar 0644 root sys
         f none opends/lib/je.jar 0644 root sys
         f none opends/lib/mail.jar 0644 root sys
         f none opends/lib/OpenDS.jar 0644 root sys
         f none opends/lib/quicksetup.jar 0644 root sys
         f none opends/opends_logo.png 0644 root sys
         f none opends/README 0644 root sys
         f none opends/setup 0755 root sys
         f none opends/tmpl_instance/config/admin-backend.ldif 0644 root sys
         f none opends/tmpl_instance/config/buildinfo 0644 root sys
         f none opends/tmpl_instance/config/config.ldif 0644 root sys
         f none opends/tmpl_instance/config/java.properties 0644 root sys
         f none opends/tmpl_instance/config/MakeLDIF/cities 0644 root sys
         f none opends/tmpl_instance/config/MakeLDIF/example.template 0644 root sys
         f none opends/tmpl_instance/config/MakeLDIF/first.names 0644 root sys
         f none opends/tmpl_instance/config/MakeLDIF/last.names 0644 root sys
         f none opends/tmpl_instance/config/MakeLDIF/states 0644 root sys
         f none opends/tmpl_instance/config/MakeLDIF/streets 0644 root sys
         f none opends/tmpl_instance/config/messages/account-disabled.template 0644 root sys
         f none opends/tmpl_instance/config/messages/account-enabled.template 0644 root sys
         f none opends/tmpl_instance/config/messages/account-expired.template 0644 root sys
         f none opends/tmpl_instance/config/messages/account-idle-locked.template 0644 root sys
         f none opends/tmpl_instance/config/messages/account-permanently-locked.template 0644 root sys
         f none opends/tmpl_instance/config/messages/account-reset-locked.template 0644 root sys
         f none opends/tmpl_instance/config/messages/account-temporarily-locked.template 0644 root sys
         f none opends/tmpl_instance/config/messages/account-unlocked.template 0644 root sys
         f none opends/tmpl_instance/config/messages/password-changed.template 0644 root sys
         f none opends/tmpl_instance/config/messages/password-expired.template 0644 root sys
         f none opends/tmpl_instance/config/messages/password-expiring.template 0644 root sys
         f none opends/tmpl_instance/config/messages/password-reset.template 0644 root sys
         f none opends/tmpl_instance/config/servicetag/opends.uuids.properties 0644 root sys
         f none opends/tmpl_instance/config/tools.properties 0644 root sys
         f none opends/tmpl_instance/config/upgrade/config.ldif.4535 0644 root sys
         f none opends/tmpl_instance/config/upgrade/schema.ldif.4535 0644 root sys
         f none opends/tmpl_instance/config/wordlist.txt 0644 root sys
         f none opends/upgrade 0755 root sys


     4.10.1  SMF Manifest and Runtime behavior

          This project proposes to provide a SMF manifest, disabled by
          default, for the opends server.
          Generally slapd is run as user ldap and group ldap.  The
          SMF manifest will start slapd as user ldap, group ldap using
          the privileges basic,net_privaddr.
          The FRMI will be : svc:/network/ldap/server:opends

          This project proposes to update the OpenSolaris databases to provide the
          the necessary dummy ldap user and group entries:

          Database                   Entry
          --------                   -----
          /etc/passwd                ldap:x:75:75:LDAP User:/:
          /etc/shadow                ldap:*LK*:::::::
          /etc/group			     ldap::75:

    4.10.2 Schema files for 
          
          The schema files necessary for enabling the LDAP Solaris naming 
          services will be delivered in /usr/opends/config/schema/
 

    4.11. Security Impact:
          The OpenDS components listens on the LDAP port and a port used
          for replication.
          The LDAP port is secured using the standard LDAP mechanisms (SASL,
          TLS and kerberos)
          The replication port is only accessible using SSL.
          The LDAP data are protected using the same access control model as
          the DSEE LDAP server.
    
    4.12. Dependencies:
          OpenDS requires a 1.5 Java Virtual Machine.

5. Reference Documents:
          https://www.opends.org

6. Resources and Schedule:
   6.1. Projected Availability:
        Dec 2008

   6.2. Cost of Effort:
        A few months of work.

   6.4. Product Approval Committee requested information:
        6.4.1. Consolidation or Component Name: DSEE
        6.4.7. Target RTI Date/Release:
                This project needs to be ready by Jan 2009 in order to 
                integrate Open Solaris 2009.04

   6.5. ARC review type: FastTrack
   6.6. ARC Exposure: open
       6.6.1. Rationale: Part of OpenSolaris

7. Prototype Availability:
   7.1. Prototype Availability:
        Nov 2008

   7.2. Prototype Cost:
        A few weeks.


--Boundary_(ID_Gz5mjL9vVEzm7XK8KguY7g)
Content-type: text/plain; name=diffs
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=diffs

