[Date Prev][Date Next]
[Chronological]
[Thread]
[Top]
Re: expansion of groups/roles/subtree subjects in LDAP ACM
On Thu, Jul 05, 2001 at 12:58:23PM -0700, Kurt D. Zeilenga wrote:
> How are exceptional conditions in expanding
> groups/roles/subtrees to be handled? In particular,
> what is the ACM behavior when the groups/roles/subtrees
> cannot be fully expanded and the requestor's DN is not
> found in the partial set of DNs?
>
> Kurt
Well as an initial (not perfect) suggestion I would opt for
notifying via the log system that the group/role/subtree
has not been fully expanded and that access has been denied
because the DN is not in the partial set.
Ryan