Re: ACLs, groups, and regular expressions... oh my

Понедельник 10 Март 2003 22:52, Howard Chu написал:
> > You will have to explicitly list all of the groups that you
> > want to give access to. Alternately, you can create a nesting
> > group, a group whose members are all the other groups in the
> > directory. Then you'll have to use the set syntax:
> > 	access to *
> > 	  by set="[cn=metagroup,dc=example,dc=com]/member*" read
> ACL sets are explained here http://www.openldap.org/faq/data/cache/452.html
> The above ACL is probably better written as
> 	access to *
> 	  by set="[cn=metagroup,dc=example,dc=com]/member* & user" read
> Regardless, it will be fairly expensive to evaluate, as it recursively
> searches the directory to expand all of the members of the set. You're
> better off just explicitly listing your groups.
Thank You very much!
I'v solved my problem with access to passwords (userPassword, ntPassword, 
lmPassword) from group of sysAdmins, using "set" clause.
There is: 
access to attr=userPassword,ntPassword,lmPassword
	by self	write
	by cn="Manager,dn=example,dc=com"	write
	by set="[cn=Domain Admins,ou=Group,dc=example,dc=com]/memberUid & uid/user"
	by * none
It works now!
Thank You again!
Best regards. Sergios