[389-users] Re: ACI with groupdn to target multiple groups

2021-02-08 Thread William Brown
> On 8 Feb 2021, at 19:18, N R wrote: > > Hi everyone, > > Thanks to Ludwig's indications, I've been able to get the behaviour I > expected, using the filter with this ACI: > (targetattr = "*") > (target = "ldap:///cn=proxy,ou=Servers,dc=domain,dc=tld;) > (version 3.0; > acl "Allow only

[389-users] Re: ACI with groupdn to target multiple groups

2021-02-08 Thread N R
Hi everyone, Thanks to Ludwig's indications, I've been able to get the behaviour I expected, using the filter with this ACI: (targetattr = "*") (target = "ldap:///cn=proxy,ou=Servers,dc=domain,dc=tld;) (version 3.0; acl "Allow only groups members to query this object"; allow (all) (groupdn =

[389-users] Re: ACI with groupdn to target multiple groups

2021-02-07 Thread William Brown
>>> >> I'm not an English native speaker, so please forgive me if there's >> mistakes in this e-mail. >> >> OS : Fedora 30 >> 389ds version / build number : 1.4.1.14 / 2020.023.2226 >> >> I'm struggling with ACI and despite hours of documentation reading, I >>

[389-users] Re: ACI with groupdn to target multiple groups

2021-02-05 Thread Ludwig Krispenz
On 05.02.21 03:33, William Brown wrote: On 5 Feb 2021, at 12:30, William Brown wrote: On 4 Feb 2021, at 22:23, Pierre Rogier wrote: Hi Nicolas, The documentation does not say that wildcard is supported in groupdn evaluation and I have not seen anything in the code that handles it.

[389-users] Re: ACI with groupdn to target multiple groups

2021-02-05 Thread Mark Reynolds
On 2/4/21 9:33 PM, William Brown wrote: On 5 Feb 2021, at 12:30, William Brown wrote: On 4 Feb 2021, at 22:23, Pierre Rogier wrote: Hi Nicolas, The documentation does not say that wildcard is supported in groupdn evaluation and I have not seen anything in the code that handles it.

[389-users] Re: ACI with groupdn to target multiple groups

2021-02-04 Thread William Brown
> On 5 Feb 2021, at 12:30, William Brown wrote: > > > >> On 4 Feb 2021, at 22:23, Pierre Rogier wrote: >> >> Hi Nicolas, >> >> The documentation does not say that wildcard is supported in groupdn >> evaluation and I have not seen anything in the code that handles it. >> IMHO The comment

[389-users] Re: ACI with groupdn to target multiple groups

2021-02-04 Thread William Brown
> On 4 Feb 2021, at 22:23, Pierre Rogier wrote: > > Hi Nicolas, > > The documentation does not say that wildcard is supported in groupdn > evaluation and I have not seen anything in the code that handles it. > IMHO The comment about group dn filter is a bit confusing: > the only place it is

[389-users] Re: ACI with groupdn to target multiple groups

2021-02-04 Thread Pierre Rogier
Hi Nicolas, The documentation does not say that wildcard is supported in groupdn evaluation and I have not seen anything in the code that handles it. IMHO The comment about group dn filter is a bit confusing: the only place it is supported while evaluating groupdn is within the (filter) part when

[389-users] Re: ACI with groupdn to target multiple groups

2021-02-04 Thread N R
Hi Ludwig, Thanks for your reply. To clarify, when I say it's not working, it means that members of the groups are not able to search the "cn=proxy" container's entries. For example, I've set the following ACI on "cn=proxy": (targetattr = "*") (target =

[389-users] Re: ACI with groupdn to target multiple groups

2021-02-03 Thread Ludwig Krispenz
On 03.02.21 16:23, N R wrote: Hi everyone, I'm not an English native speaker, so please forgive me if there's mistakes in this e-mail. OS : Fedora 30 389ds version / build number : 1.4.1.14 / 2020.023.2226 I'm struggling with ACI and despite hours of documentation reading, I don't understand