[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: Admin roles by group membership per OU





Le 12/10/2017 à 17:32, Ervin Hegedüs a écrit :
olcAccess: {0}to attrs=userPassword,shadowLastChange by self write by anonymous auth by dn="uid=repuser,dc=core,dc=hdt,dc=hu" read by * none
olcAccess: {1}to dn.base="" by * read
olcAccess: {2}to dn.children="ou=ABC Customer,dc=core,dc=hdt,dc=hu" by self write by group.exact="cn=groupabcadmin,ou=ABC Customer,dc=core,dc=hdt,dc=hu" write by self write by anonymous auth by dn="uid=repuser,dc=mycompany,dc=hu" read
olcAccess: {3}to * by * read



What is the DN of your replication user? Here you have one in dc=core,dc=hdt,dc=hu and the other in dc=mycompany,dc=hu. Just set read right to the appropriate user


--
Clément OUDOT
Consultant en logiciels libres, Expert infrastructure et sécurité
Savoir-faire Linux
137 boulevard de Magenta - 75010 PARIS
Blog: http://sflx.ca/coudot