By default, FDS will restrict access to everything - that is, you don't
need to have an explicit deny unless you have another ACI somewhere
that allows other attributes. ACIs work together in this way - when
there is a rule that allows some access and a rule that explicitly
denies that same access, the deny rule wins. In your case, if this is
the only ACI, you don't need the deny clause, you could just do this: (target = "ldap:///ou=People, dc=ite,dc=gmu,dc=edu") (targetattr ="employeeNumber") (version 3.0;acl "EmployeeNumber"; allow (read) userdn="ldap:///self" and authmethod="sasl gssapi"; ) Alastair Neil wrote: I am struggling with setting ACIs to restrict access to certain attributes |
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature
-- Fedora-directory-users mailing list Fedora-directory-users@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/fedora-directory-users