# The userPassword by default can be changed
Here is my access controls in slapd.conf.

# by the entry owning it if they are authenticated.
# Others should not be able to see it, except the
# admin entry below
# These access lines apply to database #1 only
access to attrs=userPassword,shadowLastChange
       by dn="cn=admin,dc=ubuntu-server,dc=alpinedistrict,dc=org" write
       by anonymous auth
       by self write
       by * none

# Ensure read access to the base for things like
# supportedSASLMechanisms.  Without this you may
# have problems with SASL not knowing what
# mechanisms are available and the like.
# Note that this is covered by the 'access to *'
# ACL below too but if you change that as people
# are wont to do you'll still need this if you
# want SASL (and possible other things) to work
# happily.
access to dn.base="" by * read


# The admin dn has full write access, everyone else
# can read everything.
access to *
       by dn="cn=admin,dc=ubuntu-server,dc=alpinedistrict,dc=org" write
       by * read

# For Netscape Roaming support, each user gets a roaming
# profile for which they have write access to
#access to dn=".*,ou=Roaming,o=morsnet"
#        by dn="cn=admin,dc=ubuntu-server,dc=alpinedistrict,dc=org" write
#        by dnattr=owner write

-Daniel

/*
PLUG: http://plug.org, #utah on irc.freenode.net
Unsubscribe: http://plug.org/mailman/options/plug
Don't fear the penguin.
*/

Reply via email to