![Netscape NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR Administrator'S Manual Download Page 229](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-1-administrator/netscape-directory-server-6-1-administrator_administrators-manual_1674675229.webp)
Creating ACIs From the Console
Chapter
6
Managing Access Control
229
Because Boolean expressions are evaluated from left to right, in the first case, bind
rule A is evaluated before bind rule B, and in the second case, bind rule B is
evaluated before bind rule A.
However, the Boolean
NOT
is evaluated before the Boolean
OR
and Boolean
AND
.
Thus, in the following example:
(
bind_rule_A
) AND NOT (
bind_rule_B
)
bind rule B is evaluated before bind rule A despite the left-to-right rule.
Creating ACIs From the Console
You can use the Directory Server Console to view, create, edit, and delete access
control instructions for your directory. This section provides general instructions
for:
•
Displaying the Access Control Editor
•
Viewing Current ACIs
•
Creating a New ACI
•
Editing an ACI
•
Deleting an ACI
See “Access Control Usage Examples,” on page 234 for a collection of access control
rules commonly used in Directory Server security policies, along with step-by-step
instructions for using the Directory Server Console to create them.
The Access Control Editor does not enable you to construct some of the more
complex ACIs when you are in Visual editing mode. In particular, from the Access
Control Editor you cannot:
•
Deny access (see “Permissions Syntax,” on page 210)
•
Create value-based ACIs (see “Targeting Attribute Values Using LDAP
Filters,” on page 205)
•
Define parent access (see “Parent Access (parent Keyword),” on page 214)
•
Create ACIs that contain Boolean bind rules (see “Using Boolean Bind Rules,”
on page 228)
•
Generally, create ACIs that use the following keywords:
roledn
,
userattr
,
authmethod
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR
Page 1: ...Administrator s Guide Netscape Directory Server Version6 1 August 2002...
Page 20: ...20 Netscape Directory Server Administrator s Guide August 2002...
Page 24: ...24 Netscape Directory Server Administrator s Guide August 2002...
Page 142: ...Using Referrals 142 Netscape Directory Server Administrator s Guide August 2002...
Page 440: ...Miscellaneous Tuning Tips 440 Netscape Directory Server Administrator s Guide August 2002...
Page 442: ...442 Netscape Directory Server Administrator s Guide August 2002...
Page 478: ...PTA Plug In Syntax Examples 478 Netscape Directory Server Administrator s Guide August 2002...
Page 498: ...498 Netscape Directory Server Administrator s Guide August 2002...
Page 538: ...Examples of LDAP URLs 538 Netscape Directory Server Administrator s Guide August 2002...