/usr/share/dirsrv/data/01nsroot.ldif.tmpl is in 389-admin 1.1.46-2.
This file is owned by root:root, with mode 0o644.
The actual contents of the file can be viewed below.
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 | # BEGIN COPYRIGHT BLOCK
# Copyright (C) 2007 Red Hat, Inc.
# All rights reserved.
#
# This program is free software; you can redistribute it and/or
# modify it under the terms of the GNU General Public License
# as published by the Free Software Foundation; version 2
# of the License.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with this program; if not, write to the Free Software
# Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
#
# END COPYRIGHT BLOCK
dn: o=NetscapeRoot
objectClass: top
objectClass: organization
o: NetscapeRoot
aci: (targetattr="*")(version 3.0; acl "Enable Configuration Administrator Group modification"; allow (all) groupdn="ldap:///cn=Configuration Administrators,ou=Groups,ou=TopologyManagement,o=NetscapeRoot";)
aci: (targetattr="*")(targetfilter=(o=NetscapeRoot))(version 3.0; acl "Default anonymous access"; allow (read, search) userdn="ldap:///anyone";)
aci: (targetattr="*")(version 3.0; acl "Enable Group Expansion"; allow (read, search, compare) groupdnattr="uniquemember";)
dn: ou=TopologyManagement,o=NetscapeRoot
objectClass: top
objectClass: organizationalunit
ou: TopologyManagement
description: Branch for Configuration Administration users and groups
aci: (targetattr!="userPassword")(version 3.0; acl "Enable anonymous access"; allow (read, search, compare)userdn="ldap:///anyone";)
dn: ou=Groups,ou=TopologyManagement,o=NetscapeRoot
objectClass: top
objectClass: organizationalunit
ou: Groups
description: Standard Branch for group entries
dn: ou=Administrators,ou=TopologyManagement,o=NetscapeRoot
objectClass: top
objectClass: organizationalunit
ou: Administrators
description: Standard branch for Configuration Administrator (uid) entries
dn: cn=Configuration Administrators,ou=Groups,ou=TopologyManagement,o=NetscapeRoot
objectClass: top
objectClass: groupofuniquenames
cn: Configuration Administrators
uniqueMember: uid=%as_uid%,ou=Administrators,ou=TopologyManagement,o=NetscapeRoot
dn: uid=%as_uid%,ou=Administrators,ou=TopologyManagement,o=NetscapeRoot
objectClass: top
objectClass: person
objectClass: organizationalperson
objectClass: inetorgperson
cn: Configuration Administrator
sn: Administrator
givenName: Configuration
uid: %as_uid%
userPassword: %as_passwd%
dn: ou=%domain%,o=NetscapeRoot
objectClass: top
objectClass: organizationalUnit
objectClass: nsadmindomain
ou: %domain%
description: Standard branch for configuration information
nsAdminDomainName: %domain%
dn: ou=Global Preferences,ou=%domain%,o=NetscapeRoot
objectClass: top
objectClass: organizationalunit
ou: Global Preferences
aci: (targetattr=*)(version 3.0; acl "Enable anonymous access"; allow(read,search) userdn="ldap:///anyone";)
dn: ou=Host Preferences,ou=%domain%,o=NetscapeRoot
objectClass: top
objectClass: organizationalunit
ou: Host Preferences
dn: ou=UserPreferences,ou=%domain%,o=NetscapeRoot
objectClass: top
objectClass: organizationalUnit
ou: UserPreferences
aci: (targetattr = "*")(version 3.0; acl "Allow saving of User Preferences"; allow (add) userdn = "ldap:///all";)
dn: ou=uid\=%as_uid%\,ou\=Administrators\,ou\=TopologyManagement\,o\=NetscapeRoot,ou=UserPreferences,ou=%domain%,o=NetscapeRoot
objectClass: top
objectClass: organizationalUnit
aci: (targetattr=*)(version 3.0; acl "UserDNControl"; allow (all) userdnattr="creatorsname";)
ou: uid=%as_uid%,ou=Administrators,ou=TopologyManagement,o=NetscapeRoot
|