Using Roles
178
Red Hat Directory Server Administrator’s Guide • May 2005
• Members of a filtered role are entries that match the filter specified in the
nsRoleFilter
attribute.
• Members of a nested role are members of the roles specified in the
nsRoleDN
attributes of the nested role definition entry.
Table 5-1 lists the new object classes and attributes associated with each type of
role.
Examples: Managed Role Definition
You want to create a role to be assigned to all marketing staff. Run the
ldapmodify
script as follows:
ldapmodify -D "cn=Directory Manager" -w secret -h host -p 389
Specify the managed role as follows:
dn: cn=Marketing,ou=people,dc=example,dc=com
objectclass: top
objectclass: LDAPsubentry
objectclass: nsRoleDefinition
objectclass: nsSimpleRoleDefinition
objectclass: nsManagedRoleDefinition
cn: Marketing
description: managed role for marketing staff
Table 5-1
Object Classes and Attributes for Roles
Role Type
Object Classes
Attributes
Managed Role
nsSimpleRoleDefinition
nsManagedRoleDefinition
Description (optional)
Filtered Role
nsComplexRoleDefinition
nsFilteredRoleDefinitio
n
nsRoleFilter
Description (optional)
Nested Role
nsComplexRoleDefinition
nsNestedRoleDefinition
nsRoleDN
Description (optional)
NOTE
In some cases, you need to protect the value of the
nsRoleDN
attribute with an ACI, as the attribute is writable. For more
information about security and roles, refer to “Using Roles
Securely,” on page 180.
Summary of Contents for DIRECTORY SERVER 7.1
Page 1: ...Administrator s Guide Red Hat Directory Server Version7 1 May 2005 Updated February 2009 ...
Page 20: ...20 Red Hat Directory Server Administrator s Guide May 2005 Glossary 619 Index 635 ...
Page 22: ...22 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 26: ...26 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 78: ...Maintaining Referential Integrity 78 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 200: ...Assigning Class of Service 200 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 488: ...488 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 528: ...PTA Plug in Syntax Examples 528 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 572: ...572 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 612: ...Examples of LDAP URLs 612 Red Hat Directory Server Administrator s Guide May 2005 ...
Page 634: ...634 Red Hat Directory Server Administrator s Guide May 2005 ...