Re: [phpldapadmin] Preventing deletion of attributes
Cristian Rigamonti <[email protected]> Wed, 5 Oct 2011 13:05:46 +0200
| Newsgroups | gmane.comp.ldap.davedap |
|---|---|
| Message-ID | <20111005110546.GA9263@merlino> |
--===============1366168633262194921== Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="AqsLC8rIMeq19msA" Content-Disposition: inline --AqsLC8rIMeq19msA Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Wed, Oct 05, 2011 at 09:50:25PM +1100, Deon George wrote: >=20 > No, PLA will not enforce must attributes - that is the LDAP server's > responsibility, and if the schema defines it as a must attribute, then > the server should deny an update that removes the value. Ok, can anyone imagine what would happen in this case? If PLA would just di= splay the error message received from the LDAP server and abort the operation (ju= st like when, e.g. the server denies access) that would be fine with me. > If you want to stop users from accessing userPassword, then make it > "read-only" (and/or hidden) No, users should be able to change their password, I'd just want that they couldn't set a null password, thus removing the userPassword attribute from their entry. (I've also checked the available ACL permissions in openldap but unfortunat= ely the "write" permission also allows to delete the attribute; while other applications have separate "write" and "delete" permissions) Thanks again! Cri --=20 GPG/PGP Key-Id 0x943A5F0E - http://www.linux.it/~cri/cri.asc --AqsLC8rIMeq19msA Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iEYEARECAAYFAk6MOgoACgkQrSAagZQ6Xw4mjQCfd0sF08lds+CvFb3HlrMyPoUp 740AoKb4d22dQJxg2umbk8ZGeZXVkj62 =mBk6 -----END PGP SIGNATURE----- --AqsLC8rIMeq19msA-- --===============1366168633262194921== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline ------------------------------------------------------------------------------ All the data continuously generated in your IT infrastructure contains a definitive record of customers, application performance, security threats, fraudulent activity and more. Splunk takes this data and makes sense of it. Business sense. IT sense. Common sense. http://p.sf.net/sfu/splunk-d2dcopy1 --===============1366168633262194921== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline ______________________________________ phpLDAPadmin development mailing list. To unsbuscribe: https://lists.sourceforge.net/lists/listinfo/phpldapadmin-devel http://phpldapadmin.sourceforge.net/ --===============1366168633262194921==--