$ sudo grep -Ev '^(#|$)' /etc/openldap/slapd.access.conf
access to dn.exact=""
by * read
access to dn.subtree="cn=Subschema"
by * read
access to dn.regex="^([^,]*,)?ou=[^,]+,(dc=[^,]+(,dc=[^,]+)*)$"
attrs=sambaLMPassword,sambaNTPassword,userPassword,sambaPasswordHistory,sambaPwd
LastSet
by self write
by dn.exact,expand="uid=root,ou=People,$2" write
by group.expand="cn=Domain Controllers,ou=Group,$2" write
by group.expand="cn=Replicator,ou=Group,$2" write
by anonymous auth
by * none
access to dn.regex="^sambaDomainName=([^,]+),(dc=[^,]+(,dc=[^,]+)*)$"
attrs=entry,children,sambaDomain
by dn.exact,expand="uid=root,ou=People,$2" write
by group.expand="cn=Domain Controllers,ou=Group,$2" write
by group.expand="cn=Replicator,ou=Group,$2" write
by users read
by anonymous read
access to dn.regex="^([^,]+,)?ou=People,(dc=[^,]+(,dc=[^,]+)*)$"
attrs=entry,children,posixAccount,sambaSamAccount
by dn.exact,expand="uid=root,ou=People,$2" write
by group.expand="cn=Domain Controllers,ou=Group,$2" write
by group.expand="cn=Replicator,ou=Group,$2" write
by users read
by anonymous read
access to dn.regex="([^,]+,)?ou=People,(dc=[^,]+(,dc=[^,]+)*)$"
attrs=inetOrgPerson,mail
by self write
by dn.exact,expand="uid=root,ou=People,$2" write
by group.expand="cn=Domain Controllers,ou=Group,$2" write
by group.expand="cn=Replicator,ou=Group,$2" write
by users read
by anonymous read
access to dn.regex="^([^,]+,)?ou=Group,(dc=[^,]+(,dc=[^,]+)*)$"
attrs=entry,children,posixGroup,sambaGroupMapping
by dn.exact,expand="uid=root,ou=People,$2" write
by group.expand="cn=Domain Controllers,ou=Group,$2" write
by group.expand="cn=Replicator,ou=Group,$2" write
by users read
by anonymous read
access to dn.regex="^([^,]+,)?ou=Hosts,(dc=[^,]+(,dc=[^,]+)*)$"
attrs=entry,children,posixAccount,inetOrgperson,sambaSamAccount
by dn.exact,expand="uid=root,ou=People,$2" write
by group.expand="cn=Domain Controllers,ou=Group,$2" write
by group.expand="cn=Replicator,ou=Group,$2" write
by users read
by anonymous read
access to dn.regex="^([^,]+,)?ou=Idmap,(dc=[^,]+(,dc=[^,]+)*)$"
attrs=entry,children,sambaIdmapEntry
by dn.exact,expand="uid=root,ou=People,$2" write
by group.expand="cn=Domain Controllers,ou=Group,$2" write
by group.expand="cn=Replicator,ou=Group,$2" write
by users read
by anonymous read
access to dn.regex="^([^,]+,)?ou=Contacts,(dc=[^,]+(,dc=[^,]+)*)$"
attrs=children,entry,inetOrgPerson
by dn.sub,expand="ou=People,$2" write
by group.expand="cn=Replicator,ou=Group,$2" write
by users read
by anonymous read
access to *
by dn="cn=<имя bind-учётки>,dc=<домен>,dc=ru" read
by anonymous auth
by self write
by dn="uid=root,ou=Users,dc=<домен>,dc=ru" write
by * none