[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: draft-ietf-ldapext-acl-model-04.txt



Jim,

1.  I don't know why the BNF was expanded to allow a single aci to contain
multiple
acl entries.  I'll check with Debbie when she's back from vacation next week.

2.  Level means n levels down in a subtree.  So, for example, if the
subtree is 15 levels
deep and you only want the first 4 levels, you can set the scope to level=4.

Ellen


At 05:18 PM 10/11/1999 -0600, Jim Sermersheim wrote:
>I noticed that the BNF has been expanded to allow a single aci to contain
multiple acl entries.  In other words, now we can specify this:
>aci: 1.2.3.4#subtree#grant#r,w;[all]#group#cn=Dept
XYZ#1.2.3.4#entry#grant#r;attribute1#group#cn=maude
>
>The BNF is already pretty complex and this makes it more so. Is there a
compeling reason to do this?
>
>The BNF also specifies that the scope may be entry, subtree, or a level
(number).  entry and subtree imply their own definition, but level doesn't
and it's not talked about anywhere. What does it mean?
>
>Jim
>