[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: expansion of groups/roles/subtree subjects in LDAP ACM



On Thu, Jul 05, 2001 at 12:58:23PM -0700, Kurt D. Zeilenga wrote:
> How are exceptional conditions in expanding
> groups/roles/subtrees to be handled?  In particular,
> what is the ACM behavior when the groups/roles/subtrees
> cannot be fully expanded and the requestor's DN is not
> found in the partial set of DNs?
> 
> Kurt

Well as an initial (not perfect) suggestion I would opt for
notifying via the log system that the group/role/subtree
has not been fully expanded and that access has been denied
because the DN is not in the partial set.

Ryan