14.02.2014 Views

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

A Limitation?<br />

One "limitation" of OpenLDAP is that the ACL constructs are<br />

stored in the DSA's configuration file (usually slapd.conf) and thus<br />

they can only be modified by bouncing the server.<br />

In defense of OpenLDAP's "limitation" is that a well thought out<br />

directory will require few if any adjustments to the ACL constructs.<br />

The necessity of frequent ACL changes indicates a problem with<br />

the directories structure or implementation. Constant changes will<br />

also inevitably result in granting access to inappropriate parties.<br />

Design and implement, not vice versa.<br />

If you need highly flexible and granular access control see -<br />

Access Control with ACI

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!