[Date Prev][Date Next]
Re: access control, groups/organizationalRole
- To: firstname.lastname@example.org
- Subject: Re: access control, groups/organizationalRole
- From: Frederik Bosch <email@example.com>
- Date: Thu, 26 Aug 2010 11:22:50 +0200
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:received:message-id:date:from :user-agent:mime-version:to:subject:references:in-reply-to :content-type:content-transfer-encoding; bh=0pLa/cBRvJBlBYVop9XPNhnkqgUj5C5AXx4USVdcPs8=; b=OpvadAEBGRKFaAF+nGANk4c1KWUjzwZW2bDgsPvHo2yJlzKdZHck6JeIT6IJjHf/XP 4cKlxIpWZeMXk3x0Vd/qydijfFucwULeISTvNckRM8v8+dcr6Tu0rA4zz3IN42Pde/Ks oIizCWoNskIHQtKCAUi532fz61ueusVxLqvEY=
- Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type:content-transfer-encoding; b=Rej3WgKwbNBnJeRlrtUBsiFQ4CkAAeq7tTG7RVp4Vnt8pd5dOALEofz4E4pZqysOtV Bf8ITSZfi+NPoEkgjdW7fcujP/9HzN4IJL7y2e9oe+CRIqd2YjC41VqTlU6M2jLRmrMI T4QbWkwYK00fFz84KVnmFSvZN0fkC8GohzEeQ=
- In-reply-to: <4C762A06.firstname.lastname@example.org>
- References: <4C729BBE.email@example.com> <4C750E32.firstname.lastname@example.org> <4C762A06.email@example.com>
- User-agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; nl; rv:126.96.36.199) Gecko/20100802 Thunderbird/3.1.2
By the way. This seems to be correct syntax, but does not give me the
access to attrs=uid,userPassword
by anonymous auth
by * none
access to *
by group/organizationalRole/roleOccupant.regex=".+" read
by * none
I am able to bind, but not to read the tree.
Op 26-8-2010 10:47, Frederik Bosch schreef:
Thanks again Dieter. That looks way to difficult for me :). I changed
some things. Now suppose that I want to assign read access to every
roleOccupant in a organizationalRole.
access to * by group/organizationalRole/roleOccupant read
But that's not correct syntax. Slapd won't start. It has to be like this:
access to * by group/organizationalRole/roleOccupant="<DN>" read
What syntax do I need to let "<DN>" match the whole tree?
Thanks for the help,
Op 25-8-2010 14:36, Frederik Bosch schreef:
That's not what I mean, but thanks for your suggestion.
Let me try to rephrase. Suppose I have an organizationalRole located
in Amsterdam and Rotterdam. Now I only want to assign rights to all
occupants of the organizationalRole located in Amsterdam.
In xpath-like syntax, this would look like this.
access to * by
How do I need to rewrite this for slapd?
On 08/23/2010 06:03 PM, Frederik Bosch wrote:
I am trying to setup an access control rule, but failed. All occupants
of the objectClass organizationalRole which has a certain location may
have read access. How do I setup this rule in slapd.conf?
This is my line at the moment. This matches the dn of the occupant. But
how do I match the location attribute of the organizationalRole?
access to * by
Thanks in advance,