[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: Slapd Replication Problem



Brian White wrote:
I'm afraid if I do, then I'll end up changing the access permissions of those special fields to be the same as the first "catch all" ACL. I don't have the resources to re-test everything.

It semes to be working if I add the replication DN to all the ACLs, so I think I'll just stick with that.

A viable workaround is to add, as the first rule

access to *
       by dn.exact=<your replicator's DN> write
       by * break

which basically means: your replicator's DN will have write privileges; anyone else won't have any privileges, but access control checking will move to following rules instead of stopping there.

p.



Ing. Pierangelo Masarati
OpenLDAP Core Team

SysNet s.n.c.
Via Dossi, 8 - 27100 Pavia - ITALIA
http://www.sys-net.it
------------------------------------------
Office:   +39.02.23998309
Mobile:   +39.333.4963172
Email:    pierangelo.masarati@sys-net.it
------------------------------------------