[Date Prev][Date Next]
[Chronological]
[Thread]
[Top]
Re: draft-ietf-ldapext-acl-model-04.txt
Jim,
1. I don't know why the BNF was expanded to allow a single aci to contain
multiple
acl entries. I'll check with Debbie when she's back from vacation next week.
2. Level means n levels down in a subtree. So, for example, if the
subtree is 15 levels
deep and you only want the first 4 levels, you can set the scope to level=4.
Ellen
At 05:18 PM 10/11/1999 -0600, Jim Sermersheim wrote:
>I noticed that the BNF has been expanded to allow a single aci to contain
multiple acl entries. In other words, now we can specify this:
>aci: 1.2.3.4#subtree#grant#r,w;[all]#group#cn=Dept
XYZ#1.2.3.4#entry#grant#r;attribute1#group#cn=maude
>
>The BNF is already pretty complex and this makes it more so. Is there a
compeling reason to do this?
>
>The BNF also specifies that the scope may be entry, subtree, or a level
(number). entry and subtree imply their own definition, but level doesn't
and it's not talked about anywhere. What does it mean?
>
>Jim
>