openldap search acl

Posted by Patrick on Server Fault See other posts from Server Fault or by Patrick
Published on 2012-04-16T04:11:57Z Indexed on 2012/04/16 5:33 UTC
Read the original article Hit count: 462

Filed under:
|

I'm trying to write an access control for OpenLDAP to allow a user to search with a certain base dn, but only get results back from certain sub dn's. I've played with lots of different rules but cant get it to work. I'm not sure its even possible.

For example:
I have the user with the dn uid=testuser,ou=people,dc=example,dc=com. I want this user to be able to search with a base of dc=example,dc=com and get back entries in ou=people,dc=example,dc=com. There are lots of other sub OUs under dc=example,dc=com, but only entries in ou=people should be returned (for bonus, I'd only like certain attributes to be returned as well).

Can this be done?

© Server Fault or respective owner

Related posts about openldap

Related posts about acl