Re: ACL to deny deletes but allow entry creation.
Howard Chu <[email protected]> Sat, 24 Apr 2010 19:27:04 -0700
| Newsgroups | gmane.network.openldap.general |
|---|---|
| Message-ID | <[email protected]> |
Aravind Gottipati wrote: > Hi, > > I am working on an application where we want to grant an admin account > the privileges to create new entries, but prevent any further changes > (or deletes) to the entry by the admin account. I have looked through > the docs and the faqs for this, and I am pretty sure that this is not > possible. The simile folks relate this with, is the ability to grant > insert privileges to an account in mysql, but restrict selects, > updates etc.. Before I tell the developers that this is not possible, > I wanted to check with you folks first. Have Any of you encountered > similar situations? How do others deal with cases like this? It is of course possible. Read the slapd.access(5) manpage. Note that wadd and wdel are separate privileges. -- -- Howard Chu CTO, Symas Corp. http://www.symas.com Director, Highland Sun http://highlandsun.com/hyc/ Chief Architect, OpenLDAP http://www.openldap.org/project/