HP-UX Directory Server Administrator Guide HP-UX Directory Server Version 8.1 (5900-3098, May 2013)

objectClass: top
objectClass: organizationalUnit
ou: Accounting
Because the ACL does not include the dc=example,dc=com subtree, the get effective rights
search shows that the user does not have any rights to the dc=example,dc=com entry:
Example 18 Get effective rights results with no ACL Set (directory manager)
ldapsearch -D "cn=directory manager" -w secret12 -b "dc=example,dc=com" -J,ou=people,dc=example,dc=com
"(objectclass=*)" "*@person"
dn: cn=template_person_objectclass,uid=scarter,ou=people,dc=example,dc=com
objectClass: person
objectClass: top
cn: (template_attribute)
sn: (template_attribute)
description: (template_attribute)
seeAlso: (template_attribute)
telephoneNumber: (template_attribute)
userPassword: (template_attribute)
entryLevelRights: none
attributeLevelRights: sn:none, cn:none, objectClass:none,
description:none, seeAlso:none, telephoneNumber:none, userPassword:none,
6.7.3 Using get effective rights from the console
To view effective rights from the Console:
1. Open the Directory tab, and right-click the entry of which to check the rights.
2. Select Advanced Properties from the drop-down menu.
3. Check the Show effective rights checkbox.
4. Beside each attribute, the attribute-level get effective rights are displayed. The entry-level rights
are shown beneath the entry's DN.
270 Managing Access Control