[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: ACLs applying to RootDSE

Matthew J. Smith wrote:

Thank you all for the replies!  I actually have been using the
dn.subtree syntax on each ACL, which works great.  Right now, I am the
only admin of this system, so this is simple.  However, as a few more
admins get involved, with their own suffixes/databases, I'd like to give
them their own db-xyz.acl file, included in slapd.conf for their
database.  I trust them to not do anything malicious on purpose -- but I
also want to safeguard against them simply reading something from
google, and implementing a "access to * by * write", for example, and
having that affect RootDSE and Schema.

This may only happen within the first database instance.

For now, I may just give them their own instances of OpenLDAP, running
on a different URI.

I think this is wise, since global config directives can still appear inside database definitions, so leaving too much freedom could result in unexpected behavior for other reasons as well.


   SysNet - via Dossi,8 27100 Pavia Tel: +390382573859 Fax: +390382476497