ACI woes - not doing what I want it to
Anne (juniper) Cross wrote:
> I have this syntactically correct ACI: > > (targetattr = "*") > (targetfilter="(ou=mailrouting-listserver)") > (version 3.0;acl "Listserver Administrator";allow (all) > (userdn = "ldap:///uid=listserve,ou=resource accounts,ou=people,dc=itasoftware,dc=com");) > > It's set on the ou=mailrouting-listserver,ou=resource accounts,etc,etc branch. > > I can authenticate successfully using the uid=listserve account, but I cannot in fact write or change entries in the ou=mailrouting-listserver branch using the account. > > What have I missed? > Does it work if you remove the (targetfilter="(ou=mailrouting-listserver) clause? -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users |
ACI woes - not doing what I want it to
----- "Rich Megginson" <rmeggins@redhat.com> wrote:
> Anne (juniper) Cross wrote: > > I have this syntactically correct ACI: > > > > (targetattr = "*") > > (targetfilter="(ou=mailrouting-listserver)") > > (version 3.0;acl "Listserver Administrator";allow (all) > > (userdn = "ldap:///uid=listserve,ou=resource > accounts,ou=people,dc=itasoftware,dc=com");) > > > > It's set on the ou=mailrouting-listserver,ou=resource > accounts,etc,etc branch. > > > > I can authenticate successfully using the uid=listserve account, but > I cannot in fact write or change entries in the > ou=mailrouting-listserver branch using the account. > > > > What have I missed? > > > Does it work if you remove the > (targetfilter="(ou=mailrouting-listserver) clause? It does. I'm a bit wary of leaving it like that, but given that it's set on the branch, am I correct in assuming that it will only affect the branch beneath the point it is set? -- Anne "juniper" Cross Extropic Crusader, Email Plumber Information Technology, ITA Software -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users |
ACI woes - not doing what I want it to
Anne (juniper) Cross wrote:
> ----- "Rich Megginson" <rmeggins@redhat.com> wrote: > > >> Anne (juniper) Cross wrote: >> >>> I have this syntactically correct ACI: >>> >>> (targetattr = "*") >>> (targetfilter="(ou=mailrouting-listserver)") >>> (version 3.0;acl "Listserver Administrator";allow (all) >>> (userdn = "ldap:///uid=listserve,ou=resource >>> >> accounts,ou=people,dc=itasoftware,dc=com");) >> >>> It's set on the ou=mailrouting-listserver,ou=resource >>> >> accounts,etc,etc branch. >> >>> I can authenticate successfully using the uid=listserve account, but >>> >> I cannot in fact write or change entries in the >> ou=mailrouting-listserver branch using the account. >> >>> What have I missed? >>> >>> >> Does it work if you remove the >> (targetfilter="(ou=mailrouting-listserver) clause? >> > > It does. I'm a bit wary of leaving it like that, but given that it's set on the branch, am I correct in assuming that it will only affect the branch beneath the point it is set? > Correct. In fact, what (targetfilter="(ou=mailrouting-listserver)") means is "only entries which contain an ou attribute with the value of mailrouting-listserver". Note that just because the DN contains "...,ou=mailrouting-listserver,..." does not mean all target entries contain "ou: mailrouting-listserver" -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users |
ACI woes - not doing what I want it to
----- "Rich Megginson" <rmeggins@redhat.com> wrote:
> > It does. I'm a bit wary of leaving it like that, but given that > it's set on the branch, am I correct in assuming that it will only > affect the branch beneath the point it is set? > > > Correct. In fact, what (targetfilter="(ou=mailrouting-listserver)") > means is "only entries which contain an ou attribute with the value of > > mailrouting-listserver". Note that just because the DN contains > "...,ou=mailrouting-listserver,..." does not mean all target entries > contain "ou: mailrouting-listserver" Ahah! Enlightenment. Thanks for your help! -- juniper -- Anne "juniper" Cross Extropic Crusader, Email Plumber Information Technology, ITA Software -- 389 users mailing list 389-users@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/389-users |
| All times are GMT. The time now is 05:35 AM. |
VBulletin, Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO ©2007, Crawlability, Inc.