Hi,
On Wed, 5 Jun 2013, Michael Ströder wrote: <snipp/>
So one would need to check for manage access to userPassword an if the relax control rule has been sent in this request.
I will try searching the code to see if any of that is readily accessible in the context needed for the check. I have not looked to deep in the openldap code yet to fully understand the internal archicture.
It's already done like this e.g. for write access to operational attribute 'pwdHistory'.
ok. Thanks for the pointer. I'll research and see if it possibly already works that way.
Greetings Christian