Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 189176 - default ACI on userRoot suffix doesn't match default admin group
default ACI on userRoot suffix doesn't match default admin group
Product: 389
Classification: Retired
Component: Install/Uninstall (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Nathan Kinder
Viktor Ashirov
Depends On:
Blocks: 152373 fds103trackingbug 240316
  Show dependency treegraph
Reported: 2006-04-17 16:45 EDT by Ulf Weltman
Modified: 2015-12-07 11:39 EST (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2015-12-07 11:39:35 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)
Attached exported ldif which shows proper ACI (5.90 KB, application/octet-stream)
2007-12-07 11:20 EST, Anh Nguyen
no flags Details

  None (edit)
Description Ulf Weltman 2006-04-17 16:45:54 EDT
Description of problem:
One of the default ACI on the user suffix is:
aci: (targetattr ="*")(version 3.0;acl "Directory Administrators Group";allow
 (all) (groupdn = "ldap:///ou=Directory Administrators, dc=cup,dc=hp,dc=com")

But the DN of the default directory administrators group is "cn=Directory
Administrators, dc=cup,dc=hp,dc=com" so that doesn't match the ACI.  In
ldapserver/ldap/ldif/template.ldif change the "ou" to "cn" in that ACI...

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
Actual results:

Expected results:

Additional info:
Comment 1 Nathan Kinder 2006-04-18 13:34:17 EDT
Checked into HEAD (ldapserver).

Checking in template.ldif;
/cvs/dirsec/ldapserver/ldap/ldif/template.ldif,v  <--  template.ldif
new revision: 1.5; previous revision: 1.4

Index: template.ldif
RCS file: /cvs/dirsec/ldapserver/ldap/ldif/template.ldif,v
retrieving revision 1.4
diff -r1.4 template.ldif
<  ou=Directory Administrators, %%%SUFFIX%%%");)
>  cn=Directory Administrators, %%%SUFFIX%%%");)
Comment 2 Anh Nguyen 2007-12-07 11:20:12 EST

See attached for the exported ldif file.
Comment 3 Anh Nguyen 2007-12-07 11:20:59 EST
Created attachment 281331 [details]
Attached exported ldif which shows proper ACI

Note You need to log in before you can comment on or make changes to this bug.