Thursday, December 18, 2025

[389-users] no ACI's configured, unprivileged account returns results with memberof=cn=group... query but not via cn=group

On a SLES 15 SP6 host with
389-ds-2.2.10~git146.78a60e3ac-150600.8.23.1.x86_64, I was surprised
to find that on a new instance without any ACI's configured a
non-privileged account could return results with an ldap query if the
filter was "(memberof=CN=group,...)" even though the same account
returns nothing using a filter of "(cn=group)". Is this expected? If
so, how do I disable this behavior?

I don't believe it matters but the non-privileged account is
authenticating with GSSAPI using the following sasl mapping:

nsSaslMapBaseDNTemplate: dc=corp,dc=org
nsSaslMapFilterTemplate: (cn=\1)
nsSaslMapRegexString: \(.*\)@\(.*\)\.\(.*\)

Bob
--
_______________________________________________
389-users mailing list -- 389-users@lists.fedoraproject.org
To unsubscribe send an email to 389-users-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue

No comments:

Post a Comment