Re: [389-devel] Design review: Access control on entries specified in MODDN operation (ticket 47553)

2014-02-26 Thread Ludwig Krispenz
Not sure what you mean. Do you mean the entry in which you set the aci attribute must be a parent/ancestor of both the target_to DN and the target_from DN? Also what to do if 'target_to'/'target_from' are missing, to replace them with the entry DN having the aci ? I think it would be

Re: [389-devel] Design review: Access control on entries specified in MODDN operation (ticket 47553)

2014-02-25 Thread thierry bordaz
On 02/25/2014 03:46 PM, Rich Megginson wrote: On 02/25/2014 07:42 AM, thierry bordaz wrote: On 02/25/2014 03:34 PM, Rich Megginson wrote: On 02/25/2014 07:24 AM, thierry bordaz wrote: On 02/24/2014 10:47 PM, Noriko Hosoi wrote: Rich Megginson wrote: On 02/24/2014 09:00 AM, thierry bordaz

Re: [389-devel] Design review: Access control on entries specified in MODDN operation (ticket 47553)

2014-02-25 Thread Ludwig Krispenz
On 02/25/2014 04:14 PM, thierry bordaz wrote: On 02/25/2014 03:46 PM, Rich Megginson wrote: On 02/25/2014 07:42 AM, thierry bordaz wrote: On 02/25/2014 03:34 PM, Rich Megginson wrote: On 02/25/2014 07:24 AM, thierry bordaz wrote: On 02/24/2014 10:47 PM, Noriko Hosoi wrote: Rich Megginson

Re: [389-devel] Design review: Access control on entries specified in MODDN operation (ticket 47553)

2014-02-25 Thread Rich Megginson
On 02/25/2014 08:28 AM, thierry bordaz wrote: On 02/25/2014 04:17 PM, Rich Megginson wrote: On 02/25/2014 08:14 AM, thierry bordaz wrote: On 02/25/2014 03:46 PM, Rich Megginson wrote: On 02/25/2014 07:42 AM, thierry bordaz wrote: On 02/25/2014 03:34 PM, Rich Megginson wrote: On 02/25/2014

Re: [389-devel] Design review: Access control on entries specified in MODDN operation (ticket 47553)

2014-02-25 Thread Mark Reynolds
On 02/25/2014 11:28 AM, thierry bordaz wrote: On 02/25/2014 04:53 PM, Ludwig Krispenz wrote: On 02/25/2014 04:45 PM, Rich Megginson wrote: On 02/25/2014 08:28 AM, thierry bordaz wrote: On 02/25/2014 04:17 PM, Rich Megginson wrote: On 02/25/2014 08:14 AM, thierry bordaz wrote: On

Re: [389-devel] Design review: Access control on entries specified in MODDN operation (ticket 47553)

2014-02-25 Thread Ludwig Krispenz
On 02/25/2014 05:34 PM, Mark Reynolds wrote: On 02/25/2014 11:28 AM, thierry bordaz wrote: On 02/25/2014 04:53 PM, Ludwig Krispenz wrote: On 02/25/2014 04:45 PM, Rich Megginson wrote: On 02/25/2014 08:28 AM, thierry bordaz wrote: On 02/25/2014 04:17 PM, Rich Megginson wrote: On

Re: [389-devel] Design review: Access control on entries specified in MODDN operation (ticket 47553)

2014-02-25 Thread thierry bordaz
On 02/25/2014 05:34 PM, Mark Reynolds wrote: On 02/25/2014 11:28 AM, thierry bordaz wrote: On 02/25/2014 04:53 PM, Ludwig Krispenz wrote: On 02/25/2014 04:45 PM, Rich Megginson wrote: On 02/25/2014 08:28 AM, thierry bordaz wrote: On 02/25/2014 04:17 PM, Rich Megginson wrote: On 02/25/2014

Re: [389-devel] Design review: Access control on entries specified in MODDN operation (ticket 47553)

2014-02-25 Thread thierry bordaz
On 02/25/2014 05:56 PM, Rich Megginson wrote: On 02/25/2014 09:51 AM, thierry bordaz wrote: On 02/25/2014 05:36 PM, Rich Megginson wrote: On 02/25/2014 09:28 AM, thierry bordaz wrote: On 02/25/2014 04:53 PM, Ludwig Krispenz wrote: On 02/25/2014 04:45 PM, Rich Megginson wrote: On 02/25/2014

Re: [389-devel] Design review: Access control on entries specified in MODDN operation (ticket 47553)

2014-02-24 Thread Noriko Hosoi
Rich Megginson wrote: On 02/24/2014 09:00 AM, thierry bordaz wrote: Hello, IPA team filled this ticket https://fedorahosted.org/389/ticket/47553. It requires an ACI improvement so that during a MODDN a given user is only allowed to move an entry from one specified part of

Re: [389-devel] Design review: Access control on entries specified in MODDN operation (ticket 47553)

2014-02-24 Thread Rich Megginson
On 02/24/2014 02:47 PM, Noriko Hosoi wrote: Rich Megginson wrote: On 02/24/2014 09:00 AM, thierry bordaz wrote: Hello, IPA team filled this ticket https://fedorahosted.org/389/ticket/47553. It requires an ACI improvement so that during a MODDN a given user is only allowed to