![Netscape NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR Administrator'S Manual Download Page 176](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-1-administrator/netscape-directory-server-6-1-administrator_administrators-manual_1674675176.webp)
Assigning Class of Service
176
Netscape Directory Server Administrator’s Guide • August 2002
To prevent users from removing the
nsRoleDN
attribute, use the following ACIs
depending upon the type of role being used.
Managed roles.
For entries that are members of a managed role, use the following
ACI to prevent users from unlocking themselves by removing the appropriate
nsRoleDN
:
aci: (targetattr=”nsRoleDN”)
(targattrfilters=”
add=nsRoleDN:(!(nsRoleDN=cn=AdministratorRole,dc=example,dc=com))
,
del=nsRoleDN:(!(nsRoleDN=cn=nsManagedDisabledRole,dc=example,dc=c
om))”)
(version3.0;aci “allow mod of nsRoleDN by self
but not to critical values”;
allow(write)
userdn=”ldap:///self”;)
Filtered roles.
The attributes that are part of the filter should be protected so that
the user cannot relinquish the filtered role by modifying an attribute. The user
should not be allowed to add, delete, and modify the attribute used by the filtered
role. If the value of the filter attribute is computed, then all attributes that can
modify the value of the filter attribute should be protected in the same way.
Nested roles.
A nested role is comprised of filtered and managed roles, so the
above points should be considered for each of the roles that comprise the nested
role.
For more information about account inactivation, see “Inactivating Users and
Roles,” on page 272.
Assigning Class of Service
A class of service (CoS) allows you to share attributes between entries in a way that
is transparent to applications. CoS simplifies entry management and reduces
storage requirements.
There are two methods for creating and managing CoS, using the Directory Server
Console or through the command line. The following sections describe CoS in
more detail and provide the procedures for managing CoS through both the
console and the command line:
•
About CoS
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR
Page 1: ...Administrator s Guide Netscape Directory Server Version6 1 August 2002...
Page 20: ...20 Netscape Directory Server Administrator s Guide August 2002...
Page 24: ...24 Netscape Directory Server Administrator s Guide August 2002...
Page 142: ...Using Referrals 142 Netscape Directory Server Administrator s Guide August 2002...
Page 440: ...Miscellaneous Tuning Tips 440 Netscape Directory Server Administrator s Guide August 2002...
Page 442: ...442 Netscape Directory Server Administrator s Guide August 2002...
Page 478: ...PTA Plug In Syntax Examples 478 Netscape Directory Server Administrator s Guide August 2002...
Page 498: ...498 Netscape Directory Server Administrator s Guide August 2002...
Page 538: ...Examples of LDAP URLs 538 Netscape Directory Server Administrator s Guide August 2002...