From Claudio.Strizzolo@ts.infn.it Thu Nov 23 09:15:16 2006 From: Claudio Strizzolo To: openldap-software@openldap.org Subject: Re: ACL using netgroups Date: Thu, 23 Nov 2006 10:14:43 +0100 Message-ID: <45656683.90003@ts.infn.it> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============2848986781235688966==" --===============2848986781235688966== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Hi Dieter, >> Hello Dieter, >> thanks for your reply. >> I tried as you suggested: >> >> by dn="cn=ldapauth,dc=example,dc=com" \ >> group/nisNetgroup/nisNetgroupTriple=cn=linuxa,ou=netgroup,dc=example,dc=com >> read >> >> Unfortunately it does not work: >> >> [...] >> >> If that matters, I am using openldap 2.2.13. > Ah your historic version might be a problem. I can't remember, in > which version the group expansion has been implemented. > My slapd.access(5) OpenLDAP-2.3.27 states > THE FIELD > > [...] > It can have the forms > > [ other forms deleted ] > group[/[/]] Actually I have the same syntax available in my slapd.access: ::= [ * | anonymous | users | self | dn[.]= ] [dnattr=] [group[/[/]][.