How should we handle 'aci' for the Fedora DS backend

Jelmer Vernooij jelmer at
Sat Dec 22 02:32:40 GMT 2007

Am Freitag, den 21.12.2007, 16:25 +1100 schrieb Andrew Bartlett:
> While I wait for Samba4 and OpenLDAP CVS to agree with each other again,
> I've moved on to Fedora DS.
> I needed this patch to make it work - defining the 'aci' attribute in
> Samba4's schema, so that we don't reject this attribute on the
> pass-though to Fedora DS.
> In the past this has not been a problem, because we didn't check for
> valid attribute names. 
> However, this makes it a valid attribute in the rest of the schema,
> which is also less desirable :-(
> Perhaps we should be trying to set the default aci (it only applies to
> the root entry, and really is a complete hack) another way?
Just a custom Fedora-DS specific function in the provisioning script


Jelmer Vernooij <jelmer at> -
Jabber: jelmer at
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 307 bytes
Desc: Dies ist ein digital signierter Nachrichtenteil
Url :

More information about the samba-technical mailing list