![Netscape NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR Administrator'S Manual Download Page 222](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-1-administrator/netscape-directory-server-6-1-administrator_administrators-manual_1674675222.webp)
Bind Rules
222
Netscape Directory Server Administrator’s Guide • August 2002
For example,
userattr = "parent[0,1].manager#USERDN"
This bind rule is evaluated to be true if the bindDN matches the manager attribute
of the targeted entry. The permissions granted when the bind rule is evaluated to
be true apply to the target entry and to all entries immediately below it.
Example With userattr Inheritance
The example in Figure 6-1 indicates that user
bjensen
is allowed to read and
search the
cn=Profiles
entry as well as the first level of child entries which
includes
cn=mail
and
cn=news
, thus allowing her to search through her own mail
and news IDs.
Figure 6-1
Using Inheritance With the
userattr
Keyword
In this example, if you did not use inheritance you would have to do one of the
following to achieve the same result:
•
Explicitly set read and search access for user
bjensen
on the
cn=Profiles
,
cn=mail
, and
cn=news
entries in the directory.
•
Add the owner attribute with a value of
bjensen
to the
cn=mail
and
cn=news
entries and then add the following ACI to the
cn=mail
and
cn=news
entries.
aci: (targetattr="*") (version 3.0; acl "profiles access"; allow
(read,search) userattr="owner#USERDN";)
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR
Page 1: ...Administrator s Guide Netscape Directory Server Version6 1 August 2002...
Page 20: ...20 Netscape Directory Server Administrator s Guide August 2002...
Page 24: ...24 Netscape Directory Server Administrator s Guide August 2002...
Page 142: ...Using Referrals 142 Netscape Directory Server Administrator s Guide August 2002...
Page 440: ...Miscellaneous Tuning Tips 440 Netscape Directory Server Administrator s Guide August 2002...
Page 442: ...442 Netscape Directory Server Administrator s Guide August 2002...
Page 478: ...PTA Plug In Syntax Examples 478 Netscape Directory Server Administrator s Guide August 2002...
Page 498: ...498 Netscape Directory Server Administrator s Guide August 2002...
Page 538: ...Examples of LDAP URLs 538 Netscape Directory Server Administrator s Guide August 2002...