diff options
| author | Nathan Kinder <nkinder@redhat.com> | 2010-09-01 10:13:13 -0700 |
|---|---|---|
| committer | Nathan Kinder <nkinder@redhat.com> | 2010-09-01 10:26:20 -0700 |
| commit | 0b9b5e89b5c79d3253e152e1153719a2a5ef8e09 (patch) | |
| tree | 307fd717c1a66265b8697716645748605403c046 /include | |
| parent | b69c76816fc863a17a60c2bf73b5683145b954d1 (diff) | |
| download | ds-Directory_Server_8_2_Branch.tar.gz ds-Directory_Server_8_2_Branch.tar.xz ds-Directory_Server_8_2_Branch.zip | |
Bug 612264 - ACI issue with (targetattr='userPassword')Directory_Server_8_2_Errata_9930_20100901Directory_Server_8_2_Branch
If an ACI has a targetattr of userPassword and uses the USERDN
keyword, the ACI may not be evaluated correctly for password
change operations. This is caused by the fact that we use a
dummy target entry to check if the pasword change is allowed early
in the operation. This dummy entry will not have any attributes
that the ACI may use.
The fix is to actually fetch the target entry with all of it's
attributes. We still create a dummy entry if the target doesn't
exist to prevent returning a no such entry error when we should be
returning an access denied or insufficient access error.
Diffstat (limited to 'include')
0 files changed, 0 insertions, 0 deletions
