From: Francis Cianfrocca Date: 2007-05-02T09:43:47+09:00 Subject: Re: ActiveLdap questions ------=_Part_125_4438070.1178066626147 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Content-Disposition: inline On 5/1/07, Kouhei Sutou wrote: > > > But Net::LDAP doesn't support START_TLS. Net::LDAP does support TLS connections (typically over port 636). It doesn't currently support the STARTTLS verb, but this is planned. I think Net::LDAP > is a low level library rather than ActiveLdap. To modify > a LDAP entry, I prefer > > someone = User.find("someone") > someone.description = "Who am I?" > someone.save That's really quite a good point. Early on in the development of Net::LDAP, I thought quite hard about how to make a far-simplified interface to directory functionality. Some of LDAP's weirdness can be wrapped up, but some of it is quite hard to do away with. In particular, I tried to solve the problem of writing LDAP filters by using a search-oriented interface. But everyone who works with LDAP seems to be quite invested in standard filters, especially Microsoft, so it seemed like a low-value effort. Does ActiveLDAP solve this problem by reading the root DSE records and guessing about things like the treebase, the supported authentication models and the schema? Or does it require configuration entries to be made somewhere in the user application? At the end of the day, I observed what people were doing with Net::LDAP, and it seems for the most part to be bind-authentication against Active Directory (and some group-membership querying). Actually maintaining directory information, as in your example, seems to be a rare use case indeed. (Most people seem to manage directory data with existing native tools and with workflow applications tied to HR and CRM apps.) I appreciate your insights, and if anyone disagrees with me, I'd very much like to hear from you. ------=_Part_125_4438070.1178066626147--