14.02.2014 Views

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Regular Expression Matching<br />

The use of regular expressions in the matching pattern provides the<br />

ability to construct intelligent and extrememly powerful access<br />

control rules.<br />

Example:<br />

access to dn="cn=([^,]+),ou=ListAliases,ou=MailAliases,o=Morrison Industries,c=US"<br />

by group/groupOfUniqueNames/uniquemember="cn=$1 ListAlias,ou=ACLGroups,o=Morrison Industries,c=US" write<br />

by group/groupOfUniqueNames/uniquemember="cn=CIS Dept,ou=ACLGroups,o=Morrison Industries, c=US" write<br />

by * read<br />

The above rule grants uniquemembers of the CIS Dept object under<br />

ou=ACLGroups write access to all objects directly under<br />

ou=ListAliases. For each object under ou=ListAliases a<br />

correspondingly named object under ou=ACLGroups is used to grant<br />

per object access to an arbitrary group of uniquemembers. So a<br />

uniquemember of object cn=Staff ListAlias,ou=ACLGroups,.... would<br />

have write access to the object cn=Staff,ou=MailAliases,..... All other<br />

connections would have read access.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!