On 09/05/2013 10:24 AM, Alberto Viana
wrote:
389-Directory/ 1.3.1.3 B2013.193.1948
I set an ACI to specific user to add,read or modify
everything on this OU:
dn: ou=UFRGS,ou=RNP,dc=homolog,dc=rnp
changetype: modify
add: aci
Not sure if it matters but you are missing the "search" right in
your allow list. Nevermind I see you tested with "all"
But when I do a ldapsearch with this user (app.ufrgs.w) on
this OU I cant see the userpassword attribute.
Are you requesting the userpassword attribute in the ldapsearch?
Can you paste the exact ldapsearch you are doing?
Thanks,
Mark
dn: uid=teste123,ou=UFRGS,ou=RNP,dc=homolog,dc=rnp
uid: teste123
givenName: teste123
objectClass: top
objectClass: person
objectClass: organizationalPerson
objectClass: inetorgperson
objectClass: ntUser
sn: teste
cn: teste123
ntUserDomainId: teste123
ntUserCreateNewAccount: true
ntUserDeleteAccount: true
I Also tried this kind of ACI:
dn: ou=UFRGS,ou=RNP,dc=homolog,dc=rnp
changetype: modify
add: aci
When I do it with "Directory Manager" I can see the
userpassword attribute. What I have to do?
--
389 users mailing list
389-users@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/389-users
--
Mark Reynolds
389 Development Team
Red Hat, Inc
mreynolds@xxxxxxxxxx
|
--
389 users mailing list
389-users@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/389-users