If I’have a structure like:


-          Role


-          User

-          Permission


-          Role


Now I want to get the authorization for some permission, So I have the information which user and which Permission. Now I need to match the list.

The way it already work:

                Get all Roles for a Permission

                Search in the user for the Role

If found Authorization

Else no

Therefore I need at least two requests to the LDAP server


My Question:

Is it possible to send only the DN of a Permissions and tell the Server, that he/she need to extract the Role attributes and check in the DN of a user for those Roles?

Can I Implement an overlay on the Server to manage this task or is it senseless to think about such a task for the server?


