ldap troubles

Daniel teletautala at gmail.com
Tue May 8 11:30:05 MDT 2007


# The userPassword by default can be changed
Here is my access controls in slapd.conf.

# by the entry owning it if they are authenticated.
# Others should not be able to see it, except the
# admin entry below
# These access lines apply to database #1 only
access to attrs=userPassword,shadowLastChange
        by dn="cn=admin,dc=ubuntu-server,dc=alpinedistrict,dc=org" write
        by anonymous auth
        by self write
        by * none

# Ensure read access to the base for things like
# supportedSASLMechanisms.  Without this you may
# have problems with SASL not knowing what
# mechanisms are available and the like.
# Note that this is covered by the 'access to *'
# ACL below too but if you change that as people
# are wont to do you'll still need this if you
# want SASL (and possible other things) to work
# happily.
access to dn.base="" by * read


# The admin dn has full write access, everyone else
# can read everything.
access to *
        by dn="cn=admin,dc=ubuntu-server,dc=alpinedistrict,dc=org" write
        by * read

# For Netscape Roaming support, each user gets a roaming
# profile for which they have write access to
#access to dn=".*,ou=Roaming,o=morsnet"
#        by dn="cn=admin,dc=ubuntu-server,dc=alpinedistrict,dc=org" write
#        by dnattr=owner write

-Daniel


More information about the PLUG mailing list