![Netscape NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR Administrator'S Manual Download Page 204](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-1-administrator/netscape-directory-server-6-1-administrator_administrators-manual_1674675204.webp)
Creating ACIs Manually
204
Netscape Directory Server Administrator’s Guide • August 2002
If, however, you target the tree’s branch point
ou=Marketing,dc=example,dc=com
, then all the entries beneath the branch point
that can contain a password attribute are affected by the ACI.
Targeting Both an Entry and Attributes
By default, the entry targeted by an ACI containing a
targetattr
keyword is the
entry on which the ACI is placed. That is, if you put the ACI
aci: (targetattr = "uid")(
access_control_rules
;)
on the
ou=Marketing
,
dc=example,dc=com
entry, then the ACI applies to the
entire Marketing subtree. However, you can also explicitly specify a target using
the
target
keyword as follows:
aci: (target="ldap:///ou=Marketing,
dc=example,dc=com")(targetattr="uid") (
access_control_rules
;)
The order in which you specify the
target
and the
targetattr
keywords is not
important.
Targeting Entries or Attributes Using LDAP Filters
You can use LDAP filters to target a group of entries that match certain criteria. To
do this, you must use the
targetfilter
keyword with an LDAP filter.
The syntax of the
targetfilter
keyword is:
(targetfilter = "
LDAP_filter
")
where
LDAP_filter
is a standard LDAP search filter. For more information on the
syntax of LDAP search filters, see Appendix B, “Finding Directory Entries.”
For example, suppose that all entries in the accounting department include the
attribute- value pair
ou=accounting
, and all entries in the engineering department
include the attribute- value pair
ou=engineering
subtree. To target all the entries
in the accounting and engineering branches of the directory tree, you could use the
following filter:
(targetfilter = "(|(ou=accounting)(ou=engineering))")
This type of filter targets whole entries. You can associate the
targetfilter
and
the
targetattr
keywords to create ACIs that apply to a subset of attributes in the
targeted entries.
The following LDIF example allows members of the Engineering Admins group to
modify the
departmentNumber
and
manager
attributes of all entries in the
Engineering business category. This example uses LDAP filtering to select all
entries with
businessCategory
attributes set to Engineering:
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR
Page 1: ...Administrator s Guide Netscape Directory Server Version6 1 August 2002...
Page 20: ...20 Netscape Directory Server Administrator s Guide August 2002...
Page 24: ...24 Netscape Directory Server Administrator s Guide August 2002...
Page 142: ...Using Referrals 142 Netscape Directory Server Administrator s Guide August 2002...
Page 440: ...Miscellaneous Tuning Tips 440 Netscape Directory Server Administrator s Guide August 2002...
Page 442: ...442 Netscape Directory Server Administrator s Guide August 2002...
Page 478: ...PTA Plug In Syntax Examples 478 Netscape Directory Server Administrator s Guide August 2002...
Page 498: ...498 Netscape Directory Server Administrator s Guide August 2002...
Page 538: ...Examples of LDAP URLs 538 Netscape Directory Server Administrator s Guide August 2002...