#
access to attr=objectclass
- by * =rs
+ by * =rsc stop
access to filter="objectclass=person" attr=userpassword
by anonymous auth
by self write
access to dn="^.*,ou=Alumni Association,ou=People,o=University of Michigan,c=US$"
- by anonymous auth
- by dn="^.*,o=University of Michigan,c=US$" read
+ by anonymous +x continue
+ by dn="^.*,o=University of Michigan,c=US$" +rsc continue
+ by * stop
access to attr=member
by dnattr=member selfwrite
access to filter="objectclass=rfc822mailgroup"
by dn="Bjorn Jensen,ou=Information Technology Division,ou=People,o=University of Michigan,c=US" write
- by * read
+ by * break
access to * by * read