![Netscape NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR Administrator'S Manual Download Page 242](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-1-administrator/netscape-directory-server-6-1-administrator_administrators-manual_1674675242.webp)
Access Control Usage Examples
242
Netscape Directory Server Administrator’s Guide • August 2002
c.
Click the Add button to list Self in the list of users who are granted access
permission.
d.
Click OK to dismiss the Add Users and Groups dialog box.
4.
On the Rights tab, tick the checkbox for write. Make sure the other checkboxes
are clear.
5.
On the Hosts tab, click Add to display the Add Host Filter dialog box. In the
DNS host filter field, type
*.example.com
. Click OK to dismiss the dialog box.
6.
To create the value-based filter for roles, switch to manual editing by clicking
the Edit Manually button. Add the following to the beginning of the LDIF
statement:
(targattrfilters="add=nsRoleDN:(nsRoleDN != "cn=superAdmin,
dc=example,dc=com")")
The LDIF statement should read as follows:
(targattrfilters="add=nsRoleDN:(nsRoleDN != "cn=superAdmin,
dc=example,dc=com")") (targetattr = “*”) (target =
"ldap:///dc=example,dc=com") (version 3.0; acl "Roles"; allow
(write) (userdn = "ldap:///self") and (dns="*.example.com");)
7.
Click OK.
The new ACI is added to the ones listed in the Access Control Manager
window.
Granting a Group Full Access to a Suffix
Most directories have a group that is used to identify certain corporate functions.
These groups can be given full access to all or part of the directory. By applying the
access rights to the group, you can avoid setting the access rights for each member
individually. Instead, you grant users these access rights simply by adding them to
the group.
For example, when you install the Directory Server using the Typical Install
process, an Administrators group with full access to the directory is created by
default.
At
example.com
, the Human Resources group is allowed full access to the
ou=example-people
branch of the directory so that they can update the employee
database. This is illustrated in the ACI “HR” example.
ACI “HR”
In LDIF, to grant the HR group all rights on the employee branch of the directory,
you would use the following statement:
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR
Page 1: ...Administrator s Guide Netscape Directory Server Version6 1 August 2002...
Page 20: ...20 Netscape Directory Server Administrator s Guide August 2002...
Page 24: ...24 Netscape Directory Server Administrator s Guide August 2002...
Page 142: ...Using Referrals 142 Netscape Directory Server Administrator s Guide August 2002...
Page 440: ...Miscellaneous Tuning Tips 440 Netscape Directory Server Administrator s Guide August 2002...
Page 442: ...442 Netscape Directory Server Administrator s Guide August 2002...
Page 478: ...PTA Plug In Syntax Examples 478 Netscape Directory Server Administrator s Guide August 2002...
Page 498: ...498 Netscape Directory Server Administrator s Guide August 2002...
Page 538: ...Examples of LDAP URLs 538 Netscape Directory Server Administrator s Guide August 2002...