Apache Directory Project - [APACHDS] [ACI] problem to use ACIs

This is Interesting: Free IT Magazines  
Home > Archive > Apache Directory Project > January 2006 > [APACHDS] [ACI] problem to use ACIs





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author [APACHDS] [ACI] problem to use ACIs
Tony Blanchard

2006-01-23, 7:45 am

Hi ,

I have some troubles to add some ACIs on ou=system to enable users to do
what they want with their own entry.
I added an "accessControlSpecificArea" value to the "administrativeRole"
attribute on ou=system.
I used the following subtree specification : "{}" and the following
value for my prescriptiveACI on the accesControlSubentry I created
under ou=system :
" { identificationTag "enableUserSelfModification", precedence 1,
authenticationLevel simple, itemOrUserFirst userFirst:{ userClasses {
thisEntry }, userPermissions { { protectedItems { entry,
allUserAttributeTypesAndValues }, grantsAndDenials { grantAdd,
grantRemove, grantModify, grantFilterMatch, grantCompare, grantRead,
grantReturnDN, grantBrowse } } } } }"

When i create a new user with admin rights and try to log under this
user, i get a 50 error code : noPermission. This is not an 49 error code
: AuthenticationException

Should i use "authenticationLevel none" for some kind of permissions
before expecting to go ahead with other authorizations ?
Has someone an idea on what is my error ?
Thanks to all,
Tony Blanchard





Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2008 webservertalk.com