13c13
<         27/10/2008
---
>         19/11/2008
96,188d95
<         /opt/opends                                  Volatile
<         /opt/opends/upgrade                          Uncommitted
<         /opt/opends/bin                              Uncommitted
<         /opt/opends/bin/dsreplication                Uncommitted
<         /opt/opends/bin/control-panel                Uncommitted
<         /opt/opends/bin/dsconfig                     Uncommitted
<         /opt/opends/bin/ldif-diff                    Uncommitted
<         /opt/opends/bin/verify-index                 Uncommitted
<         /opt/opends/bin/dbtest                       Uncommitted
<         /opt/opends/bin/encode-password              Uncommitted
<         /opt/opends/bin/base64                       Uncommitted
<         /opt/opends/bin/rebuild-index                Uncommitted
<         /opt/opends/bin/restore                      Uncommitted
<         /opt/opends/bin/ldifmodify                   Uncommitted
<         /opt/opends/bin/ldappasswordmodify           Uncommitted
<         /opt/opends/bin/start-ds                     Uncommitted
<         /opt/opends/bin/dsframework                  Uncommitted
<         /opt/opends/bin/list-backends                Uncommitted
<         /opt/opends/bin/manage-account               Uncommitted
<         /opt/opends/bin/manage-tasks                 Uncommitted
<         /opt/opends/bin/dsjavaproperties             Uncommitted
<         /opt/opends/bin/export-ldif                  Uncommitted
<         /opt/opends/bin/make-ldif                    Uncommitted
<         /opt/opends/bin/create-rc-script             Uncommitted
<         /opt/opends/bin/status                       Uncommitted
<         /opt/opends/bin/ldifsearch                   Uncommitted
<         /opt/opends/bin/status-panel                 Uncommitted
<         /opt/opends/bin/import-ldif                  Uncommitted
<         /opt/opends/bin/backup                       Uncommitted
<         /opt/opends/bin/stop-ds                      Uncommitted
<         /opt/opends/setup                            Uncommitted
<         /opt/opends/configure                        Uncommitted
<         /opt/opends/config                           Uncommitted
<         /opt/opends/config/schema                    Uncommitted
<         /opt/opends/config/schema/03-rfc3712.ldif    Uncommitted
<         /opt/opends/config/schema/03-rfc2713.ldif    Uncommitted
<         /opt/opends/config/schema/01-pwpolicy.ldif   Uncommitted
<         /opt/opends/config/schema/03-uddiv3.ldif     Uncommitted
<         /opt/opends/config/schema/03-rfc3112.ldif    Uncommitted
<         /opt/opends/config/schema/04-rfc2307bis.ldif Uncommitted
<         /opt/opends/config/schema/02-config.ldif     Uncommitted
<         /opt/opends/config/schema/03-rfc2739.ldif    Uncommitted
<         /opt/opends/config/schema/00-core.ldif       Uncommitted
<         /opt/opends/config/schema/03-rfc2714.ldif    Uncommitted
<         /opt/opends/config/schema/03-changelog.ldif  Uncommitted
<         /opt/opends/config/schema/03-rfc2926.ldif    Uncommitted
<         /opt/opends/config/schema/04-rfc4876.ldif    Uncommitted
<         /opt/opends/config/schema/04-solaris.ldif    Uncommitted
<         /var/opt/opends                              Volatile
<         /var/opt/opends/bak                          Uncommitted
<         /var/opt/opends/changelogDb                  Uncommitted
<         /var/opt/opends/classes                      Uncommitted
<         /var/opt/opends/config                       Uncommitted
<         /var/opt/opends/config/MakeLDIF              Uncommitted
<         /var/opt/opends/config/messages              Uncommitted
<         /var/opt/opends/config/schema                Uncommitted
<         /var/opt/opends/config/servicetag            Uncommitted
<         /var/opt/opends/config/snmp                  Uncommitted
<         /var/opt/opends/config/snmp/security         Uncommitted
<         /var/opt/opends/config/upgrade               Uncommitted
<         /var/opt/opends/db                           Uncommitted
<         /var/opt/opends/import-tmp                   Uncommitted
<         /var/opt/opends/ldif                         Uncommitted
<         /var/opt/opends/lib                          Uncommitted
<         /var/opt/opends/lib/extensions               Uncommitted
<         /var/opt/opends/locks                        Uncommitted
<         /var/opt/opends/logs                         Uncommitted
<         /var/opt/opends/config/buildinfo             Uncommitted
<         /var/opt/opends/config/config.ldif           Uncommitted
<         /var/opt/opends/config/java.properties       Uncommitted
<         /var/opt/opends/config/MakeLDIF/cities                              Uncommitted
<         /var/opt/opends/config/MakeLDIF/example.template                    Uncommitted
<         /var/opt/opends/config/MakeLDIF/first.names                         Uncommitted
<         /var/opt/opends/config/MakeLDIF/last.names                          Uncommitted
<         /var/opt/opends/config/MakeLDIF/states                              Uncommitted
<         /var/opt/opends/config/MakeLDIF/streets                             Uncommitted
<         /var/opt/opends/config/messages/account-disabled.template           Uncommitted
<         /var/opt/opends/config/messages/account-enabled.template            Uncommitted
<         /var/opt/opends/config/messages/account-expired.template            Uncommitted
<         /var/opt/opends/config/messages/account-idle-locked.template        Uncommitted
<         /var/opt/opends/config/messages/account-permanently-locked.template Uncommitted
<         /var/opt/opends/config/messages/account-reset-locked.template       Uncommitted
<         /var/opt/opends/config/messages/account-temporarily-locked.template Uncommitted
<         /var/opt/opends/config/messages/account-unlocked.template           Uncommitted
<         /var/opt/opends/config/messages/password-changed.template           Uncommitted
<         /var/opt/opends/config/messages/password-expired.template           Uncommitted
<         /var/opt/opends/config/messages/password-expiring.template          Uncommitted
<         /var/opt/opends/config/messages/password-reset.template             Uncommitted
<         /var/opt/opends/config/servicetag/opends.uuids.properties           Uncommitted
<         /var/opt/opends/config/tools.properties                             Uncommitted
<         /var/opt/opends/config/upgrade/config.ldif.4535                     Uncommitted
<         /var/opt/opends/config/upgrade/schema.ldif.4535                     Uncommitted
<         /var/opt/opends/config/wordlist.txt                                 Uncommitted
190,191c97,192
<         All the files and directories in /var/opt/ are created by the
<         /opt/opends/configure command. /var/opt is only the default path, this can
---
>         /usr/opends                                  Volatile
>         /usr/opends/upgrade                          Uncommitted
>         /usr/opends/bin                              Uncommitted
>         /usr/opends/bin/dsreplication                Uncommitted
>         /usr/opends/bin/control-panel                Uncommitted
>         /usr/opends/bin/dsconfig                     Uncommitted
>         /usr/opends/bin/ldif-diff                    Uncommitted
>         /usr/opends/bin/verify-index                 Uncommitted
>         /usr/opends/bin/dbtest                       Uncommitted
>         /usr/opends/bin/encode-password              Uncommitted
>         /usr/opends/bin/base64                       Uncommitted
>         /usr/opends/bin/rebuild-index                Uncommitted
>         /usr/opends/bin/restore                      Uncommitted
>         /usr/opends/bin/ldifmodify                   Uncommitted
>         /usr/opends/bin/ldappasswordmodify           Uncommitted
>         /usr/opends/bin/start-ds                     Uncommitted
>         /usr/opends/bin/dsframework                  Uncommitted
>         /usr/opends/bin/list-backends                Uncommitted
>         /usr/opends/bin/manage-account               Uncommitted
>         /usr/opends/bin/manage-tasks                 Uncommitted
>         /usr/opends/bin/dsjavaproperties             Uncommitted
>         /usr/opends/bin/export-ldif                  Uncommitted
>         /usr/opends/bin/make-ldif                    Uncommitted
>         /usr/opends/bin/create-rc-script             Uncommitted
>         /usr/opends/bin/status                       Uncommitted
>         /usr/opends/bin/ldifsearch                   Uncommitted
>         /usr/opends/bin/status-panel                 Uncommitted
>         /usr/opends/bin/import-ldif                  Uncommitted
>         /usr/opends/bin/backup                       Uncommitted
>         /usr/opends/bin/stop-ds                      Uncommitted
>         /usr/opends/setup                            Uncommitted
>         /usr/opends/configure                        Uncommitted
>         /usr/opends/config                           Uncommitted
>         /usr/opends/config/schema                    Uncommitted
>         /usr/opends/config/schema/03-rfc3712.ldif    Uncommitted
>         /usr/opends/config/schema/03-rfc2713.ldif    Uncommitted
>         /usr/opends/config/schema/01-pwpolicy.ldif   Uncommitted
>         /usr/opends/config/schema/03-uddiv3.ldif     Uncommitted
>         /usr/opends/config/schema/03-rfc3112.ldif    Uncommitted
>         /usr/opends/config/schema/04-rfc2307bis.ldif Uncommitted
>         /usr/opends/config/schema/02-config.ldif     Uncommitted
>         /usr/opends/config/schema/03-rfc2739.ldif    Uncommitted
>         /usr/opends/config/schema/00-core.ldif       Uncommitted
>         /usr/opends/config/schema/03-rfc2714.ldif    Uncommitted
>         /usr/opends/config/schema/03-changelog.ldif  Uncommitted
>         /usr/opends/config/schema/03-rfc2926.ldif    Uncommitted
>         /usr/opends/config/schema/04-rfc4876.ldif    Uncommitted
>         /usr/opends/config/schema/04-solaris.ldif    Uncommitted
>         /var/opends                              Volatile
>         /var/opends/bak                          Uncommitted
>         /var/opends/changelogDb                  Uncommitted
>         /var/opends/classes                      Uncommitted
>         /var/opends/config                       Uncommitted
>         /var/opends/config/MakeLDIF              Uncommitted
>         /var/opends/config/messages              Uncommitted
>         /var/opends/config/schema                Uncommitted
>         /var/opends/config/servicetag            Uncommitted
>         /var/opends/config/snmp                  Uncommitted
>         /var/opends/config/snmp/security         Uncommitted
>         /var/opends/config/upgrade               Uncommitted
>         /var/opends/db                           Uncommitted
>         /var/opends/import-tmp                   Uncommitted
>         /var/opends/ldif                         Uncommitted
>         /var/opends/lib                          Uncommitted
>         /var/opends/lib/extensions               Uncommitted
>         /var/opends/locks                        Uncommitted
>         /var/opends/logs                         Uncommitted
>         /var/opends/config/buildinfo             Uncommitted
>         /var/opends/config/config.ldif           Uncommitted
>         /var/opends/config/java.properties       Uncommitted
>         /var/opends/config/MakeLDIF/cities                              Uncommitted
>         /var/opends/config/MakeLDIF/example.template                    Uncommitted
>         /var/opends/config/MakeLDIF/first.names                         Uncommitted
>         /var/opends/config/MakeLDIF/last.names                          Uncommitted
>         /var/opends/config/MakeLDIF/states                              Uncommitted
>         /var/opends/config/MakeLDIF/streets                             Uncommitted
>         /var/opends/config/messages/account-disabled.template           Uncommitted
>         /var/opends/config/messages/account-enabled.template            Uncommitted
>         /var/opends/config/messages/account-expired.template            Uncommitted
>         /var/opends/config/messages/account-idle-locked.template        Uncommitted
>         /var/opends/config/messages/account-permanently-locked.template Uncommitted
>         /var/opends/config/messages/account-reset-locked.template       Uncommitted
>         /var/opends/config/messages/account-temporarily-locked.template Uncommitted
>         /var/opends/config/messages/account-unlocked.template           Uncommitted
>         /var/opends/config/messages/password-changed.template           Uncommitted
>         /var/opends/config/messages/password-expired.template           Uncommitted
>         /var/opends/config/messages/password-expiring.template          Uncommitted
>         /var/opends/config/messages/password-reset.template             Uncommitted
>         /var/opends/config/servicetag/opends.uuids.properties           Uncommitted
>         /var/opends/config/tools.properties                             Uncommitted
>         /var/opends/config/upgrade/config.ldif.4535                     Uncommitted
>         /var/opends/config/upgrade/schema.ldif.4535                     Uncommitted
>         /var/opends/config/wordlist.txt                                 Uncommitted
> 
>         All the files and directories in /var/opends/ are created by the
>         /usr/opends/configure command. /var/opends is the default path, it can
219c220
<          basedir: /opt
---
>          basedir: /usr
336a338,362
> 
>      4.10.1  SMF Manifest and Runtime behavior
> 
>           This project proposes to provide a SMF manifest, disabled by
>           default, for the opends server.
>           Generally slapd is run as user ldap and group ldap.  The
>           SMF manifest will start slapd as user ldap, group ldap using
>           the privileges basic,net_privaddr.
>           The FRMI will be : svc:/network/ldap/server:opends
> 
>           This project proposes to update the OpenSolaris databases to provide the
>           the necessary dummy ldap user and group entries:
> 
>           Database                   Entry
>           --------                   -----
>           /etc/passwd                ldap:x:75:75:LDAP User:/:
>           /etc/shadow                ldap:*LK*:::::::
>           /etc/group			     ldap::75:
> 
>     4.10.2 Schema files for 
>           
>           The schema files necessary for enabling the LDAP Solaris naming 
>           services will be delivered in /usr/opends/config/schema/
>  
> 

