[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: LDAP search filter on superior/parent attribute



Howard Chu wrote:
> Roman Rybalko wrote:
>> The entry with timeInteger=1347014897 is obviously not in
>> [1348900000,1349000000] range, but it is matched because there are
>> another attributes in the entry with "SUP timeInteger", so
>> timeIntegerYear=2012 is matched the (timeInteger<=1349000000) filter part.
>>
>> I'm looking for RFC that describes such behavior.
>>
> RFC4512 section 2.5.3.

Also note that attribute type inheritance is also applied
when processing ACLs!

Ciao, Michael.

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature