Re: ldap basic

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Tony Heaton wrote:

access  to *
        by * read
        by dn.base="cn=Manager,dc=frop,dc=net" write
        by self write
        by anonymous auth
...
rootdn          "cn=Manager,dc=frop,dc=net"

Nitpicking: There's no real need to specify that the rootdn can write in your ACIs. The rootdn can always write, regardless of ACIs.

Also, I'd avoid providing examples that would allow users to change their own uidNumber value, and thereby become root. ;)


[Index of Archives]     [Current Fedora Users]     [Fedora Desktop]     [Fedora SELinux]     [Yosemite News]     [Yosemite Photos]     [KDE Users]     [Fedora Tools]     [Fedora Docs]

  Powered by Linux