Andrew Bartlett wrote:
Sorry, this seems a bit recursive. I'm lost.
In fact, it is. The point is that what you're asking for may not comply
with the ACL model of most DSA implementations, which usually is a
desirable model for a number of reasons. What you need is a
"cooperative" DSA administrator that agrees to use only a subset of the
ACL semantics so that their effect can be computed a priori, without any
knowledge of the values that are/will be stored in the attributes.
Under this assumption, implementing the feature you desire should be
straightforward.
p.
Ing. Pierangelo Masarati
OpenLDAP Core Team
SysNet s.n.c.
Via Dossi, 8 - 27100 Pavia - ITALIA
http://www.sys-net.it
------------------------------------------
Office: +39.02.23998309
Mobile: +39.333.4963172
Email: pierangelo.masarati@xxxxxxxxxx
------------------------------------------
--
Fedora-directory-devel mailing list
Fedora-directory-devel@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/fedora-directory-devel