https://bugs.openldap.org/show_bug.cgi?id=9211

            Bug ID: 9211
           Summary: Relax control is not consistently access-restricted
           Product: OpenLDAP
           Version: 2.4.49
          Hardware: All
                OS: All
            Status: UNCONFIRMED
          Severity: normal
          Priority: ---
         Component: slapd
          Assignee: [email protected]
          Reporter: [email protected]
  Target Milestone: ---

The following operations can be performed by anyone having 'write' access (not
even 'manage') using the Relax control:

- modifying/replacing structural objectClass
- adding/modifying OBSOLETE attributes

Some operations are correctly restricted:
- adding/modifying NO-USER-MODIFICATION attributes marked as manageable

(Modification of non-conformant objects doesn't appear to be implemented at
all.)

In the absence of ACLs for controls, I'm of the opinion that all use of the
Relax control should require manage access. The Relax draft clearly and
repeatedly discusses its use cases in terms of directory _administrators_
temporarily relaxing constraints in order to accomplish a specific task.

-- 
You are receiving this mail because:
You are on the CC list for the bug.

Reply via email to