--Boundary_(ID_Gz5mjL9vVEzm7XK8KguY7g)--

From Jyri.Virkki@sun.com Wed Nov 19 01:09:44 2008
Received: from dm-sfbay-02.sfbay.sun.com (dm-sfbay-02.SFBay.Sun.COM [129.146.11.31])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAJ99iME007195
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 19 Nov 2008 01:09:44 -0800 (PST)
Received: from brmea-mail-4.sun.com (brmea-mail-4.Sun.COM [192.18.98.36])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mAJ99h0q000491
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 19 Nov 2008 01:09:44 -0800 (PST)
Received: from dm-usca15-11.red.iplanet.com (host-185-56-18-192.iplanet.com [192.18.56.185] (may be forged))
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id mAJ99hcj024054;
	Wed, 19 Nov 2008 09:09:43 GMT
Received: from buye.red.iplanet.com (buye [192.18.65.224])
	by dm-usca15-11.red.iplanet.com (8.11.7p1+Sun/8.11.7/IPLANET,v1.2) with ESMTP id mAJ99gm14166;
	Wed, 19 Nov 2008 01:09:42 -0800 (PST)
Received: from buye.red.iplanet.com (localhost [127.0.0.1])
	by buye.red.iplanet.com (8.13.7+Sun/8.13.7) with ESMTP id mAJ99gBB020519;
	Wed, 19 Nov 2008 01:09:42 -0800 (PST)
Received: (from jyri@localhost)
	by buye.red.iplanet.com (8.13.7+Sun/8.13.7/Submit) id mAJ99g4j020518;
	Wed, 19 Nov 2008 01:09:42 -0800 (PST)
Date: Wed, 19 Nov 2008 01:09:42 -0800
From: Jyri Virkki <Jyri.Virkki@sun.com>
To: Gilles Bellaton <Gilles.Bellaton@sun.com>
Cc: LSARC-ext@sac.sfbay.sun.com, James Carlson <James.D.Carlson@sun.com>,
        Nicolas Williams <Nicolas.Williams@sun.com>,
        Barbara Kroczak <Barbara.Kroczak@sun.com>,
        Carole Hebrard <Carole.Hebrard@sun.com>,
        Ludovic Poitou <Ludovic.Poitou@sun.com>,
        Didier Simonazzi <Didier.Simonazzi@sun.com>,
        Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack timeout 11/19/2008]
Message-ID: <20081119090942.GA14324@sun.com>
References: <491A9B6E.4070408@sun.com> <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM> <491C13E0.5010502@sun.com> <18716.14917.907419.605178@gargle.gargle.HOWL> <491D3678.2030908@sun.com> <20081117204145.GH111792@Sun.COM> <18721.55607.960074.52341@gargle.gargle.HOWL> <20081119043449.GS29832@sun.com> <4923D51E.6050604@sun.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <4923D51E.6050604@sun.com>
User-Agent: Mutt/1.5.11
Status: RO
Content-Length: 1053

Gilles Bellaton wrote:
>
> 
>         /usr/opends                                  Volatile
>         /usr/opends/upgrade                          Uncommitted
>         /usr/opends/bin                              Uncommitted
[...]

Seems like a syntax error there, if you plan on moving/renaming
/usr/opends/ path at a Volatile level (pretty much any time), the path
to child directories of /usr/opends/ will change as well so can't be
Uncommitted. Either that or /usr/opends is also Uncommitted [better].

>         /var/opends                              Volatile
>         /var/opends/bak                          Uncommitted
>         /var/opends/changelogDb                  Uncommitted

Same here.


>         All the files and directories in /var/opends/ are created by the
>         /usr/opends/configure command. /var/opends is the default path, it ca
>         be changed by the user at installation time.

What does installation time mean here? When I run 'pkg install opends'?


