Assigning Class of Service
172
Netscape Directory Server Administrator’s Guide • May 2002
To prevent users from removing the
nsRoleDN
attribute, use the following ACIs
depending upon the type of role being used.
Managed roles.
For entries that are members of a managed role, use the following
ACI to prevent users from unlocking themselves by removing the appropriate
nsRoleDN
:
aci: (targetattr=”nsRoleDN”)
(targattrfilters=”
add=nsRoleDN:(!(nsRoleDN=cn=AdministratorRole,dc=example,dc=com))
,
del=nsRoleDN:(!(nsRoleDN=cn=nsManagedDisabledRole,dc=example,dc=c
om))”)
(version3.0;aci “allow mod of nsRoleDN by self
but not to critical values”;
allow(write)
userdn=”ldap:///self”;)
Filtered roles
. The attributes that are part of the filter should be protected so that
the user cannot relinquish the filtered role by modifying an attribute. The user
should not be allowed to add, delete, and modify the attribute used by the filtered
role. If the value of the filter attribute is computed, then all attributes that can
modify the value of the filter attribute should be protected in the same way.
Nested roles.
A nested role is comprised of filtered and managed roles, so the
above points should be considered for each of the roles that comprise the nested
role.
For more information about account inactivation, see “Inactivating Users and
Roles,” on page 268.
Assigning Class of Service
A class of service (CoS) allows you to share attributes between entries in a way that
is transparent to applications. CoS simplifies entry management and reduces
storage requirements.
There are two methods for creating and managing CoS, using the Directory Server
Console or through the command line. The following sections describe CoS in
more detail and provide the procedures for managing CoS through both the
console and the command line:
•
About CoS
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.02
Page 1: ...Administrator s Guide Netscape Directory Server Version6 02 May 2002 ...
Page 16: ...16 Netscape Directory Server Administrator s Guide May 2002 ...
Page 20: ...20 Netscape Directory Server Administrator s Guide May 2002 ...
Page 74: ...Maintaining Referential Integrity 74 Netscape Directory Server Administrator s Guide May 2002 ...
Page 138: ...Using Referrals 138 Netscape Directory Server Administrator s Guide May 2002 ...
Page 432: ...Miscellaneous Tuning Tips 432 Netscape Directory Server Administrator s Guide May 2002 ...
Page 434: ...434 Netscape Directory Server Administrator s Guide May 2002 ...
Page 468: ...PTA Plug In Syntax Examples 468 Netscape Directory Server Administrator s Guide May 2002 ...
Page 488: ...488 Netscape Directory Server Administrator s Guide May 2002 ...
Page 528: ...Examples of LDAP URLs 528 Netscape Directory Server Administrator s Guide May 2002 ...