[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: Patch: ACL #access-id#<invalid-DN> granted access to everyone (ITS#2006)

Applied to HEAD.  Thanks, Kurt

At 04:17 AM 2002-08-05, h.b.furuseth@usit.uio.no wrote:
>Full_Name: Hallvard B. Furuseth
>Version: HEAD
>OS: Linux
>URL: http://folk.uio.no/hbf/OpenLDAP/acl-bad-dn.txt
>Submission from: (NULL) (
>There is a bug in OpenLDAPaci's "access-id":  If the specified DN is
>invalid so dnNormalize2() fails, everyone gets access.
>This means that e.g. "#access-id#[all]" gives public access, so it
>might be considered a feature, but I fixed it anyway:-)  I guess that
>means the change should be documented in the release notes, though.
>See also ITS#2005 (add OpenLDAPaci #public# access).