-- 
Jyri J. Virkki - jyri.virkki@sun.com - Sun Microsystems

From Gilles.Bellaton@Sun.COM Wed Nov 19 02:11:55 2008
Received: from dm-sfbay-01.sfbay.sun.com (dm-sfbay-01.SFBay.Sun.COM [129.145.155.118])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAJABt0Z010506
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 19 Nov 2008 02:11:55 -0800 (PST)
Received: from gmp-eb-inf-1.sun.com (gmp-eb-inf-1.EU.Sun.COM [192.18.6.21])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mAJABsP8042147
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 19 Nov 2008 02:11:55 -0800 (PST)
Received: from fe-emea-09.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id mAJABn2g009951
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 19 Nov 2008 10:11:49 GMT
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0KAK00501RRIAX00@fe-emea-09.sun.com>
 (original mail from Gilles.Bellaton@Sun.COM) for LSARC-ext@sac.sfbay.sun.com;
 Wed, 19 Nov 2008 10:11:49 +0000 (GMT)
Received: from [129.157.192.61] by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0KAK004Y2SBIUA70@fe-emea-09.sun.com> for
 LSARC-ext@sac.sfbay.sun.com; Wed, 19 Nov 2008 10:11:42 +0000 (GMT)
Date: Wed, 19 Nov 2008 11:11:42 +0100
From: Gilles Bellaton <Gilles.Bellaton@Sun.COM>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
 timeout 11/19/2008]
In-reply-to: <20081119090942.GA14324@sun.com>
Sender: Gilles.Bellaton@Sun.COM
To: Jyri Virkki <Jyri.Virkki@Sun.COM>
Cc: LSARC-ext@sac.sfbay.sun.com, James Carlson <James.D.Carlson@Sun.COM>,
        Nicolas Williams <Nicolas.Williams@Sun.COM>,
        Barbara Kroczak <Barbara.Kroczak@Sun.COM>,
        Carole Hebrard <Carole.Hebrard@Sun.COM>,
        Ludovic Poitou <Ludovic.Poitou@Sun.COM>,
        Didier Simonazzi <Didier.Simonazzi@Sun.COM>,
        Darren J Moffat <Darren.Moffat@Sun.COM>
Message-id: <4923E65E.6060909@sun.com>
MIME-version: 1.0
Content-type: multipart/alternative;
 boundary="Boundary_(ID_CBATolpyaInbE43sOGwvgw)"
References: <491A9B6E.4070408@sun.com>
 <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM>
 <491C13E0.5010502@sun.com> <18716.14917.907419.605178@gargle.gargle.HOWL>
 <491D3678.2030908@sun.com> <20081117204145.GH111792@Sun.COM>
 <18721.55607.960074.52341@gargle.gargle.HOWL> <20081119043449.GS29832@sun.com>
 <4923D51E.6050604@sun.com> <20081119090942.GA14324@sun.com>
User-Agent: Thunderbird 2.0.0.17 (X11/20080925)
Status: RO
Content-Length: 4029

This is a multi-part message in MIME format.

--Boundary_(ID_CBATolpyaInbE43sOGwvgw)
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT

Jyri Virkki wrote:
> Gilles Bellaton wrote:
>   
>>         /usr/opends                                  Volatile
>>         /usr/opends/upgrade                          Uncommitted
>>         /usr/opends/bin                              Uncommitted
>>     
> [...]
>
> Seems like a syntax error there, if you plan on moving/renaming
> /usr/opends/ path at a Volatile level (pretty much any time), the path
> to child directories of /usr/opends/ will change as well so can't be
> Uncommitted. Either that or /usr/opends is also Uncommitted [better].
>
>   
>>         /var/opends                              Volatile
>>         /var/opends/bak                          Uncommitted
>>         /var/opends/changelogDb                  Uncommitted
>>     
>
> Same here.
>   

I'll change /usr/opends and /var/opends to uncommitted then.
>
>   
>>         All the files and directories in /var/opends/ are created by the
>>         /usr/opends/configure command. /var/opends is the default path, it ca
>>         be changed by the user at installation time.
>>     
>
> What does installation time mean here? When I run 'pkg install opends'?
>   
It means  : when the  configure command is run.
I'll change the whole paragraph to :

"All the files and directories in /var/opends/ are created by the
 /usr/opends/configure command. /var/opends is the default path, it can
 be changed when the administrator runs the configure command."

Gilles


>
>   


--Boundary_(ID_CBATolpyaInbE43sOGwvgw)
Content-type: text/html; charset=ISO-8859-1
Content-transfer-encoding: 7BIT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
  <meta content="text/html;charset=ISO-8859-1" http-equiv="Content-Type">
</head>
<body bgcolor="#ffffff" text="#000000">
Jyri Virkki wrote:
<blockquote cite="mid:20081119090942.GA14324@sun.com" type="cite">
  <pre wrap="">Gilles Bellaton wrote:
  </pre>
  <blockquote type="cite">
    <pre wrap="">
        /usr/opends                                  Volatile
        /usr/opends/upgrade                          Uncommitted
        /usr/opends/bin                              Uncommitted
    </pre>
  </blockquote>
  <pre wrap=""><!---->[...]

Seems like a syntax error there, if you plan on moving/renaming
/usr/opends/ path at a Volatile level (pretty much any time), the path
to child directories of /usr/opends/ will change as well so can't be
Uncommitted. Either that or /usr/opends is also Uncommitted [better].

  </pre>
  <blockquote type="cite">
    <pre wrap="">        /var/opends                              Volatile
        /var/opends/bak                          Uncommitted
        /var/opends/changelogDb                  Uncommitted
    </pre>
  </blockquote>
  <pre wrap=""><!---->
Same here.
  </pre>
</blockquote>
<br>
I'll change /usr/opends and /var/opends to uncommitted then.
<blockquote cite="mid:20081119090942.GA14324@sun.com" type="cite">
  <pre wrap="">

  </pre>
  <blockquote type="cite">
    <pre wrap="">        All the files and directories in /var/opends/ are created by the
        /usr/opends/configure command. /var/opends is the default path, it ca
        be changed by the user at installation time.
    </pre>
  </blockquote>
  <pre wrap=""><!---->
What does installation time mean here? When I run 'pkg install opends'?
  </pre>
</blockquote>
It means&nbsp; : when the&nbsp; configure command is run.<br>
I'll change the whole paragraph to :<br>
<br>
<pre wrap="">"All the files and directories in /var/opends/ are created by the
 /usr/opends/configure command. /var/opends is the default path, it can
 be changed when the administrator runs the configure command."

