@!@
ldap_base=baseConfig['ldap/base']
print 'access to dn="uid=Administrator,cn=users,%s" attrs="krb5Key,userPassword,sambaPwdCanChange,sambaPwdMustChange,sambaLMPassword,sambaNTPassword,sambaPwdLastSet,pwhistory,sambaPasswordHistory,krb5KDCFlags,krb5KeyVersionNumber,krb5PasswordEnd,shadowMax,shadowLastChange,uid,cn,entry"' % (ldap_base, )
print '    by self read'
print '    by group/univentionGroup/uniqueMember="cn=Domain Admins,cn=groups,%s" read' % (ldap_base, )
print '    by * none break'
print
@!@
