mirror of
https://git.openldap.org/openldap/openldap.git
synced 2026-01-03 13:40:37 -05:00
document new flag values for identity assertion
This commit is contained in:
parent
2480ae2908
commit
9565ec4bbd
1 changed files with 18 additions and 0 deletions
|
|
@ -231,6 +231,10 @@ permissions, or the asserted identities must have appropriate
|
|||
permissions. Note, however, that the ID assertion feature is mostly
|
||||
useful when the asserted identities do not exist on the remote server.
|
||||
|
||||
Flags can be
|
||||
|
||||
\fBoverride,{prescriptive|non-prescriptive}\fP
|
||||
|
||||
When the
|
||||
.B override
|
||||
flag is used, identity assertion takes place even when the database
|
||||
|
|
@ -239,6 +243,20 @@ with the provided identity, and thus authenticating it, the proxy
|
|||
performs the identity assertion using the configured identity and
|
||||
authentication method.
|
||||
|
||||
When the
|
||||
.B prescriptive
|
||||
flag is used (the default), operations fail with
|
||||
\fIinappropriateAuthentication\fP
|
||||
for those identities whose assertion is not allowed by the
|
||||
.B idassert-authzFrom
|
||||
patterns.
|
||||
If the
|
||||
.B non-prescriptive
|
||||
flag is used, operations are performed anonymously for those identities
|
||||
whose assertion is not allowed by the
|
||||
.B idassert-authzFrom
|
||||
patterns.
|
||||
|
||||
This directive obsoletes
|
||||
.BR idassert-authcDN ,
|
||||
.BR idassert-passwd ,
|
||||
|
|
|
|||
Loading…
Reference in a new issue