software-infrastructure/roles/ericomeehan.openldap.eom.dev/files/allowpwchange.ldif
2024-07-08 12:26:06 -04:00

7 lines
416 B
Plaintext

dn: olcDatabase={1}mdb,cn=config
changetype: modify
replace: olcAccess
olcAccess: {0}to attrs=cn,givenName,sn,userPassword,shadowLastChange,mail,loginShell,photo by self write by anonymous auth by dn.base="cn=Manager,dc=eom,dc=dev" write by * none
olcAccess: {1}to * by self read by dn.base="cn=Manager,dc=eom,dc=dev" write by * read
olcAccess: {2}to * by dn.base="uid=reader,ou=service accounts,dc=eom,dc=dev" read