QUIPU question

m.abbott@frsow.bull.fr Mon, 06 February 1995 08:53 UTC

Received: from ietf.nri.reston.va.us by IETF.CNRI.Reston.VA.US id aa00359; 6 Feb 95 3:53 EST
Received: from CNRI.Reston.VA.US by IETF.CNRI.Reston.VA.US id aa00355; 6 Feb 95 3:53 EST
Received: from haig.cs.ucl.ac.uk by CNRI.Reston.VA.US id aa00811; 6 Feb 95 3:53 EST
Received: from bells.cs.ucl.ac.uk by haig.cs.ucl.ac.uk with local SMTP id <g.10983-0@haig.cs.ucl.ac.uk>; Mon, 6 Feb 1995 08:11:52 +0000
Received: from gwx400a.bull.fr by bells.cs.ucl.ac.uk with Internet SMTP id <g.04430-0@bells.cs.ucl.ac.uk>; Mon, 6 Feb 1995 08:11:43 +0000
Received: from thot.frso.bull.fr by kheops.bull.fr; Mon, 6 Feb 1995 08:49:27 +0100 (MET)
Received: by thot.frso.bull.fr (AIX 3.2/UCB 5.64/4.03) id AA20842; Mon, 6 Feb 1995 07:43:54 +0100
Return-Path: m.abbott@frsow.bull.fr
X400-Trace: FR*ATLAS*BULL; arrival.Mon,.06.Feb.95.07:40:49.GMT action.relayed
Sender: ietf-archive-request@IETF.CNRI.Reston.VA.US
From: m.abbott@frsow.bull.fr
X400-Recipients: osi-ds@cs.ucl.ac.uk
To: osi-ds@cs.ucl.ac.uk
X400-Mts-Identifier: [FR*ATLAS*BULL;FRSO-horus :eT1:+8RBj0-]
Date: Mon, 06 Feb 95 07:40:49 GMT
Message-Id: <ma/95-0104>
Sensitivity: private
Original-Encoded-Information-Types: IA5_Text
Content-Identifier: ma/95-0104
X400-Content-Type: P2-1984 (2)
Subject: QUIPU question

P2-body: IA5Text


Hello,

I am having a problem with a QUIPU DSA that I can't
seem to resolve. If anyone has any suggestions they
would be welcomed.

Thank you,

Michael Abbott
m.abbott@frsow.bull.fr

The DSA (quipu 8.0) is a small test and is not connected
to any other DSA. The DSA is master of all EDB's and the
structure is the following:

cn=orion (the DSA)
o=myorg
o=myorg@c=fr
o=myorg@c=us
o=myorg@cn=emma (the DSA manager)
o=myorg@c=fr@ou=paris
o=myorg@c=fr@ou=paris@cn=Michael Abbott

Default ACL's are used throughout the DIT. The problem is
that with dish if I logon to the DSA as an anonymous user
the directory will not let me do a search of the type:

search "cn=abbott*" -subtree (positioned at o=myorg)

The following error is returned:

*** Service error: Unwilling to perform ***

The following search succeeds:

search "cn=abbott*" -subtree (positioned at o=myorg@c=fr)

I can; however, list, move throught the hieracrchy and perform singal 
level with no problem. If I logon as the manager, "o=myorg@cn=emma", 
the DSA allows a subtree search from any position in the DIT. What is 
the mechanism in operation here? Is there a way to allow subtree 
searches for the anonymous user from the "o=myorg" level?