Re: Restricted/controlled simple bind

Hi again.

Small update...

I started fiddling around with regexp ACLs after I wrote my mail (I thought of it just as I was finishing the mail), and so far I have been able to limit access to the userPassword (and as such, simple binds) to users in ou=People who have a userPassword like regexp "{SASL}.+@REALM". However, I have yet to find a way to expand a regexp from the dn containing the uid, into the attrs regexp. My ACL looks something like this:

access to dn.regex="^uid=([^,]+),ou=People,dc=example,dc=com$"
   attrs=userPassword val.regex="{SASL}.+@EXAMPLE.COM"
       by self read
       by anonymous auth
       by * none

I have tried to use val.exact="{SASL}$1@EXAMPLE.COM" but it doesn't appear to expand the $1 from teh first dn.regex as I would like. Any ideas?


