
Creating ACIs Manually
208
Red Hat Directory Server Administrator’s Guide • May 2005
• An attribute value, or a combination of values, that match a specified LDAP
filter, as described in “Targeting Attribute Values Using LDAP Filters,” on
page 213.
The general syntax for a target is:
(
keyword
= "
expression
")
(
keyword
!= "
expression
")
where:
❍
keyword
indicates the type of target.
❍
equal (=) indicates that the target is the object specified in the
expression
,
and not equal (!=) indicates the target is not the object specified in the
expression
.
❍
expression
identifies the target.
The quotation marks ("") around
expression
are required. What you use for
expression
is dependent upon the
keyword
that you supply.
The following table lists each keyword and the associated expressions:
In all cases, you must keep in mind that when you place an ACI on an entry, if it is
not a leaf entry, the ACI also applies to all entries below it. For example, if you
target the entry
ou=accounting,dc=example,dc=com
, the permissions you set
will apply to all entries in the accounting branch of the
example.com
tree.
As a counter example, if you place an ACI on the
ou=accounting,dc=example,dc=com
entry, you cannot target the
uid=sarette,ou=people,dc=example,dc=com
entry because it is not located
under the accounting tree.
Table 6-1
LDIF Target Keywords
Keyword
Valid Expressions
Wildcard
Allowed?
target
ldap:///
distinguished_name
yes
targetattr
attribute
yes
targetfilter
LDAP_filter
yes
targattrfilters
LDAP_operation:LDAP_filter
yes
Summary of Contents for DIRECTORY SERVER 7.1
Page 1: ...Administrator s Guide Red Hat Directory Server Version7 1 May 2005 Updated February 2009 ...
Page 20: ...20 Red Hat Directory Server Administrator s Guide May 2005 Glossary 619 Index 635 ...
Page 22: ...22 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 26: ...26 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 78: ...Maintaining Referential Integrity 78 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 200: ...Assigning Class of Service 200 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 488: ...488 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 528: ...PTA Plug in Syntax Examples 528 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 572: ...572 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 612: ...Examples of LDAP URLs 612 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 634: ...634 Red Hat Directory Server Administrator s Guide May 2005 ...