From Russell.Mosemann@cune.edu Wed Sep 4 20:22:10 2013 From: Russell.Mosemann@cune.edu To: openldap-bugs@openldap.org Subject: (ITS#7673) Date: Wed, 04 Sep 2013 20:22:10 +0000 Message-ID: <201309042022.r84KMAk2041827@boole.openldap.org> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============8453377502148238898==" --===============8453377502148238898== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit --_000_B01302EA11DF7D40B2AD9CBEC71B02562C4A3ED5exchange2cunepr_ Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable The lookup succeeds, and the returned entry is run through the searchEntryD= N context. It appears that somewhere in or around there all of the attribut= es are removed except for the requested attributes. That means the ACL filt= er will fail, if the filter attributes are not requested in the query. If t= he requested attributes include the filter attributes, the query succeeds, = but the result only returns the dn without any other attributes. If no attributes are requested, all allowed attributes are returned. The man page indicates that searchEntryDN should not be applied, because it= is not defined, and there is no default. --_000_B01302EA11DF7D40B2AD9CBEC71B02562C4A3ED5exchange2cunepr_ Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable

The lookup succeeds, and the returne= d entry is run through the searchEntryDN context. It appears that somewhere= in or around there all of the attributes are removed except for the requested attributes. That means the ACL filter will fail, if the = filter attributes are not requested in the query. If the requested attribut= es include the filter attributes, the query succeeds, but the result only r= eturns the dn without any other attributes.

 

If no attributes are requested, all = allowed attributes are returned.

 

The man page indicates that searchEn= tryDN should not be applied, because it is not defined, and there is no def= ault.

 

--_000_B01302EA11DF7D40B2AD9CBEC71B02562C4A3ED5exchange2cunepr_-- --===============8453377502148238898==--