simple ACL requirement, grant access to modify myself and my sub entries, not sure how to do it

2007-05-09 Thread Zhang Weiwu
Dear all. In my installation it's required if someone logs in, he can modify his own entry and can modify & delete & create entries of his own entry, e.g. login as: dn: ou=Support,o=Real Softservice Then I should be able to modify & delete & create: dn: cn=Wang Penghui,ou=Suport,o=Real Softservi

Re: simple ACL requirement, grant access to modify myself and my sub entries, not sure how to do it

2007-05-09 Thread Shane
Hopefully someone will correct me if I'm wrong but as far as I'm aware you cannot log in as an ou object. I'd has setup and admin user for dn: ou=Support,o=Real Softservice eg: cn=admin,ou=Support,o=Real Softservice then create an ACL like access to dn.base="ou=Support,o=Real Softservice"

Re: simple ACL requirement, grant access to modify myself and my sub entries, not sure how to do it

2007-05-09 Thread Pierangelo Masarati
Shane wrote: > Hopefully someone will correct me if I'm wrong but as far as I'm aware > you cannot log in as an ou object. You can login with __ANY__ DN, provided you configure your server to authenticate that identity. As per how to do that, there are innumerable ways (SASL in the first place, b

Re: simple ACL requirement, grant access to modify myself and my sub entries, not sure how to do it

2007-05-10 Thread Michael Ströder
Zhang Weiwu wrote: > Dear all. In my installation it's required if someone logs in, he can > modify his own entry and can modify & delete & create entries of his own > entry, e.g. > [..] > Looks like a simple requirement. Anyway I dug into ACL manual for days > without a clue (maybe also because of

Re: simple ACL requirement, grant access to modify myself and my sub entries, not sure how to do it

2007-05-11 Thread Zhang Weiwu
On Thu, 2007-05-10 at 00:29 +0930, Shane wrote: > Hopefully someone will correct me if I'm wrong but as far as I'm aware > you cannot log in as an ou object. > > I'd has setup and admin user for dn: ou=Support,o=Real Softservice eg: > > cn=admin,ou=Support,o=Real Softservice > > then create an A