Working With Access Control Instructions
172
Managing Servers with Netscape Console • December 2001
Bind Rules
Bind rules specify the circumstances under which access is allowed or denied. Bind
rules may include any of the following:
•
The user or group granted or denied access permission
•
Host computers from which users are allowed or denied access
•
An interval of time during which a user or group is allowed or denied access
•
The type of permissions to grant or deny to a user or group
ACIs are stored as attributes of the target Directory Server entry. The following
example illustrates the use of two ACIs in the same directory entry. The first ACI
grants unrestricted access to the user directory to all members of the Directory
Administrators group. The second ACI denies access to the user directory to the
Directory Administrators group from 1:00 a.m. to 3:00 a.m. (0100 to 0300) on
Sunday, Tuesday, and Friday. The more restrictive ACI takes control during the
times specified by it. Thus, the end result is that members of the Directory
Administrator’s group can access the user directory at any time except between
1:00 a.m. and 3:00 a.m. on Sunday, Tuesday, and Friday.
Using the ACI Manager and ACI Editor
When you apply ACIs to tasks, user interface elements, or other directory entries,
you use the ACI Manager. When setting access permissions for anything other than
servers in the Netscape Console navigation tree (for instance, tasks or user interface
elements), you use the ACI Editor to create new ACIs and to modify existing ones.
dn: o=example.com
objectClass: top
objectClass: organization
ACI: (target=“ldap:///o=example.com”)(targetattr=*)
(version 3.0; acl “acl 1”; allow (all)
groupdn = “ldap:///cn=Directory Administrators, o=example.com”;)
ACI: (target=”ldap:///o=example.com”)(targetattr=*)
(version 3.0; acl “acl 2”; deny (all)
groupdn = “ldap:///cn=Directory Administrators, o=example.com”
and dayofweek = “Sun, Tues, Fri” and
(timeofday >= “0100” and timeofday <= “0300”);)
Summary of Contents for NETSCAPE CONSOLE 6.0 - MANAGING SERVERS
Page 1: ...Managing Servers with Netscape Console Netscape Console Version6 0 December 2001 ...
Page 18: ...Getting Additional Help 18 Managing Servers with Netscape Console December 2001 ...
Page 20: ...20 Managing Servers with Netscape Console December 2001 ...
Page 40: ...Uninstallation 40 Managing Servers with Netscape Console December 2001 ...
Page 42: ...42 Managing Servers with Netscape Console December 2001 ...
Page 80: ...Working with Netscape Servers 80 Managing Servers with Netscape Console December 2001 ...
Page 110: ...110 Managing Servers with Netscape Console December 2001 ...
Page 118: ...The Netscape Administration Page 118 Managing Servers with Netscape Console December 2001 ...
Page 166: ...166 Managing Servers with Netscape Console December 2001 ...
Page 208: ...Using Client Authentication 208 Managing Servers with Netscape Console December 2001 ...
Page 226: ...Using the Windows NT SNMP Service 226 Managing Servers with Netscape Console December 2001 ...
Page 228: ...228 Managing Servers with Netscape Console December 2001 ...
Page 264: ...Managing Certificates 264 Managing Servers with Netscape Console December 2001 ...
Page 280: ...The SSL Handshake 280 Managing Servers with Netscape Console December 2001 ...
Page 302: ...302 Managing Servers with Netscape Console December 2001 ...