greek ordono <[EMAIL PROTECTED]> writes:

> Hello,                                                                        
>                                                   
>                                                                               
>                                                   
> I've changed my acl like this:                                                
>                                                   
> access to 
> attrs=userPassword,shadowLastChange,sambaNTPassword,sambaLMPassword,sambaPwdLastSet,sambaPwdMustChange
>                 
>         by dn="cn=nssldap,ou=DSA,dc=moldex,dc=group" write                    
>                                                   
>         by anonymous auth                                                     
>                                                   
>         by self write                                                         
>                                                   
>                                                                               
>                                                   
> access to *                                                                   
>                                                   
>         by self write                                                         
>                                                   
>         by * read                                                             
>                                                   
>                                                                               
>                                                   
                                            
> <= acl_mask: [3] applying auth(=xd) (stop)                                    
>                                                   
> <= acl_mask: [3] mask: auth(=xd)                                              
>                                                   
> => slap_access_allowed: read access denied by auth(=xd)                       
>                                                   
> => access_allowed: no more rules                                              
>                                                   

The answer is obvious, your rule "by anonymous auth" is applied.
You should prabably read
http://www.openldap.org/faq/data/cache/189.html
in order to design access rules

-Dieter

-- 
Dieter Klünter | Systemberatung
http://www.dkluenter.de
GPG Key ID:8EF7B6C6

Reply via email to