[Date Prev][Date Next]
Re: aci for anonymous (ITS#1508)
This has been incorporated into HEAD.
At 01:42 AM 2001-12-28, firstname.lastname@example.org wrote:
>Full_Name: Norbert Pabis
>Submission from: (NULL) (220.127.116.11)
>When using ldap compiled with --enable-aci, aci's do not work for anonymous.
>What I did:
>As wrote in http://www.OpenLDAP.org/lists/openldap-devel/200112/msg00150.html
>by Kurt D. Zeilenga we do not have to deal with ietf drafts so I did not
>another dntype "public" as it was proposed in
>Instead I considered empty dn as anonymous which is ok according to
>The simple patch I submitted removes stopper that made aci not processed while
>Right now aci: ...#access-id# corresponds to anonymous
>and aci: ...#access-id#* corresponds to all users and anonymous too.
>The only thing needed is to include a rule in slapd.conf
>access to attr=userPassword by anonymous compare
>that enables user authorization.
>This is the only thing that bothers me whether this all is ok. But I hope that
>someone more competent will take a look at the patch.
>I did 'make test' and all gone ok, even acl test, so hopefully patch does not
>spoil anything but improves aci.