[Date Prev][Date Next]
[Chronological]
[Thread]
[Top]
Re: ACL processing: additive privs (using control continue)
- To: Dora Paula <deepee@gmx.net>, openldap-technical@openldap.org
- Subject: Re: ACL processing: additive privs (using control continue)
- From: devzero2000 <pinto.elia@gmail.com>
- Date: Sat, 4 Aug 2012 11:38:11 +0200
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :content-type; bh=Tdr0hLn5SD6tndWNL5HXohGw9m9WEYvynDrug9JNkiE=; b=FBwHnRVfwCzqmtFDDr4uPIRoDJEZzNAygiSr+5KND7mEIHYG/H2w7GHaXDZWy/2JMV ZgaZE2u2+PMsVnr28xyRYT4NZVp7MauW/aNTQfZTishFBktv+Bp0l2MWF3vcSlgChsbs adxABZ0WY3Z/LcDVbUcypaFBjuOK0OjxOnEKTQhFQsLgOUtwsvIwLLAeRS3t+1Z9xXgE 86JpBcYxytCcGJAjjxyYE9BMr9fw+mgtRAaAIwhJvqFwzagQKmOzntuW4qFq5MiCjQUH Oxo+BcntyEY+TYs4zdOKhknoF1piAY4/hq8PmPVqtNgZub+6yK5h+rS8sQtSWLyEZIXl Khgg==
- In-reply-to: <501CDC55.4050104@gmx.net>
- References: <501CDC55.4050104@gmx.net>
Sorry for the top posting.
Iiuc, your acl permit search ( There are any entries of question type
in term of search filter) to any authenticated user. If the user is
also member of the group grant also read privilege ( give me the
entries question type) .
Regards
2012/8/4, Dora Paula <deepee@gmx.net>:
> Hi list,
>
> just a short question about "continue" and additive privileges, given
> the following acl statement:
>
> access to dn.subtree="o=test" attrs=sn
> by users =s continue
> by group/groupOfNames/member="cn=readers,ou=groups,o=test" +r
>
> If the current user's bindDn isn't a member of the group
> "cn=readers,..." or the group's entry does not exist, the previously set
> privilege "=s" will be reset to "none"?
>
> As the slapd.access man page just gives a "silly" and an "even more
> silly" example regarding "continue" I'm not sure this is the intended
> behavior.
>
> Attached you'll find my minimalistic testbed:
> slapd.conf
> sample ldif data
> two ldapsearch commands (including their slapd.log level 128)
>
> I'm using openldap MASTER.
>
> Thank you very much.
>
> Cheers
> Dora
>
>
--
Inviato dal mio dispositivo mobile