Gilles
</pre>
<br>
<blockquote cite="mid:20081119090942.GA14324@sun.com" type="cite">
  <pre wrap="">

  </pre>
</blockquote>
<br>
</body>
</html>

--Boundary_(ID_CBATolpyaInbE43sOGwvgw)--

From Darren.Moffat@Sun.COM Wed Nov 19 05:20:00 2008
Received: from dm-sfbay-02.sfbay.sun.com (dm-sfbay-02.SFBay.Sun.COM [129.146.11.31])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAJDK043014349
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 19 Nov 2008 05:20:00 -0800 (PST)
Received: from gmp-eb-inf-2.sun.com (gmp-eb-inf-2.EU.Sun.COM [192.18.6.24])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mAJDJxLb056047
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 19 Nov 2008 05:19:59 -0800 (PST)
Received: from fe-emea-10.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id mAJDJrUY000453
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 19 Nov 2008 13:19:53 GMT
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0KAK00B01ZD29N00@fe-emea-10.sun.com>
 (original mail from Darren.Moffat@Sun.COM) for LSARC-ext@sac.sfbay.sun.com;
 Wed, 19 Nov 2008 13:19:53 +0000 (GMT)
Received: from [129.156.173.21] by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0KAL00A92111WC20@fe-emea-10.sun.com> for
 LSARC-ext@sac.sfbay.sun.com; Wed, 19 Nov 2008 13:19:50 +0000 (GMT)
Date: Wed, 19 Nov 2008 13:19:49 +0000
From: Darren J Moffat <Darren.Moffat@Sun.COM>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
 timeout 11/19/2008]
In-reply-to: <4923D51E.6050604@sun.com>
Sender: Darren.Moffat@Sun.COM
To: Gilles Bellaton <Gilles.Bellaton@Sun.COM>
Cc: LSARC-ext@sac.sfbay.sun.com, Tom Childers <tom.childers@Sun.COM>,
        Jyri Virkki <Jyri.Virkki@Sun.COM>,
        James Carlson <James.D.Carlson@Sun.COM>,
        Nicolas Williams <Nicolas.Williams@Sun.COM>,
        Barbara Kroczak <Barbara.Kroczak@Sun.COM>,
        Carole Hebrard <Carole.Hebrard@Sun.COM>,
        Ludovic Poitou <Ludovic.Poitou@Sun.COM>,
        Didier Simonazzi <Didier.Simonazzi@Sun.COM>
Message-id: <49241275.70503@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
References: <4918A818.1020203@sun.com>
 <6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com> <491A9B6E.4070408@sun.com>
 <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM>
 <491C13E0.5010502@sun.com> <18716.14917.907419.605178@gargle.gargle.HOWL>
 <491D3678.2030908@sun.com> <20081117204145.GH111792@Sun.COM>
 <18721.55607.960074.52341@gargle.gargle.HOWL> <20081119043449.GS29832@sun.com>
 <4923D51E.6050604@sun.com>
User-Agent: Thunderbird 2.0.0.16 (X11/20080922)
Status: RO
Content-Length: 1372

Gilles Bellaton wrote:
> Hi all,
> 
> Please find a new proposal for OpenDS Integration into OpenSolaris 
> integrating
> (I hope) most of the comments.
> 
> - OpenDS now install in /usr
> - OpenDS now delivers SMF manifest
> - OpenDS now use ldap user

Why is the ldap user deliver as a locked account (*LK*) rather than an 
non login account (NP) ?  Is there never a need to run cron jobs as ldap 
user ?

It think the ldap user should also be shipped as an RBAC role (type=role 
in /etc/user_attr), like has been done for postgres and zfssnap.

Why are the schema files delivered in /usr/opends/config/schema/
rather than /usr/share/lib/ldif/ ? Are they in a format specific to 
opends ?  Does the existing kerberos.ldif file work for OpenDS ?

Why is /var/opends not delivered in a package ? I would really like it 
if the only thing that had to be done before populating the database 
with data was 'svcadm enable opends' particularly for the case where it 
is likely to be used as the namservice backend for ldap.  If the admin 
wants to put the data somewhere else or make other config changes they 
are free to do so but I'd really rather they weren't forced to do so in 
the default config if possible.  However I won't hold up this case for that.

What user id is supposed to run the opends/configure command ? ldap, 
root, something else ?

-- 
Darren J Moffat

From carlsonj@phorcys.east.sun.com Wed Nov 19 06:23:55 2008
Received: from phorcys.east.sun.com (phorcys.East.Sun.COM [129.148.174.143])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAJENsqY017590
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 19 Nov 2008 06:23:55 -0800 (PST)
Received: from phorcys.east.sun.com (localhost [127.0.0.1])
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id mAJENsVp018137;
	Wed, 19 Nov 2008 09:23:54 -0500 (EST)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3/Submit) id mAJENsnY018134;
	Wed, 19 Nov 2008 09:23:54 -0500 (EST)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Message-ID: <18724.8570.337031.725980@gargle.gargle.HOWL>
Date: Wed, 19 Nov 2008 09:23:54 -0500
From: James Carlson <james.d.carlson@sun.com>
To: Jyri Virkki <Jyri.Virkki@sun.com>
Cc: Nicolas Williams <Nicolas.Williams@sun.com>,
        Gilles Bellaton <Gilles.Bellaton@sun.com>,
        Barbara Kroczak <Barbara.Kroczak@sun.com>, LSARC-ext@sac.sfbay.sun.com,
        Carole Hebrard <Carole.Hebrard@sun.com>,
        Ludovic Poitou <Ludovic.Poitou@sun.com>,
        Didier Simonazzi <Didier.Simonazzi@sun.com>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
 timeout 11/19/2008]
In-Reply-To: <20081119043449.GS29832@sun.com>
References: <4918A818.1020203@sun.com>
	<6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com>
	<491A9B6E.4070408@sun.com>
	<EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com>
	<491BF8BB.3050200@Sun.COM>
	<491C13E0.5010502@sun.com>
	<18716.14917.907419.605178@gargle.gargle.HOWL>
	<491D3678.2030908@sun.com>
	<20081117204145.GH111792@Sun.COM>
	<18721.55607.960074.52341@gargle.gargle.HOWL>
	<20081119043449.GS29832@sun.com>
X-Mailer: VM 7.01 under Emacs 21.3.1
Status: RO
Content-Length: 1208

Jyri Virkki writes:
> James Carlson wrote:
> > I think I agree, but it's a precedent-setting change of policy, and
> > clearly worth a review.
> 
> I'm curious what is the perceived change here?

As strange as it may seem, we've used /opt for components that ship
with Solaris in the past where the intent was to allow for different
(and possibly conflicting) alternatives to be installed at the same
time.  I'd expected that OpenDS was in the same class.

The line between how things are packaged for shipping and what's
considered "bundled" in the OS can be blurry at times -- SXDE had that
in spades.

If the assertion is that it's not one of those things, and we're not
just changing how we're shipping it, but are now calling it a
"bundled" part of the OS, then I agree that the move becomes obvious.

> If the proposal was to do away with /opt and migrate it to /usr then
> sure, that'd be quite the new precedent to discuss! I don't think that
> was the case here though.

OK.

-- 
James Carlson, Solaris Networking              <james.d.carlson@sun.com>
Sun Microsystems / 35 Network Drive        71.232W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.496N   Fax +1 781 442 1677

