## Root Entry dn: dc=example,dc=com dc: example objectClass: top objectClass: domain aci: (targetattr != "userPassword || passwordHistory || passwordExpirationTime || passwordExpWarned || passwordRetryCount || retryCountResetTime || accountUnlockTime || passwordAllowChangeTime ") (version 3.0; acl "Anonymous access"; allow (read, search, compare)userdn = "ldap:///anyone";) aci: (targetattr != "nsroledn || aci || nsLookThroughLimit || nsSizeLimit || nsTimeLimit || nsIdleTimeout || passwordPolicySubentry || passwordExpirationTime || passwordExpWarned || passwordRetryCount || retryCountResetTime || accountUnlockTime || passwordHistory || passwordAllowChangeTime")(version 3.0; acl "Allow self entry modification except for nsroledn, aci, resource limit attributes, passwordPolicySubentry and password policy state attributes"; allow (write)userdn ="ldap:///self";) ## OUs dn: ou=Groups, dc=example,dc=com objectClass: top objectClass: organizationalunit ou: Groups dn: ou=People, dc=example,dc=com objectClass: top objectClass: organizationalunit ou: People aci: (targetattr ="userpassword || telephonenumber || facsimiletelephonenumber")(version 3.0;acl "Allow self entry modification";allow (write)(userdn = "ldap:///self");) ## Objectclasses ## Groups dn: cn=Group1,ou=Groups,dc=example,dc=com description: Group1 uniqueMember: uid=user2,ou=People,dc=example,dc=com cn: Group1 objectClass: top objectClass: groupOfUniqueNames dn: cn=Group2,ou=Groups,dc=example,dc=com description: Group2 memberURL: ldap:///ou=people,dc=example,dc=com??sub?(sn=testUser) cn: Group2 objectClass: groupOfURLs objectClass: top # Users dn: uid=exampleUser1uid,ou=People,dc=example,dc=com uid: exampleUser1uid description: This is the description for exampleUser1. sn: testUser givenName: User1 cn: cnforexampleUser1 objectClass: top objectClass: organizationalPerson objectClass: person objectClass: inetOrgPerson dn: uid=exampleUser2uid,ou=People,dc=example,dc=com uid: exampleUser2uid description: This is the description for exampleUser2. sn: testUser givenName: User2 telephoneNumber: +1 390 103 6917 cn: cnforexampleUser2 objectClass: top objectClass: inetOrgPerson objectClass: organizationalPerson objectClass: person dn: uid=exampleUser3uid,ou=People,dc=example,dc=com uid: exampleUser3uid description: This is the description for exampleUser3. sn: Hello givenName: User3 cn: cnforexampleUser3 objectClass: top objectClass: inetOrgPerson objectClass: organizationalPerson objectClass: person