![Netscape Certificate Management System 6.2 Administrator'S Manual Download Page 347](http://html1.mh-extra.com/html/netscape/certificate-management-system-6-2/certificate-management-system-6-2_administrators-manual_1674697347.webp)
Authorization for CMS Users
Chapter
8
Authorization
347
As you can see, there usually is not a need to include a deny statement. There
might, however, be cases where you would need to specify one. For example, say
that user
JohnB
has just been fired.
JohnB
was a member of the Administrators
Group. You might want to specifically deny access to
JohnB
if you cannot delete
the user immediately. Another case might be that you want to set the user
BrianC
up as an administrator, but you do not want him to be able to change some
resource. Since you do want to allow the Administrators group access to this
resource, you could specifically deny access to
BrianC
by creating an ACI that
denies this user access.
Operations
When you are creating an ACI, you specify the operation that this ACI is allowing
or denying. To allow or deny access to more than one operator in a single ACI,
select the first operator from the list, and then hold down Ctrl while selecting other
operators.
Syntax
The syntax field of the ACI editor is where you specify the evaluator for the
expression. The ACL feature allows for the evaluator types of group, name, and IP
address. You add one of these along with the name of the entity, separated by
either by
=
(equals) or
!=
(does not equal).
Group Syntax
The syntax for a group is:
group=”groupname”
to specify that the group named is to be allowed or denied
access to the operation specified.
group!=”groupname”
to specify that any group except for the group named is to be
allowed or denied access to the operation specified.
For example:
group=”Administrators”
group!=”Auditors”
User Syntax
The syntax for a user is:
user=”userID”
to specify that the user ID named is to be allowed or denied access
to the operation specified.
user!=”userID”
to specify that any user ID except for the user ID named is to be
allowed or denied access to the operation specified.
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...