> -----Original Message----- > From: fedora-directory-users-bounces at redhat.com > [mailto:fedora-directory-users-bounces at redhat.com] On Behalf > Of Pete Rowley > Sent: Tuesday, June 14, 2005 3:03 PM > To: 'General discussion list for the Fedora Directory server project.' > Subject: RE: roles and access control > > A combination of a value based aci targeting nsroledn: That should be nsrole - _never_ use nsroledn for anything other than adding and removing roles from an entry.