This is *not* a low priority bug.  The ability to read the cn=subschema
entry is critical to all applications that need to retrieve schema data
from the LDAP server.  The first two ACL's for an LDAP server should
pretty much always be:

olcAccess: {1}to dn.base=""  by * read
olcAccess: {2}to dn.base="cn=subschema"  by * read


The first so that access to the controls available, etc, is there, and the 
second so that access to the cn=subschema entry is available.

These access issues both broken with Ubuntu, and very serious.

--Quanah

-- 
"Our attempts to find your SCHEMA for "attributetypes" have FAILED"
https://bugs.launchpad.net/bugs/489619
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to