Bug 1371559 - ACI syntax, if targetattr (and targetattrfilter) is missing then NO attribute are targeted
Summary: ACI syntax, if targetattr (and targetattrfilter) is missing then NO attribute...
Keywords:
Status: CLOSED DUPLICATE of bug 1261944
Alias: None
Product: Red Hat Directory Server
Classification: Red Hat
Component: Doc-administration-guide
Version: 10.0
Hardware: Unspecified
OS: Unspecified
unspecified
medium
Target Milestone: ---
: ---
Assignee: Marc Muehlfeld
QA Contact: Viktor Ashirov
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-08-30 13:17 UTC by thierry bordaz
Modified: 2016-11-18 14:27 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-11-18 14:27:21 UTC
Target Upstream Version:


Attachments (Terms of Use)

Description thierry bordaz 2016-08-30 13:17:02 UTC
Description of problem:

The following aci:
(targetfilter = "(&(memberOf=cn=devel-group,cn=groups,SUFFIX))")
(version 3.0;acl "group_manager allowed to update any member of devel group";                                                                          
allow (all) groupdn = "ldap:///cn=group_manager,cn=groups,SUFFIX";)

allows 'group_manager' to ADD/DEL/MODDN/SRCH all members of 'devel-group', but does not allow to access any attribute of those members.
targetattr being missing, it means that NO attribute are targeted by this aci.



I think we need to update https://access.redhat.com/documentation/en-US/Red_Hat_Directory_Server/10/html/Administration_Guide/Managing_Access_Control-Creating_ACIs_Manually.html#Defining_Targets-Targeting_Attributes to inform that if 'targetattr' is missing, no attribute can be read/updated from the targeted entries.

Comment 1 Marc Muehlfeld 2016-11-18 14:27:21 UTC
I updated this a few days ago while working on a different BZ. See:
https://bugzilla.redhat.com/show_bug.cgi?id=1261944#c1

*** This bug has been marked as a duplicate of bug 1261944 ***


Note You need to log in before you can comment on or make changes to this bug.