Technical Note: Sun Java System Access Manager ACI Guide

Top-Level Help Desk Admin Role ACIs

ACI 1:

aci: (target="ldap:///ROOT_SUFFIX")
(targetfilter=(!(nsroledn=cn=Top-level Admin Role,ROOT_SUFFIX)))
(targetattr= "*") (version 3.0; acl "S1IS Top-level Help Desk Admin Role access allow";
allow (read,search) roledn = "ldap:///cn=Top-level Help Desk Admin Role,ROOT_SUFFIX";)

Members with Top-level Help Desk Admin role:

ACI 2:

aci: (target="ldap:///ROOT_SUFFIX")
(targetfilter=(!(nsroledn=cn=Top-level Admin Role,ROOT_SUFFIX)))
(targetattr= "userPassword") 
(version 3.0; acl "S1IS Top-level Help Desk Admin Role access allow"; allow (write) 
roledn ="ldap:///cn=Top-level Help Desk Admin Role,ROOT_SUFFIX";)

Members with Top-Level Help Desk Admin role: