1999-09-09 06:52:19 +08:00
|
|
|
# $OpenLDAP$
|
1998-08-09 08:43:13 +08:00
|
|
|
#
|
|
|
|
# master slapd config -- for testing
|
|
|
|
#
|
2000-09-04 07:48:35 +08:00
|
|
|
ucdata-path ./ucdata
|
2000-05-30 00:39:16 +08:00
|
|
|
include ./schema/core.schema
|
|
|
|
include ./schema/cosine.schema
|
|
|
|
include ./schema/inetorgperson.schema
|
2001-12-20 07:41:31 +08:00
|
|
|
include ./schema/openldap.schema
|
2003-08-08 00:42:40 +08:00
|
|
|
include ./schema/nis.schema
|
1999-01-22 02:08:33 +08:00
|
|
|
pidfile ./test-db/slapd.pid
|
|
|
|
argsfile ./test-db/slapd.args
|
1998-08-09 08:43:13 +08:00
|
|
|
|
2001-09-01 13:01:31 +08:00
|
|
|
# global ACLs
|
|
|
|
access to dn.base="" attr=objectClass by users read
|
|
|
|
access to * by * read
|
|
|
|
|
2003-04-30 11:04:18 +08:00
|
|
|
modulepath ../servers/slapd/back-@BACKEND@/
|
|
|
|
@MODULELOAD@
|
|
|
|
|
1998-08-09 08:43:13 +08:00
|
|
|
#######################################################################
|
|
|
|
# ldbm database definitions
|
|
|
|
#######################################################################
|
|
|
|
|
2000-10-02 06:46:52 +08:00
|
|
|
database @BACKEND@
|
2002-01-14 11:42:24 +08:00
|
|
|
#ldbm#cachesize 0
|
2001-12-06 15:32:53 +08:00
|
|
|
suffix "o=University of Michigan,c=US"
|
1998-08-09 08:43:13 +08:00
|
|
|
directory ./test-db
|
2001-12-06 15:32:53 +08:00
|
|
|
rootdn "cn=Manager,o=University of Michigan,c=US"
|
1998-08-09 08:43:13 +08:00
|
|
|
rootpw secret
|
2001-08-01 12:50:47 +08:00
|
|
|
#ldbm#index objectClass eq
|
|
|
|
#ldbm#index cn,sn,uid pres,eq,sub
|
2001-10-04 05:27:37 +08:00
|
|
|
#bdb#index objectClass eq
|
|
|
|
#bdb#index cn,sn,uid pres,eq,sub
|
1999-07-05 14:26:26 +08:00
|
|
|
|
1999-07-16 10:45:46 +08:00
|
|
|
#
|
2003-02-25 01:15:31 +08:00
|
|
|
# normal installations should protect root dse, cn=monitor, cn=subschema
|
1999-07-16 10:45:46 +08:00
|
|
|
#
|
|
|
|
|
2002-07-11 09:45:22 +08:00
|
|
|
access to dn="" by * read
|
|
|
|
access to dn.base="" by * read
|
|
|
|
|
1998-08-09 08:43:13 +08:00
|
|
|
access to attr=objectclass
|
1999-10-22 05:23:43 +08:00
|
|
|
by * =rsc stop
|
1999-07-05 14:26:26 +08:00
|
|
|
|
2002-01-04 02:31:18 +08:00
|
|
|
access to filter="(objectclass=person)" attr=userpassword
|
1999-07-05 14:26:26 +08:00
|
|
|
by anonymous auth
|
1999-10-22 02:48:16 +08:00
|
|
|
by self write
|
1999-07-05 14:26:26 +08:00
|
|
|
|
2001-12-06 15:32:53 +08:00
|
|
|
access to dn.children="ou=Alumni Association,ou=People,o=University of Michigan,c=US"
|
2000-06-13 11:24:12 +08:00
|
|
|
by dn.regex=".+,o=University of Michigan,c=US" +c continue
|
2001-12-06 15:32:53 +08:00
|
|
|
by dn.subtree="o=University of Michigan,c=US" +rs continue
|
1999-10-22 05:23:43 +08:00
|
|
|
by * stop
|
1999-07-05 14:26:26 +08:00
|
|
|
|
1998-08-09 08:43:13 +08:00
|
|
|
access to attr=member
|
|
|
|
by dnattr=member selfwrite
|
|
|
|
by * read
|
1999-07-05 14:26:26 +08:00
|
|
|
|
2002-03-24 09:55:11 +08:00
|
|
|
access to attr=member filter=(mail=*edu)
|
|
|
|
by * read
|
|
|
|
|
2002-01-04 02:31:18 +08:00
|
|
|
access to filter="(objectclass=groupofnames)"
|
2001-12-07 09:54:53 +08:00
|
|
|
by dn.base="cn=Bjorn Jensen,ou=Information Technology Division,ou=People,o=University of Michigan,c=US" =sc continue
|
2003-05-30 13:24:39 +08:00
|
|
|
by dn.regex="^cn=Bjorn Jensen,ou=Information Technology Division,ou=People,o=University of Michigan,c=US$" +rw stop
|
1999-10-22 05:23:43 +08:00
|
|
|
by * break
|
1999-07-05 14:26:26 +08:00
|
|
|
|
2002-09-13 23:04:04 +08:00
|
|
|
access to dn.children="ou=Information Technology Division,ou=People,o=University of Michigan,c=US"
|
|
|
|
by group.exact="cn=ITD Staff,ou=Groups,o=University of Michigan,c=US" write
|
|
|
|
by * read
|
|
|
|
|
2002-03-02 02:58:11 +08:00
|
|
|
access to filter="(name=X*Y*Z)"
|
|
|
|
by * continue
|
|
|
|
|
2001-09-01 13:01:31 +08:00
|
|
|
# fall into global ACLs
|