summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorNalin Dahyabhai <nalin.dahyabhai@pobox.com>2008-06-09 18:58:29 -0400
committerNalin Dahyabhai <nalin.dahyabhai@pobox.com>2008-06-09 18:58:29 -0400
commit05e84c23677dcdb6823cf7929ecd2b3efe58c83c (patch)
tree685d22bb81a0cc344940f78605a0a967837314bf
parent91296180405086d4e840db85efee86fb3cb00533 (diff)
downloadslapi-nis-05e84c23677dcdb6823cf7929ecd2b3efe58c83c.tar.gz
slapi-nis-05e84c23677dcdb6823cf7929ecd2b3efe58c83c.tar.xz
slapi-nis-05e84c23677dcdb6823cf7929ecd2b3efe58c83c.zip
- drop the bit about the local securenets file
-rw-r--r--doc/design.txt12
1 files changed, 7 insertions, 5 deletions
diff --git a/doc/design.txt b/doc/design.txt
index 05f9130..ecff7ef 100644
--- a/doc/design.txt
+++ b/doc/design.txt
@@ -108,16 +108,18 @@ Because connected clients may not always transmit an entire request at
once, and because the server may find itself unable to transmit an
entire response at once, it buffers traffic for connected clients,
multiplexing the work it does for all of its clients from inside of the
-thread.] The actual protocol datagram parsing is performed by libnsl,
+thread. The actual protocol datagram parsing is performed by libnsl,
which is provided as a part of the C library.
Client requests are limited by the local tcp_wrappers configuration on
the directory server.
-[Unless explicitly disabled in the module's configuration or in a
- map's configuration, the local /etc/securenets file is consulted to
- control access to map information to specific clients. The list of
- securenet entries can also be stored in the module or map.]
+Access control can be performed based on a client's address using
+"nis-plugin-securenet" settings in the module's configuration entry.
+If no values are specified, access is allowed to all clients. If values
+in the form "netmask address" (for example, "255.0.0.0 127.0.0.0") are
+found, then access will only be allowed to clients on the designated
+networks.
== Map Cache ==