14.02.2014 Views

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The ACL Stack<br />

Access control for objects and attributes is managed through the<br />

construction of a stack of access control lists. The first matching<br />

rule applies and subsequent rules do not apply, thus order is<br />

extremely important.<br />

Access Control List syntax:<br />

access to <br />

<br />

by < compare | search | read | write ><br />

If a dn matching pattern is not included the rule applies to the<br />

attributes listed in all the objects in the DSA not previously<br />

matched by a dn regular expression.<br />

The special attribute children grants modification privilages<br />

(create, delete) to an objects children. The special attribute entry<br />

control is used to grant privilage to modify the object itself (delete).

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!