From uwe.sauter.de@gmail.com Fri Feb 5 16:05:19 2021 From: Uwe Sauter To: openldap-technical@openldap.org Subject: How to restrict access to operational attributes? Date: Fri, 05 Feb 2021 08:40:56 +0100 Message-ID: MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============2297811632264406571==" --===============2297811632264406571== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Good morning, I'm trying to restrict access to the operational attributes that are provided= by the ppolicy overlay (e.g. pwdChangedTime, pwdHistory). When I add the following to my ACL configuration file and try to verify the c= onfiguration an error occurs: #### ACL access to attrs=3DpwdHistory by * none ######## #### slaptest output 601cf554 /etc/openldap/acl.conf: line 96: unknown attr "pwdHistory" in to cla= use 601cf554 ::=3D access to [ by [ ] [ ] ]+ ::=3D * | dn[.=3D] [filter=3D] [attrs=3D] ::=3D [val[/][.]=3D] | = ::=3D [ , ] ::=3D | @ | ! | entry | children ::=3D [ * | anonymous | users | self | dn[.]=3D ] [ realanonymous | realusers | realself | realdn[.]=3D ] [dnattr=3D] [realdnattr=3D] [group[/[/]][.