Michael Ströder wrote:
HI!
Still trying to optimize a bunch of set-based ACLs I wonder whether the (possibly heavy-weight) set-clauses in the <WHO> part are evaluated only in case of an actually matching <WHAT> part.
Any hint is appreciated.
Hint: OpenLDAP is the fastest, most efficient LDAP software in the world. Hint: Evaluating a clause that doesn't even match the target would be wasteful and inefficient.
Ciao, Michael.