Re: LDAP search filter on superior/parent attribute

Howard Chu wrote:
> Roman Rybalko wrote:
>> The entry with timeInteger=1347014897 is obviously not in
>> [1348900000,1349000000] range, but it is matched because there are
>> another attributes in the entry with "SUP timeInteger", so
>> timeIntegerYear=2012 is matched the (timeInteger<=1349000000) filter part.
>> I'm looking for RFC that describes such behavior.
> RFC4512 section 2.5.3.

Also note that attribute type inheritance is also applied
when processing ACLs!

Ciao, Michael.

