Re: memberOf search ACLs

Andrew Bartlett wrote:

The fix was to define rootdn globally (as the module operates globally),
and then to give it explicit manage access in an ACL.  eg

I didn't even know that was possible at all.

access to dn.subtree="${DOMAINDN}"
       by dn=cn=samba-admin,cn=samba manage
       by dn=cn=manager manage
       by * none

rootdn cn=Manager

Adding a rootdn to each database then quashed the warnings about 'rootdn
can always manage'.

Shall I file an ITS?

I need to investigate it a little bit more. But filing an ITS could be a starting point, as the issue could get hairy.


