
Chapter 6. Managing Access Control
196
6.9.7.1. ACI "Billing Info Read"
In LDIF, to grant subscribers permission to read billing information in their own entry, write the
following statement:
aci: (targetattr="connectionTime || accountBalance") (version
3.0; acl "Billing Info Read"; allow (search,read) userdn=
"ldap:///self";)
This example assumes that the relevant attributes have been created in the schema and that the ACI
is added to the
ou=subscribers,dc=example,dc=com
entry.
From the Console, set this permission by doing the following:
1. In the
Directory
tab, right-click the
Subscribers
entry under the
example.com
node in the
left navigation tree, and choose
Set Access Permissions
from the pop-up menu to display the
Access Control Manager
.
2. Click
New
to display the
Access Control Editor
.
3. In the
Users/Groups
tab, in the
ACI name
field, type
Billing Info Read
. In the list of users
granted access permission, do the following:
a. Select and remove
All Users
, then click
Add
.
The
Add Users and Groups
dialog box opens.
b. Set the
Search
area in the
Add Users and Groups
dialog box to
Special Rights
, and
select
Self
from the search results list.
c. Click the
Add
button to list
Self
in the list of users who are granted access permission.
d. Click
OK
to dismiss the
Add Users and Groups
dialog box.
4. In the
Rights
tab, select the checkboxes for
search
and
read
rights. Make sure the other
checkboxes are clear.
5. In the
Targets
tab, click
This Entry
to display the
ou=subscribers, dc=example,dc=com
suffix in the
Target directory entry
field. In the attribute table, select the checkboxes for the
connectionTime
and
accountBalance
attributes.
All other checkboxes should be clear; if it is made easier, click the
Check None
button to clear
the checkboxes for all attributes in the table, then click the
Name
header to organize them
alphabetically, and select the appropriate ones.
This example assumes that you have added the
connectionTime
and
accountBalance
attributes to the schema.
6. Click
OK
.
The new ACI is added to the ones listed in the
Access Control Manager
window.
6.9.7.2. ACI "Billing Info Deny"
In LDIF, to deny subscribers permission to modify billing information in their own entry, write the
following statement:
Summary of Contents for DIRECTORY SERVER 8.0
Page 18: ...xviii ...
Page 29: ...Configuring the Directory Manager 11 6 Enter the new password and confirm it 7 Click Save ...
Page 30: ...12 ...
Page 112: ...94 ...
Page 128: ...110 ...
Page 190: ...Chapter 6 Managing Access Control 172 4 Click New to open the Access Control Editor ...
Page 224: ...206 ...
Page 324: ...306 ...
Page 334: ...316 ...
Page 358: ...340 ...
Page 410: ...392 ...
Page 420: ...402 ...
Page 444: ...426 ...
Page 454: ...436 ...
Page 464: ...446 ...
Page 484: ...466 ...
Page 512: ...494 ...
Page 522: ...504 ...