Add aci to make managed netgroups immutable.

ticket 962
This commit is contained in:
Rob Crittenden
2011-02-17 17:19:24 -05:00
parent 6943acc161
commit 496ab3f738
2 changed files with 6 additions and 1 deletions

View File

@@ -0,0 +1,4 @@
# Don't allow managed netgroups to be modified
dn: cn=ng,cn=alt,$SUFFIX
add:aci: '(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)'