
64
Novell eDirectory 8.8 Administration Guide
n
ov
do
cx (e
n)
11
Ju
ly 20
08
The following process shows how eDirectory calculates DJones’ effective rights to Acctg_Vol:
1. The trustees whose rights are to be considered in the calculation are DJones, Marketing, Tree,
and [Public].
This assumes that DJones doesn’t belong to any groups or roles and has not been explicitly
assigned any security equivalences.
2. The effective rights for each trustee are as follows:
DJones: Zero object, zero all properties
The assignment of zero all property rights at Acctg_Vol overrides the assignment of Write
all properties at Accounting.
Marketing: Zero all properties
The assignment of Write all properties at the top of the tree is filtered out by the IRF at
Accounting.
Tree: No rights
No rights are assigned for Tree anywhere in the pertinent branch of the tree.
[Public]: Browse object, Read all properties
These rights are assigned at the root and aren’t filtered or overridden anywhere in the
pertinent branch of the tree.
3. Combining the rights from all these trustees results in the following:
DJones: Browse object, Read all properties
4. Adding the Compare all properties right that is implied by the Read all properties right, DJones
has the following final effective rights to Acctg_Vol:
DJones: Browse object, Read and Compare all properties
Blocking Effective Rights
Because of the way that effective rights are calculated, it is not always obvious how to block
particular rights from being effective for specific users without resorting to an IRF (an IRF blocks
rights for all users).
To block particular rights from being effective for a user without using an IRF, do either of the
following:
Ensure that neither the user nor any of the objects that the user is security equivalent to ever
gets assigned those rights, either at the target resource or at any level above the target resource
in the tree.
If the user or any object that the user is security equivalent to does get assigned those rights,
ensure that that object also has an assignment lower in the tree that omits those rights. Do this
for every trustee (associated with the user) that has the unwanted rights.
Security Equivalence
Security equivalence means having the same rights as another object. When you make one object
security equivalent to another object, the rights of the second object are added to the rights of the
first object when the system calculates the first object's effective rights.
For example, suppose you make User object Joe security equivalent to the Admin object. After you
create the security equivalence, Joe has the same rights to the tree and file system as Admin.
Summary of Contents for EDIRECTORY 8.8 SP3
Page 4: ...novdocx en 11 July 2008...
Page 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Page 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...