Oracle Fusion Middleware Administration Guide for Oracle Directory Server Enterprise Edition

Access Control and the Retro Change Log

The retro change log supports search operations. It is optimized for searches that include filters of this form:


(&(changeNumber>=X)(changeNumber<=Y))

As a general rule, do not perform add or modify operations on the retro change log entries. You can delete entries to trim the size of the log. The only time that you need to perform a modify operation on the retro change log is to modify the default access control policy.

When the retro change log is created, by default, the following access control rules apply:

To modify the default access control policy that applies to the retro change log, modify the aci attribute of the cn=changelog entry. Refer to Chapter 6, Directory Server Access Control.