From Gilles.Bellaton@Sun.COM Wed Nov 19 06:47:39 2008
Received: from dm-sfbay-02.sfbay.sun.com (dm-sfbay-02.SFBay.Sun.COM [129.146.11.31])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAJEld4B018115
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 19 Nov 2008 06:47:39 -0800 (PST)
Received: from gmp-eb-inf-1.sun.com (gmp-eb-inf-1.EU.Sun.COM [192.18.6.21])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mAJElcvN041311
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 19 Nov 2008 06:47:38 -0800 (PST)
Received: from fe-emea-10.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id mAJElWLf003393
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 19 Nov 2008 14:47:32 GMT
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0KAL00H012QKQ700@fe-emea-10.sun.com>
 (original mail from Gilles.Bellaton@Sun.COM) for LSARC-ext@sac.sfbay.sun.com;
 Wed, 19 Nov 2008 14:47:32 +0000 (GMT)
Received: from [129.157.192.61] by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0KAL00KLG527V240@fe-emea-10.sun.com> for
 LSARC-ext@sac.sfbay.sun.com; Wed, 19 Nov 2008 14:47:09 +0000 (GMT)
Date: Wed, 19 Nov 2008 15:46:55 +0100
From: Gilles Bellaton <Gilles.Bellaton@Sun.COM>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
 timeout 11/19/2008]
In-reply-to: <49241275.70503@Sun.COM>
Sender: Gilles.Bellaton@Sun.COM
To: Darren J Moffat <Darren.Moffat@Sun.COM>
Cc: LSARC-ext@sac.sfbay.sun.com, Tom Childers <tom.childers@Sun.COM>,
        Jyri Virkki <Jyri.Virkki@Sun.COM>,
        James Carlson <James.D.Carlson@Sun.COM>,
        Nicolas Williams <Nicolas.Williams@Sun.COM>,
        Barbara Kroczak <Barbara.Kroczak@Sun.COM>,
        Carole Hebrard <Carole.Hebrard@Sun.COM>,
        Ludovic Poitou <Ludovic.Poitou@Sun.COM>,
        Didier Simonazzi <Didier.Simonazzi@Sun.COM>
Message-id: <492426DF.9070102@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
References: <4918A818.1020203@sun.com>
 <6ABAAEBC-979D-4A80-86B8-91731365E3AC@sun.com> <491A9B6E.4070408@sun.com>
 <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM>
 <491C13E0.5010502@sun.com> <18716.14917.907419.605178@gargle.gargle.HOWL>
 <491D3678.2030908@sun.com> <20081117204145.GH111792@Sun.COM>
 <18721.55607.960074.52341@gargle.gargle.HOWL> <20081119043449.GS29832@sun.com>
 <4923D51E.6050604@sun.com> <49241275.70503@Sun.COM>
User-Agent: Thunderbird 2.0.0.17 (X11/20080925)
Status: RO
Content-Length: 2285

Darren J Moffat wrote:
> Gilles Bellaton wrote:
>> Hi all,
>>
>> Please find a new proposal for OpenDS Integration into OpenSolaris 
>> integrating
>> (I hope) most of the comments.
>>
>> - OpenDS now install in /usr
>> - OpenDS now delivers SMF manifest
>> - OpenDS now use ldap user
>
> Why is the ldap user deliver as a locked account (*LK*) rather than an 
> non login account (NP) ?  Is there never a need to run cron jobs as 
> ldap user ?
>
> It think the ldap user should also be shipped as an RBAC role 
> (type=role in /etc/user_attr), like has been done for postgres and 
> zfssnap.
I've been following what has been done for the openLDAP case.
But I agree that your propositions looks better.

>
> Why are the schema files delivered in /usr/opends/config/schema/
> rather than /usr/share/lib/ldif/ ? Are they in a format specific to 
> opends ?
Yes, those files contains information that are specific to each LDAP 
server implementation.
> Does the existing kerberos.ldif file work for OpenDS ?
This file a not a schema file directly usable by an LDAP server but is a 
LDIF file
containing modifications of the schema that can be used by command line 
tools like
ldapmodify or openldapmodify to load the schema in any LDAP server.

It does not work with OpenDS. I believe this is because it does not 
comply with the LDIF
rules.

>
> Why is /var/opends not delivered in a package ?
1- so that the files in /var/opends can be owned by the user who is 
going to run the server.
2- it looks easier to have a single package with no dependencies.
> I would really like it if the only thing that had to be done before 
> populating the database with data was 'svcadm enable opends' 
> particularly for the case where it is likely to be used as the 
> namservice backend for ldap.  If the admin wants to put the data 
> somewhere else or make other config changes they are free to do so but 
> I'd really rather they weren't forced to do so in the default config 
> if possible.  However I won't hold up this case for that.
>
> What user id is supposed to run the opends/configure command ? ldap, 
> root, something else ?

The configure command must be run by somebody with the rights to write 
into /var/
it can be root or any user which has been given this privilege.

Gilles


From Nicolas.Williams@sun.com Wed Nov 19 09:05:02 2008
Received: from binky.Central.Sun.COM (binky.Central.Sun.COM [129.153.128.104])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAJH52J1022271
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 19 Nov 2008 09:05:02 -0800 (PST)
Received: from binky.central.sun.com (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3) with ESMTP id mAJH4MqV119574;
	Wed, 19 Nov 2008 11:04:22 -0600 (CST)
Received: (from nw141292@localhost)
	by binky.central.sun.com (8.14.3+Sun/8.14.3/Submit) id mAJH4Mrw119573;
	Wed, 19 Nov 2008 11:04:22 -0600 (CST)
X-Authentication-Warning: binky.central.sun.com: nw141292 set sender to Nicolas.Williams@sun.com using -f
Date: Wed, 19 Nov 2008 11:04:21 -0600
From: Nicolas Williams <Nicolas.Williams@sun.com>
To: James Carlson <James.D.Carlson@sun.com>
Cc: Jyri Virkki <Jyri.Virkki@sun.com>,
        Gilles Bellaton <Gilles.Bellaton@sun.com>,
        Barbara Kroczak <Barbara.Kroczak@sun.com>, LSARC-ext@sac.sfbay.sun.com,
        Carole Hebrard <Carole.Hebrard@sun.com>,
        Ludovic Poitou <Ludovic.Poitou@sun.com>,
        Didier Simonazzi <Didier.Simonazzi@sun.com>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack timeout 11/19/2008]
Message-ID: <20081119170421.GM111792@Sun.COM>
References: <491A9B6E.4070408@sun.com> <EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com> <491BF8BB.3050200@Sun.COM> <491C13E0.5010502@sun.com> <18716.14917.907419.605178@gargle.gargle.HOWL> <491D3678.2030908@sun.com> <20081117204145.GH111792@Sun.COM> <18721.55607.960074.52341@gargle.gargle.HOWL> <20081119043449.GS29832@sun.com> <18724.8570.337031.725980@gargle.gargle.HOWL>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <18724.8570.337031.725980@gargle.gargle.HOWL>
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 1410

On Wed, Nov 19, 2008 at 09:23:54AM -0500, James Carlson wrote:
> Jyri Virkki writes:
> > James Carlson wrote:
> > > I think I agree, but it's a precedent-setting change of policy, and
> > > clearly worth a review.
> > 
> > I'm curious what is the perceived change here?
> 
> As strange as it may seem, we've used /opt for components that ship
> with Solaris in the past where the intent was to allow for different
> (and possibly conflicting) alternatives to be installed at the same
> time.  I'd expected that OpenDS was in the same class.
> 
> The line between how things are packaged for shipping and what's
> considered "bundled" in the OS can be blurry at times -- SXDE had that
> in spades.
> 
> If the assertion is that it's not one of those things, and we're not
> just changing how we're shipping it, but are now calling it a
> "bundled" part of the OS, then I agree that the move becomes obvious.

OK, then we're left with a marketing issue.  OpenLDAP will be in /usr
but OpenDS in /opt.  If that can confuse customers as to which we intend
to support the best (e.g., we'll keep OpenLDAP up to date but we
actually maintain and develop OpenDS, but a customer might conclude the
opposite from the filesystem locations of these things), then perhaps
the i-team should reconsider.  In any case, marketing issues as not ARC
issues, so if leaving this in /opt is allowable then I have no further
comment.

