Re: [Freeipa-devel] [389-devel] Design review (second): Access control on entries specified in MODDN operation (ticket 47553)

2014-02-28 Thread thierry bordaz
HI Ludwig, Thanks for catching that, I will update the doc. When the legacy server receives an aci with that new syntax, it does not recognize the new keywords (moddn, target_to, target_from) so the parser fails and the aci is simply ignored. In the implementation (__aclp__parse_ac) ,

[Freeipa-devel] [389-devel] Design review (second): Access control on entries specified in MODDN operation (ticket 47553)

2014-02-27 Thread thierry bordaz
Hello, Thanks to all your feedbacks, they helped me a lot and raised a severe limitation in the original design. I updated the design following the aci syntax proposed during the discussion. On the implementation side, it is a bit more complex but less than I expected. I have not yet

Re: [Freeipa-devel] [389-devel] Design review (second): Access control on entries specified in MODDN operation (ticket 47553)

2014-02-27 Thread Ludwig Krispenz
Hi, in the replication section you describe the behaviour when replicating to older versions of ds, but this is for n1, how about the new design ? Ludwig On 02/27/2014 04:46 PM, thierry bordaz wrote: Hello, Thanks to all your feedbacks, they helped me a lot and raised a severe limitation