![Netscape NETSCAPE DIRECTORY SERVER 6.02 Administrator'S Manual Download Page 231](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-02/netscape-directory-server-6-02_administrators-manual_1674673231.webp)
Access Control Usage Examples
Chapter
6
Managing Access Control
231
Granting Anonymous Access
Most directories are run such that you can anonymously access at least one suffix
for read, search, or compare. For example, you might want to set these permissions
if you are running a corporate personnel directory that you want employees to be
able to search, such as a phonebook. This is the case at
example.com
internally, and
is illustrated in the ACI “Anonymous example.com” example.
As an ISP,
example.com
also wants to advertise the contact information of all of its
subscribers by creating a public phonebook accessible to the world. This is
illustrated in the ACI “Anonymous World” example.
ACI “Anonymous example.com”
In LDIF, to grant read, search, and compare permissions to the entire
example.com
tree to
example.com
employees, you would write the following statement:
aci: (targetattr !="userPassword")(version 3.0; acl "Anonymous
Example"; allow (read, search, compare) userdn= "ldap:///anyone" and
dns="*.example.com";)
This example assumes that the
aci
is added to the
dc=example,dc=com entry
.
Note that the userPassword attribute is excluded from the scope of the ACI.
From the Console, you can set this permission by doing the following:
1.
On the Directory tab, right click the
example.com
node in the left navigation
tree, and choose Set Access Permissions from the pop-up menu to display the
Access Control Manager.
2.
Click New to display the Access Control Editor.
3.
On the Users/Groups tab, in the ACI name field, type "
Anonymous
example.com
". Check that All Users is displayed in the list of users granted
access permission.
4.
On the Rights tab, tick the checkboxes for read, compare, and search rights.
Make sure the other checkboxes are clear.
5.
On the Targets tab, click This Entry to display the
dc=example,dc=com
suffix
in the target directory entry field. In the attribute table, locate the
userPassword
attribute and clear the corresponding checkbox.
All other checkboxes should be ticked. This task is made easier if you click the
Name header to organize the list of attributes alphabetically.
6.
On the Hosts tab, click Add, and in the DNS host filter field, type
*.example.com
. Click OK to dismiss the dialog box.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.02
Page 1: ...Administrator s Guide Netscape Directory Server Version6 02 May 2002 ...
Page 16: ...16 Netscape Directory Server Administrator s Guide May 2002 ...
Page 20: ...20 Netscape Directory Server Administrator s Guide May 2002 ...
Page 74: ...Maintaining Referential Integrity 74 Netscape Directory Server Administrator s Guide May 2002 ...
Page 138: ...Using Referrals 138 Netscape Directory Server Administrator s Guide May 2002 ...
Page 432: ...Miscellaneous Tuning Tips 432 Netscape Directory Server Administrator s Guide May 2002 ...
Page 434: ...434 Netscape Directory Server Administrator s Guide May 2002 ...
Page 468: ...PTA Plug In Syntax Examples 468 Netscape Directory Server Administrator s Guide May 2002 ...
Page 488: ...488 Netscape Directory Server Administrator s Guide May 2002 ...
Page 528: ...Examples of LDAP URLs 528 Netscape Directory Server Administrator s Guide May 2002 ...