@!@
ldap_base = configRegistry['ldap/base']
print('access to dn="uid=Administrator,cn=users,%s" attrs="krb5Key,userPassword,sambaPwdCanChange,sambaPwdMustChange,sambaLMPassword,sambaNTPassword,sambaPwdLastSet,pwhistory,sambaPasswordHistory,krb5KDCFlags,krb5KeyVersionNumber,krb5PasswordEnd,shadowMax,shadowLastChange,uid,cn,entry"' % (ldap_base, ))
print('    by self read')
print('    by group/univentionGroup/uniqueMember="cn=Domain Admins,cn=groups,%s" read' % (ldap_base, ))
print('    by * none break')
print('')
@!@
