[389-devel] Re: Do aci's work in nested groups?

2018-01-10 Thread William Brown
On Wed, 2018-01-10 at 10:44 +0100, Ludwig Krispenz wrote: > On 01/10/2018 07:03 AM, William Brown wrote: > > If I have: > > > > (targetattr=x)(version 3.0; allow(read, > > search)(groupdn=cn=x);) > > > > If cn=x has member cn=y, and cn=y member uid=z > > > > Does uid=z have permission to th

[389-devel] Re: Do aci's work in nested groups?

2018-01-10 Thread Ludwig Krispenz
On 01/10/2018 07:03 AM, William Brown wrote: If I have: (targetattr=x)(version 3.0; allow(read, search)(groupdn=cn=x);) If cn=x has member cn=y, and cn=y member uid=z Does uid=z have permission to the targetattr here? IE do our aci's work through nested groups? yes, they should, but the