2010-12-11 10:02:08 -06:00
|
|
|
# Replica administration
|
|
|
|
|
2011-02-25 17:23:10 -06:00
|
|
|
dn: cn=config
|
|
|
|
changetype: modify
|
|
|
|
add: aci
|
|
|
|
aci: (targetattr != aci)(version 3.0; aci "replica admins read access"; allow (read, search, compare) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,$SUFFIX";)
|
|
|
|
|
2010-12-11 10:02:08 -06:00
|
|
|
dn: cn="$SUFFIX",cn=mapping tree,cn=config
|
|
|
|
changetype: modify
|
|
|
|
add: aci
|
2011-01-31 10:01:56 -06:00
|
|
|
aci: (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,$SUFFIX";)
|
2010-12-11 10:02:08 -06:00
|
|
|
|
|
|
|
dn: cn="$SUFFIX",cn=mapping tree,cn=config
|
|
|
|
changetype: modify
|
|
|
|
add: aci
|
2011-01-31 10:01:56 -06:00
|
|
|
aci: (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,$SUFFIX";)
|
2010-12-20 09:05:17 -06:00
|
|
|
|
|
|
|
dn: cn="$SUFFIX",cn=mapping tree,cn=config
|
|
|
|
changetype: modify
|
|
|
|
add: aci
|
2011-01-31 10:01:56 -06:00
|
|
|
aci: (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,$SUFFIX";)
|
2010-12-20 09:05:17 -06:00
|
|
|
|
2013-03-01 14:02:14 -06:00
|
|
|
dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config
|
|
|
|
changetype: modify
|
|
|
|
add: aci
|
|
|
|
aci: (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,$SUFFIX";)
|
|
|
|
|
2012-09-17 10:45:42 -05:00
|
|
|
dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config
|
|
|
|
changetype: modify
|
|
|
|
add: aci
|
|
|
|
aci: (targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,$SUFFIX";)
|
|
|
|
|
2010-12-20 22:34:00 -06:00
|
|
|
dn: cn=tasks,cn=config
|
|
|
|
changetype: modify
|
|
|
|
add: aci
|
2011-01-31 10:01:56 -06:00
|
|
|
aci: (targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,$SUFFIX";)
|