Thursday, December 18, 2025

[389-users] Re: no ACI's configured, unprivileged account returns results with memberof=cn=group... query but not via cn=group

Please ignore this email for now. I may have applied an ACI rule and
need to do some more testing. I apologize for the spam

On Thu, Dec 18, 2025 at 3:29 PM Bob Green <wood.green.robert@gmail.com> wrote:
>
> On a SLES 15 SP6 host with
> 389-ds-2.2.10~git146.78a60e3ac-150600.8.23.1.x86_64, I was surprised
> to find that on a new instance without any ACI's configured a
> non-privileged account could return results with an ldap query if the
> filter was "(memberof=CN=group,...)" even though the same account
> returns nothing using a filter of "(cn=group)". Is this expected? If
> so, how do I disable this behavior?
>
> I don't believe it matters but the non-privileged account is
> authenticating with GSSAPI using the following sasl mapping:
>
> nsSaslMapBaseDNTemplate: dc=corp,dc=org
> nsSaslMapFilterTemplate: (cn=\1)
> nsSaslMapRegexString: \(.*\)@\(.*\)\.\(.*\)
>
> Bob
--
_______________________________________________
389-users mailing list -- 389-users@lists.fedoraproject.org
To unsubscribe send an email to 389-users-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue

No comments:

Post a Comment