[Date Prev][Date Next]
aci for anonymous (ITS#1508)
Full_Name: Norbert Pabis
Submission from: (NULL) (126.96.36.199)
When using ldap compiled with --enable-aci, aci's do not work for anonymous.
What I did:
As wrote in http://www.OpenLDAP.org/lists/openldap-devel/200112/msg00150.html
by Kurt D. Zeilenga we do not have to deal with ietf drafts so I did not
another dntype "public" as it was proposed in
Instead I considered empty dn as anonymous which is ok according to
The simple patch I submitted removes stopper that made aci not processed while
Right now aci: ...#access-id# corresponds to anonymous
and aci: ...#access-id#* corresponds to all users and anonymous too.
The only thing needed is to include a rule in slapd.conf
access to attr=userPassword by anonymous compare
that enables user authorization.
This is the only thing that bothers me whether this all is ok. But I hope that
someone more competent will take a look at the patch.
I did 'make test' and all gone ok, even acl test, so hopefully patch does not
spoil anything but improves aci.