[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: Give user only access to a few entries that he "owns"



PenguinWhispererThe . wrote:
> Thanks for the link.  I've looked in the examples. Should expand be used to
> accomplish this then?
> 
> Note that the host is in an other tree. And the attribute that should be
> editable by the user is at the same level (sibling) as the owner (so the
> user that should be able to edit it).

That's all possible and you should find similar examples in the FAQ.
But crafting your ACLs is your homework.
And yes, it takes some time to get familiar with this.

Ciao, Michael.

> On Jun 21, 2016 7:59 AM, "Michael Ströder" <michael@stroeder.com> wrote:
> 
>> PenguinWhispererThe . wrote:
>>> I want the user to be able to update one attribute of this host.
>>> "self" keyword doesn't work here as the user doesn't bind to it.
>>> [..]
>>> Could anyone share an example?
>>
>> The FAQ-O-MATIC has many very useful examples.
>>
>> Start here: http://www.openldap.org/faq/data/cache/189.html
>>
>> Ciao, Michael.

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature