Thierry Lacoste wrote:
Hello, According to SLAPD.ACCESS(5) the access needed to the 'entry' pseudo-attribute always correspond to the access needed on the 'children' pseudo-attribute of the entry's parent. The only exception is the search operation. So what is the purpose of children? Are there examples of ACLs where the two pseudo-attributes are treated differently.
Your question makes no sense. Perhaps you can rephrase it.Note that modrdn requires quite different privileges on each of the pseudo-attributes involved.
-- -- Howard Chu CTO, Symas Corp. http://www.symas.com Director, Highland Sun http://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/