
Understanding Novell eDirectory
57
no
vd
ocx (
E
NU)
01
F
ebr
ua
ry
200
6
NOTE:
The [Public] trustee is not an object. It is a specialized trustee that represents any network
user, logged in or not, for rights assignment purposes.
1.10.2 eDirectory Rights Concepts
The following concepts can help you better understand eDirectory rights.
•
“Object (Entry) Rights” on page 57
•
“Property Rights” on page 57
•
“Effective Rights” on page 58
•
“How Effective Rights Are Calculated” on page 58
•
“Security Equivalence” on page 60
•
“Access Control List (ACL)” on page 61
•
“Inherited Rights Filter (IRF)” on page 61
Object (Entry) Rights
When you make a trustee assignment, you can grant object rights and property rights. Object rights
apply to manipulation of the entire object, while property rights apply only to certain object
properties. An object right is described as an entry right because it provides an entry into the
eDirectory database.
A description of each object right follows:
• Supervisor
includes all rights to the object and all of its properties.
• Browse
lets the trustee see the object in the tree. It does not include the right to see an object’s
properties.
• Create
applies only when the target object is a container. It allows the trustee to create new
objects below the container and also includes the Browse right.
• Delete
lets the trustee delete the target from the directory.
• Rename
lets the trustee change the name of the target.
Property Rights
When you make a trustee assignment, you can grant object rights and property rights. Object rights
apply to manipulation of the entire object, while property rights apply only to certain object
properties.
iManager gives you two options for managing property rights:
• You can manage all properties at once when the [All Attributes Rights] item is selected.
• You can manage one or more individual properties when the specific property is selected.
A description of each property right follows:
• Supervisor
gives the trustee complete power over the property.
• Compare
lets the trustee compare the value of a property to a given value. This right allows
searching and returns only a true or false result. It does not allow the trustee to actually see the
value of the property.
Summary of Contents for EDIRECTORY 8.8 - GUIDE
Page 4: ...novdocx ENU 01 February 2006...
Page 16: ...16 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 68: ...68 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 90: ...90 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 184: ...184 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 249: ...250 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 307: ...308 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 333: ...334 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 371: ...372 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 439: ...440 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 519: ...520 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 529: ...530 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 555: ...556 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...