Re: ACL: access to all values vs. to value

2012-08-10 Thread Dora Paula
Gavin Henry wrote: is there a possibility to create an acl statement that grants access to any (unknown) value of an attribute but denys access to all values of the same attribute? Can you explain that again? BTW: Your answer didn't find its way into the openldap-technical archive:

Re: ACL: access to all values vs. to value

2012-08-10 Thread Gavin Henry
Gavin Henry wrote: is there a possibility to create an acl statement that grants access to any (unknown) value of an attribute but denys access to all values of the same attribute? Can you explain that again? BTW: Your answer didn't find its way into the openldap-technical archive:

ACL: access to all values vs. to value

2012-08-09 Thread Dora Paula
Hi list, is there a possibility to create an acl statement that grants access to any (unknown) value of an attribute but denys access to all values of the same attribute? For example: # allow this: dn: cn=PersonA,ou=persons,o=test changetype: modify delete: description description: