[389-users] Re: ACI limiting read to groups a user is member of

2020-02-17 Thread Grant Byers
On 18/2/20 7:56 am, William Brown wrote: > >> On 17 Feb 2020, at 19:25, thierry bordaz wrote: >> >> >> >> On 2/17/20 5:26 AM, Grant Byers wrote: >>> Got it.. >>> >>> >>> (userattr = "uniqueMember#USERDN") >> It allows a member of a groupofUniqueName to read/search that group. If you >> are also

[389-users] Re: winsync password problems

2020-02-17 Thread William Brown
Mark, any ideas what to look at next :S Besides actually trying to setup and reproduce it which I think would be the next step > On 18 Feb 2020, at 05:45, Alberto Viana wrote: > > Hi Guys, > > Setup another environment 389 1.4.1.14 + windows 2016, still not working, > exactly the

[389-users] Re: ACI limiting read to groups a user is member of

2020-02-17 Thread William Brown
> On 17 Feb 2020, at 19:25, thierry bordaz wrote: > > > > On 2/17/20 5:26 AM, Grant Byers wrote: >> Got it.. >> >> >> (userattr = "uniqueMember#USERDN") > It allows a member of a groupofUniqueName to read/search that group. If you > are also supporting GroupofName groups you may want to

[389-users] Re: winsync password problems

2020-02-17 Thread Alberto Viana
Hi Guys, Setup another environment 389 1.4.1.14 + windows 2016, still not working, exactly the same behavior. :/ Cheers, Alberto Viana On Wed, Jan 29, 2020 at 8:19 PM Alberto Viana wrote: > William, > > Yes, *other* attributes are replicated to AD normally (in all versions > that I tested).

[389-users] Re: ACI limiting read to groups a user is member of

2020-02-17 Thread thierry bordaz
On 2/17/20 5:26 AM, Grant Byers wrote: Got it.. (userattr = "uniqueMember#USERDN") It allows  a member of a groupofUniqueName to read/search that group. If you are also supporting GroupofName groups you may want to add the bind rule (userasttr="member#userDN"). With this rule, targetfilter