[Date Prev][Date Next]
[Chronological]
[Thread]
[Top]
Re: Fine grained access to attributes
- To: openldap-technical@openldap.org
- Subject: Re: Fine grained access to attributes
- From: Dieter Klünter <dieter@dkluenter.de>
- Date: Thu, 29 Sep 2016 10:18:09 +0200
- In-reply-to: <a2d-57ecba00-68b-59528980@6948193>
- Organization: AVCI
- References: <a2d-57ecba00-68b-59528980@6948193>
Am Thu, 29 Sep 2016 08:52:17 +0200
schrieb "Ralf Mattes" <rm@mh-freiburg.de>:
>
> Just a quick question: isit possible to control access to attributes
> based on an attribute tag? The idea is to hide certain attributes by
> adding a "...;x-hidden' tag.
Yes, that is possible, i.e.
access to attrs=name;x-hidden by * =cs
by dn.exact="cn=foo bar,o=example" +r
by dn.exact="cn=some one,o=example" +w
-Dieter
--
Dieter Klünter | Systemberatung
http://sys4.de
GPG Key ID: E9ED159B
53°37'09,95"N
10°08'02,42"E