Restrict access to totpSeed
[mirror/userdir-ldap.git] / userdir-ldap-slapd.conf.in
index eca64fd..be4988c 100644 (file)
@@ -67,6 +67,10 @@ access to attrs=c,l,loginShell,ircNick,labeledURI,icqUIN,jabberJID,onVacation,bi
 access to attrs=userPassword,sudoPassword,webPassword,rtcPassword,bATVToken
        by * compare
 
+# inaccessible to everybody
+access to attrs=totpSeed
+       by * none
+
 # readable only by self
 access to attrs=sshrsaauthkey
        by self read