Hello everyone,
I have a question and I'm looking for advice regarding the following scenario.
In our environment, we use a custom objectclass for ISIM persons and we use ACIs to restrict attribute visibility for certain users. So far, so good: only the selected attributes are visible and authorized (R or RW).
Here's the issue: users with lower privileges can still see all attributes (including those that should be hidden from them) by, for example, viewing the "entity" section of a "user data change" request.
The question is: is there a simple way to control which attributes are exposed in db2 logs to lower-privileged users (who belong to a specific ISIM group)?
As always, thanks for your valuable suggestions.
------------------------------
Andrea Gatto
------------------------------