From carlsonj@phorcys.east.sun.com Wed Nov 19 09:21:06 2008
Received: from phorcys.east.sun.com (phorcys.East.Sun.COM [129.148.174.143])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAJHL5dc023046
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 19 Nov 2008 09:21:06 -0800 (PST)
Received: from phorcys.east.sun.com (localhost [127.0.0.1])
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id mAJHL5FQ019374;
	Wed, 19 Nov 2008 12:21:05 -0500 (EST)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3/Submit) id mAJHL5SU019371;
	Wed, 19 Nov 2008 12:21:05 -0500 (EST)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Message-ID: <18724.19201.429831.663993@gargle.gargle.HOWL>
Date: Wed, 19 Nov 2008 12:21:05 -0500
From: James Carlson <james.d.carlson@sun.com>
To: Nicolas Williams <Nicolas.Williams@sun.com>
Cc: Barbara Kroczak <Barbara.Kroczak@sun.com>, LSARC-ext@sac.sfbay.sun.com,
        Gilles Bellaton <Gilles.Bellaton@sun.com>,
        Carole Hebrard <Carole.Hebrard@sun.com>,
        Didier Simonazzi <Didier.Simonazzi@sun.com>,
        Ludovic Poitou <Ludovic.Poitou@sun.com>,
        Jyri Virkki <Jyri.Virkki@sun.com>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
	timeout 11/19/2008]
In-Reply-To: <20081119170421.GM111792@Sun.COM>
References: <491A9B6E.4070408@sun.com>
	<EBC6CE72-0226-4043-AF54-B19CDE4FEAD1@sun.com>
	<491BF8BB.3050200@Sun.COM>
	<491C13E0.5010502@sun.com>
	<18716.14917.907419.605178@gargle.gargle.HOWL>
	<491D3678.2030908@sun.com>
	<20081117204145.GH111792@Sun.COM>
	<18721.55607.960074.52341@gargle.gargle.HOWL>
	<20081119043449.GS29832@sun.com>
	<18724.8570.337031.725980@gargle.gargle.HOWL>
	<20081119170421.GM111792@Sun.COM>
X-Mailer: VM 7.01 under Emacs 21.3.1
Status: RO
Content-Length: 809

Nicolas Williams writes:
> OK, then we're left with a marketing issue.  OpenLDAP will be in /usr
> but OpenDS in /opt.  If that can confuse customers as to which we intend
> to support the best (e.g., we'll keep OpenLDAP up to date but we
> actually maintain and develop OpenDS, but a customer might conclude the
> opposite from the filesystem locations of these things), then perhaps
> the i-team should reconsider.  In any case, marketing issues as not ARC
> issues, so if leaving this in /opt is allowable then I have no further
> comment.

?

I was agreeing with the move to /usr.

-- 
James Carlson, Solaris Networking              <james.d.carlson@sun.com>
Sun Microsystems / 35 Network Drive        71.232W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.496N   Fax +1 781 442 1677

From Nicolas.Williams@sun.com Wed Nov 19 09:23:32 2008
Received: from binky.Central.Sun.COM (binky.Central.Sun.COM [129.153.128.104])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAJHNWEX023302
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 19 Nov 2008 09:23:32 -0800 (PST)
Received: from binky.central.sun.com (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3) with ESMTP id mAJHMqYH119600;
	Wed, 19 Nov 2008 11:22:52 -0600 (CST)
Received: (from nw141292@localhost)
	by binky.central.sun.com (8.14.3+Sun/8.14.3/Submit) id mAJHMqBP119599;
	Wed, 19 Nov 2008 11:22:52 -0600 (CST)
X-Authentication-Warning: binky.central.sun.com: nw141292 set sender to Nicolas.Williams@sun.com using -f
Date: Wed, 19 Nov 2008 11:22:52 -0600
From: Nicolas Williams <Nicolas.Williams@sun.com>
To: James Carlson <James.D.Carlson@sun.com>
Cc: Barbara Kroczak <Barbara.Kroczak@sun.com>, LSARC-ext@sac.sfbay.sun.com,
        Gilles Bellaton <Gilles.Bellaton@sun.com>,
        Carole Hebrard <Carole.Hebrard@sun.com>,
        Didier Simonazzi <Didier.Simonazzi@sun.com>,
        Ludovic Poitou <Ludovic.Poitou@sun.com>,
        Jyri Virkki <Jyri.Virkki@sun.com>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack timeout 11/19/2008]
Message-ID: <20081119172251.GO111792@Sun.COM>
References: <491BF8BB.3050200@Sun.COM> <491C13E0.5010502@sun.com> <18716.14917.907419.605178@gargle.gargle.HOWL> <491D3678.2030908@sun.com> <20081117204145.GH111792@Sun.COM> <18721.55607.960074.52341@gargle.gargle.HOWL> <20081119043449.GS29832@sun.com> <18724.8570.337031.725980@gargle.gargle.HOWL> <20081119170421.GM111792@Sun.COM> <18724.19201.429831.663993@gargle.gargle.HOWL>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <18724.19201.429831.663993@gargle.gargle.HOWL>
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 717

On Wed, Nov 19, 2008 at 12:21:05PM -0500, James Carlson wrote:
> Nicolas Williams writes:
> > OK, then we're left with a marketing issue.  OpenLDAP will be in /usr
> > but OpenDS in /opt.  If that can confuse customers as to which we intend
> > to support the best (e.g., we'll keep OpenLDAP up to date but we
> > actually maintain and develop OpenDS, but a customer might conclude the
> > opposite from the filesystem locations of these things), then perhaps
> > the i-team should reconsider.  In any case, marketing issues as not ARC
> > issues, so if leaving this in /opt is allowable then I have no further
> > comment.
> 
> ?
> 
> I was agreeing with the move to /usr.

Oh, then I'm really confused.  Pardon me.

From tom.childers@sun.com Mon Nov 24 10:21:07 2008
Received: from dm-sfbay-02.sfbay.sun.com (dm-sfbay-02.SFBay.Sun.COM [129.146.11.31])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAOIL7Nl016086
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 24 Nov 2008 10:21:07 -0800 (PST)
Received: from sca-es-mail-2.sun.com (sca-es-mail-2.Sun.COM [192.18.43.133])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mAOIL7WC014132
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 24 Nov 2008 10:21:07 -0800 (PST)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id mAOIL2Hq029992
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 24 Nov 2008 10:21:02 -0800 (PST)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0KAU00B01NS17000@fe-sfbay-10.sun.com>
 (original mail from tom.childers@sun.com) for LSARC-ext@sac.sfbay.sun.com;
 Mon, 24 Nov 2008 10:21:02 -0800 (PST)
Received: from [71.141.132.219] by fe-sfbay-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0KAU00LH5OAZZXG0@fe-sfbay-10.sun.com> for
 LSARC-ext@sac.sfbay.sun.com; Mon, 24 Nov 2008 10:20:59 -0800 (PST)
Date: Mon, 24 Nov 2008 10:20:54 -0800
From: Tom Childers <tom.childers@sun.com>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
 timeout 11/19/2008]
In-reply-to: <20081119172251.GO111792@Sun.COM>
Sender: Thomas.Childers@sun.com
To: LSARC-ext@sac.sfbay.sun.com
Cc: Barbara Kroczak <Barbara.Kroczak@sun.com>,
        Gilles Bellaton <Gilles.Bellaton@sun.com>,
        Carole Hebrard <Carole.Hebrard@sun.com>,
        Didier Simonazzi <Didier.Simonazzi@sun.com>,
        Ludovic Poitou <Ludovic.Poitou@sun.com>,
        Jyri Virkki <Jyri.Virkki@sun.com>
Message-id: <0B3B0928-CD0D-4A8A-BCC1-086B76927BF5@sun.com>
MIME-version: 1.0
X-Mailer: Apple Mail (2.929.2)
Content-type: text/plain; delsp=yes; format=flowed; charset=US-ASCII
Content-transfer-encoding: 7BIT
References: <491BF8BB.3050200@Sun.COM> <491C13E0.5010502@sun.com>
 <18716.14917.907419.605178@gargle.gargle.HOWL> <491D3678.2030908@sun.com>
 <20081117204145.GH111792@Sun.COM>
 <18721.55607.960074.52341@gargle.gargle.HOWL> <20081119043449.GS29832@sun.com>
 <18724.8570.337031.725980@gargle.gargle.HOWL>
 <20081119170421.GM111792@Sun.COM>
 <18724.19201.429831.663993@gargle.gargle.HOWL>
 <20081119172251.GO111792@Sun.COM>
Status: RO
Content-Length: 1360

