Targeting Both An Entry And Attributes; Targeting Entries Or Attributes Using Ldap Filters - Red Hat DIRECTORY SERVER 7.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Creating ACIs Manually
The attributes specified in the
ACI is targeting and to all the entries below it. If you target the password attribute
on the entry
password attribute on the
entry.
If, however, you target the tree's branch point
ou=Marketing,dc=example,dc=com
that can contain a password attribute are affected by the ACI.

Targeting Both an Entry and Attributes

By default, the entry targeted by an ACI containing a
entry on which the ACI is placed. That is, if you put the ACI
aci: (targetattr = "uid")(access_control_rules;)
on the
entire Marketing subtree. However, you can also explicitly specify a target using
the
target
aci: (target="ldap:///ou=Marketing,
dc=example,dc=com")(targetattr="uid") (access_control_rules;)
The order in which you specify the
important.

Targeting Entries or Attributes Using LDAP Filters

You can use LDAP filters to target a group of entries that match certain criteria. To
do this, you must use the
The syntax of the
(targetfilter = "LDAP_filter")
where
syntax of LDAP search filters, see Appendix B, "Finding Directory Entries."
For example, suppose that all entries in the accounting department include the
attribute-value pair
include the attribute-value pair
in the accounting and engineering branches of the directory tree, you could use
the following filter:
(targetfilter = "(|(ou=accounting)(ou=engineering))")
212
Red Hat Directory Server Administrator's Guide • May 2005
uid=bjensen,ou=Marketing,dc=example,dc=com
bjensen
,
ou=Marketing
dc=example,dc=com
keyword as follows:
targetfilter
targetfilter
is a standard LDAP search filter. For more information on the
LDAP_filter
ou=accounting
keyword apply to the entry that the
targetattr
entry is affected by the ACI because it is a leaf
, then all the entries beneath the branch point
entry, then the ACI applies to the
and the
target
keyword with an LDAP filter.
keyword is:
, and all entries in the engineering department
subtree. To target all the entries
ou=engineering
, only the
keyword is the
targetattr
keywords is not
targetattr

Advertisement

Table of Contents
loading

This manual is also suitable for:

Directory server 7.1

Table of Contents