Issue 9552 - slapo-accesslog should record new DN after rename
Summary: slapo-accesslog should record new DN after rename
Status: VERIFIED FIXED
Alias: None
Product: OpenLDAP
Classification: Unclassified
Component: overlays (show other issues)
Version: unspecified
Hardware: All All
: --- normal
Target Milestone: 2.5.5
Assignee: OpenLDAP project
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2021-05-12 11:02 UTC by Ondřej Kuzník
Modified: 2021-06-03 22:39 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this issue.
Description Ondřej Kuzník 2021-05-12 11:02:33 UTC
To use accesslog as a sessionlog source, one needs to be able to resolve whether a modrdn moved an entry in/out of the search scope. Syncprov would either have to examine every modrdn request or, if accesslog were to log the final DN, it could check for entries which crossed the scope.

A new attribute 'reqNewDN' should be tracked for modrdn ops.
Comment 1 Ondřej Kuzník 2021-05-12 11:05:09 UTC
MR!331 https://git.openldap.org/openldap/openldap/-/merge_requests/331
Comment 2 Quanah Gibson-Mount 2021-05-13 21:38:53 UTC
  • c2edf41f 
by Ondřej Kuzník at 2021-05-13T20:14:55+00:00 
ITS#9552 Record reqNewDN for modRDNs