It sounds like we are done with the discussion of this case.

1. the onepager has been modified to show installation into /usr/ 
opends instead of /opt

2 /usr/opends and /var/opends are uncommitted interfaces, not volatile

3.  user ldap, group ldap will be used. The user will be delivered as  
a non-login account (NP) rather than locked account (LK), and will  
have an RBAC role.

If there are no further comments, I am marking this case as approved  
at the close of business today, Pacific Time. The timer expired on the  
19th.
-tdc



On Nov 19, 2008, at 9:22 AM, Nicolas Williams wrote:

> On Wed, Nov 19, 2008 at 12:21:05PM -0500, James Carlson wrote:
>> Nicolas Williams writes:
>>> OK, then we're left with a marketing issue.  OpenLDAP will be in / 
>>> usr
>>> but OpenDS in /opt.  If that can confuse customers as to which we  
>>> intend
>>> to support the best (e.g., we'll keep OpenLDAP up to date but we
>>> actually maintain and develop OpenDS, but a customer might  
>>> conclude the
>>> opposite from the filesystem locations of these things), then  
>>> perhaps
>>> the i-team should reconsider.  In any case, marketing issues as  
>>> not ARC
>>> issues, so if leaving this in /opt is allowable then I have no  
>>> further
>>> comment.
>>
>> ?
>>
>> I was agreeing with the move to /usr.
>
> Oh, then I'm really confused.  Pardon me.


From tom.childers@sun.com Tue Nov 25 07:23:43 2008
Received: from dm-sfbay-02.sfbay.sun.com (dm-sfbay-02.SFBay.Sun.COM [129.146.11.31])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id mAPFNhAJ007658
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 25 Nov 2008 07:23:43 -0800 (PST)
Received: from sca-es-mail-1.sun.com (sca-es-mail-1.Sun.COM [192.18.43.132])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id mAPFNhQZ058520
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 25 Nov 2008 07:23:43 -0800 (PST)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id mAPFNc7B000340
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 25 Nov 2008 07:23:38 -0800 (PST)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0KAW00B01AGQEW00@fe-sfbay-10.sun.com>
 (original mail from tom.childers@sun.com) for LSARC-ext@sac.sfbay.sun.com;
 Tue, 25 Nov 2008 07:23:38 -0800 (PST)
Received: from [192.168.15.2] ([75.101.10.233])
 by fe-sfbay-10.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb
 28 2007)) with ESMTPSA id <0KAW002HHAR5RPC0@fe-sfbay-10.sun.com> for
 LSARC-ext@sac.sfbay.sun.com; Tue, 25 Nov 2008 07:23:38 -0800 (PST)
Date: Tue, 25 Nov 2008 07:23:24 -0800
From: Tom Childers <tom.childers@sun.com>
Subject: Re: OpenDS Integration into OpenSolaris [ LSARC/2008/691 FastTrack
 timeout 11/19/2008]
In-reply-to: <0B3B0928-CD0D-4A8A-BCC1-086B76927BF5@sun.com>
Sender: Thomas.Childers@sun.com
To: LSARC-ext@sac.sfbay.sun.com
Cc: Barbara Kroczak <Barbara.Kroczak@sun.com>,
        Gilles Bellaton <Gilles.Bellaton@sun.com>,
        Carole Hebrard <Carole.Hebrard@sun.com>,
        Didier Simonazzi <Didier.Simonazzi@sun.com>,
        Ludovic Poitou <Ludovic.Poitou@sun.com>
Message-id: <5A91A540-4DFE-407F-91AC-44252FB81AFE@sun.com>
MIME-version: 1.0
X-Mailer: Apple Mail (2.929.2)
Content-type: text/plain; delsp=yes; format=flowed; charset=US-ASCII
Content-transfer-encoding: 7BIT
References: <491BF8BB.3050200@Sun.COM> <491C13E0.5010502@sun.com>
 <18716.14917.907419.605178@gargle.gargle.HOWL> <491D3678.2030908@sun.com>
 <20081117204145.GH111792@Sun.COM>
 <18721.55607.960074.52341@gargle.gargle.HOWL> <20081119043449.GS29832@sun.com>
 <18724.8570.337031.725980@gargle.gargle.HOWL>
 <20081119170421.GM111792@Sun.COM>
 <18724.19201.429831.663993@gargle.gargle.HOWL>
 <20081119172251.GO111792@Sun.COM>
 <0B3B0928-CD0D-4A8A-BCC1-086B76927BF5@sun.com>
Status: RO
Content-Length: 1540

Without further discussion, this case is approved. Thanks, Gilles.
-tdc

On Nov 24, 2008, at 10:20 AM, Tom Childers wrote:

> It sounds like we are done with the discussion of this case.
>
> 1. the onepager has been modified to show installation into /usr/ 
> opends instead of /opt
>
> 2 /usr/opends and /var/opends are uncommitted interfaces, not volatile
>
> 3.  user ldap, group ldap will be used. The user will be delivered  
> as a non-login account (NP) rather than locked account (LK), and  
> will have an RBAC role.
>
> If there are no further comments, I am marking this case as approved  
> at the close of business today, Pacific Time. The timer expired on  
> the 19th.
> -tdc
>
>
>
> On Nov 19, 2008, at 9:22 AM, Nicolas Williams wrote:
>
>> On Wed, Nov 19, 2008 at 12:21:05PM -0500, James Carlson wrote:
>>> Nicolas Williams writes:
>>>> OK, then we're left with a marketing issue.  OpenLDAP will be in / 
>>>> usr
>>>> but OpenDS in /opt.  If that can confuse customers as to which we  
>>>> intend
>>>> to support the best (e.g., we'll keep OpenLDAP up to date but we
>>>> actually maintain and develop OpenDS, but a customer might  
>>>> conclude the
>>>> opposite from the filesystem locations of these things), then  
>>>> perhaps
>>>> the i-team should reconsider.  In any case, marketing issues as  
>>>> not ARC
>>>> issues, so if leaving this in /opt is allowable then I have no  
>>>> further
>>>> comment.
>>>
>>> ?
>>>
>>> I was agreeing with the move to /usr.
>>
>> Oh, then I'm really confused.  Pardon me.
>


