Re: [phpldapadmin] Preventing deletion of attributes

Cristian Rigamonti <[email protected]> Wed, 5 Oct 2011 13:05:46 +0200
Newsgroups gmane.comp.ldap.davedap
Message-ID <20111005110546.GA9263@merlino>
--===============1366168633262194921==
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature"; boundary="AqsLC8rIMeq19msA"
Content-Disposition: inline


--AqsLC8rIMeq19msA
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Wed, Oct 05, 2011 at 09:50:25PM +1100, Deon George wrote:
>=20
> No, PLA will not enforce must attributes - that is the LDAP server's
> responsibility, and if the schema defines it as a must attribute, then
> the server should deny an update that removes the value.

Ok, can anyone imagine what would happen in this case? If PLA would just di=
splay
the error message received from the LDAP server and abort the operation (ju=
st
like when, e.g. the server denies access) that would be fine with me.

> If you want to stop users from accessing userPassword, then make it
> "read-only" (and/or hidden)

No, users should be able to change their password, I'd just want that they
couldn't set a null password, thus removing the userPassword attribute from
their entry.

(I've also checked the available ACL permissions in openldap but unfortunat=
ely
the "write" permission also allows to delete the attribute; while other
applications have separate "write" and "delete" permissions)

Thanks again!

Cri

--=20
GPG/PGP Key-Id 0x943A5F0E      -    http://www.linux.it/~cri/cri.asc

--AqsLC8rIMeq19msA
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAk6MOgoACgkQrSAagZQ6Xw4mjQCfd0sF08lds+CvFb3HlrMyPoUp
740AoKb4d22dQJxg2umbk8ZGeZXVkj62
=mBk6
-----END PGP SIGNATURE-----

--AqsLC8rIMeq19msA--


--===============1366168633262194921==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

------------------------------------------------------------------------------
All the data continuously generated in your IT infrastructure contains a
definitive record of customers, application performance, security
threats, fraudulent activity and more. Splunk takes this data and makes
sense of it. Business sense. IT sense. Common sense.
http://p.sf.net/sfu/splunk-d2dcopy1
--===============1366168633262194921==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

______________________________________
phpLDAPadmin development mailing list.
To unsbuscribe: https://lists.sourceforge.net/lists/listinfo/phpldapadmin-devel
http://phpldapadmin.sourceforge.net/

--===============1366168633262194921==--