SLAPD.ACCESS(5) File Formats Manual SLAPD.ACCESS(5) (NAME) slapd.access - slapd LDAP (SYNOPSIS) /etc/openldap/slapd.conf (DESCRIPTION) slapd.conf(5) slapd(8) . SLAPD slapacl(8) slapadd(8) slapauth(8) slapcat(8) slapdn(8) slapindex(8) slapmodify(8) slaptest(8) . slapd.conf slapd ( ) . slapd.conf : # comment - these options apply to every database # first database definition & configuration options database # subsequent database definitions & configuration options ... . (naming context) . . rootdn ( "access to * by * read"). access to * by * none . (default read) . : rootdn ! ( root DSE) . <> . (THE ACCESS DIRECTIVE) : access to [ by [ ] [ ] ]+ ( ) / ( ) ( ). slapd.conf . . . . by * none stop . . by * break . access to * by * none . (THE FIELD) . : dn[.]= filter= attrs=[ val[/matchingRule][.]=] ={{exact|base(object)}|regex |one(level)|sub(tree)|children} ={|[{!|@}]}[,] ={{exact|base(object)}|regex |one(level)|sub(tree)|children} dn= (naming context) . DN . * dn . . Base ( baseObject) exact ( base) DN one ( onelevel) sub ( subtree) children () . regex POSIX ( <>) regex(7) / re_format(7) DN . regex () UTF-8 . filter= LDAP RFC 4515 . filter (objectClass=*) . attrs= . entry children . ObjectClass / objectClass . @ objectClass . ! objectClass objectClass . attrs attrs=@extensibleObject . attrs= val[/matchingRule][.]= . . exact () (equality matching rule) ( ) . regex POSIX ( <>) . DN base onelevel subtree children base onelevel subtree children . dn filter attrs . regex ${v} . $ ${d} dnpattern . (THE FIELD) . . : * anonymous users self[.] dn[.[,]]= dnattr= realanonymous realusers realself[.] realdn[.[,]]= realdnattr= group[/[/]] [.]= peername[.]= sockname[.