Re: newbie question - acl for write/read not delete or change

I believe this is the way it works...

Access levels can be applied to entries themselves or to the attributes
of the entries or both. If you have write access to the entry it does
not necessarily imply access to modify the attributes of the entry (the
change permission you request). Write access to the entry itself grants
you the ability to rename it, delete it, and add sub objects to it.

So with this understanding I don't know if you can have what you desire.
Because if a user can add an entry he needs write access on the parent
entry which implies that he can potentially change the parent entry?

Can anyone verify my conclusions here?


On Fri, 2005-03-18 at 14:05 -0500, Prakash Velayutham wrote:
> write gives the permission to change, isn't it?
> Prakash
>>> ray v <rayv5n@yahoo.com> 03/18/05 12:32 PM >>>
> Can openldap ACLs be set up to allow write and read
> but never change or delete?
