The system account needs to be added to an RBAC group. You probably need to add the memberOf attribute manually through LDAP.

image.png

- Y

On Wed, Apr 20, 2022 at 10:55 AM Jim Kinney via FreeIPA-users <freeipa-users@lists.fedorahosted.org> wrote:
I need to compare a number stored on CAC with the one in employeenumber in IdM. I have a non-admin bind user for this and other generic LDAP data access for 3rd party needs. But only the Directory Manager can pull that field.

Is there a permission setting to allow a system account to access that field? The account was created using the method from redhat solutions 4408441.
--
Computers amplify human error
Super computers are really cool_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-leave@lists.fedorahosted.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure