mirror of
https://github.com/opencloud-eu/opencloud-compose.git
synced 2026-06-08 20:20:04 +08:00
fix: fix #104 - LDAP userPassword attribute can be read without auth
This commit is contained in:
12
config/ldap/ldif/50_acls.ldif
Normal file
12
config/ldap/ldif/50_acls.ldif
Normal file
@@ -0,0 +1,12 @@
|
||||
# OpenCloud ldap acl file which gets applied during the first db initialisation
|
||||
dn: olcDatabase={2}mdb,cn=config
|
||||
changetype: modify
|
||||
replace: olcAccess
|
||||
olcAccess: {0}to dn.subtree="dc=opencloud,dc=eu" attrs=entry,uid,objectClass,entryUUID
|
||||
by * read
|
||||
olcAccess: {1}to attrs=userPassword
|
||||
by self write
|
||||
by * auth
|
||||
olcAccess: {2}to *
|
||||
by dn.base="uid=admin,ou=users,dc=opencloud,dc=eu" write
|
||||
by * none
|
||||
Reference in New Issue
Block a user