![Netscape NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR Administrator'S Manual Download Page 194](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-1-administrator/netscape-directory-server-6-1-administrator_administrators-manual_1674675194.webp)
Access Control Principles
194
Netscape Directory Server Administrator’s Guide • August 2002
Access Control Principles
The mechanism by which you define access is called access control. When the server
receives a request, it uses the authentication information provided by the user in
the bind operation, and the access control instructions (ACIs) defined in the server
to allow or deny access to directory information. The server can allow or deny
permissions such as read, write, search, and compare. The permission level granted
to a user may be dependent on the authentication information provided.
Using access control, you can control access to the entire directory, a subtree of the
directory, specific entries in the directory (including entries defining configuration
tasks), or a specific set of entry attributes. You can set permissions for a specific
user, all users belonging to a specific group or role, or all users of the directory.
Finally, you can define access for a specific location such as an IP address or a DNS
name.
ACI Structure
Access control instructions are stored in the directory, as attributes of entries. The
aci
attribute is an operational attribute; it is available for use on every entry in the
directory, regardless of whether it is defined for the object class of the entry. It is
used by the Directory Server to evaluate what rights are granted or denied when it
receives an LDAP request from a client. The
aci
attribute is returned in an
ldapsearch
operation if specifically requested.
The three main parts of an ACI statement are:
•
Target
•
Permission
•
Bind Rule
The permission and bind rule portions of the ACI are set as a pair, also called an
Access Control Rule (ACR). The specified permission is granted or denied
depending on whether the accompanying rule is evaluated to be true.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR
Page 1: ...Administrator s Guide Netscape Directory Server Version6 1 August 2002...
Page 20: ...20 Netscape Directory Server Administrator s Guide August 2002...
Page 24: ...24 Netscape Directory Server Administrator s Guide August 2002...
Page 142: ...Using Referrals 142 Netscape Directory Server Administrator s Guide August 2002...
Page 440: ...Miscellaneous Tuning Tips 440 Netscape Directory Server Administrator s Guide August 2002...
Page 442: ...442 Netscape Directory Server Administrator s Guide August 2002...
Page 478: ...PTA Plug In Syntax Examples 478 Netscape Directory Server Administrator s Guide August 2002...
Page 498: ...498 Netscape Directory Server Administrator s Guide August 2002...
Page 538: ...Examples of LDAP URLs 538 Netscape Directory Server Administrator s Guide August 2002...