OpenLDAP通过groupOfNames进行访问控制

例如所有用户都在ou=Employee,dc=hs,dc=com下

# access control by group member
access to dn.subtree="ou=Employee,dc=hs,dc=com"
	 by groupOfNames="cn=GeneralManager,ou=roles,dc=hs,dc=com" read
	 by groupOfNames="cn=DepartmentManager,ou=roles,dc=hs,dc=com" read
     by self read
     by * auth
# user password visible strategy
access to attrs=userPassword
     by self write
     by * auth
# basic access control
access to * 
     by * read



你可能感兴趣的:(OpenLDAP通过groupOfNames进行访问控制)