About Authorization
326
Netscape Certificate Management System Administrator’s Guide • February 2003
authorization check before allowing an operation to be performed in that area.
Access Control Instructions (ACI s) in each of the ACLs are created that specifically
allow or deny one or more possible operations for that ACL to specified users,
groups, or IP addresses.
The ACLs contain a default set of ACIs for the default groups that are created. You
can change those ACIs to change the privileges of those predefined groups, or
create groups of your own assigning the new group privileges by adding or
modifying ACI’s for the new group in the ACLs.
How Authorization Works
The following is the process that defines authorization:
1.
Users authenticates to the interface they are trying to access either using their
CMS user ID and password or with a certificate.
2.
The server authenticates them either by matching their user ID and password
with the one stored in the database, or by checking their certificate against one
stored in the database. With certificate-based authentication, the server also
checks that the certificate is valid, and finds the group membership of the user
by associating the DN of the certificate with a user and determining the user’s
group membership. With password based authentication, the server checks the
password against the user ID, and then finds the group membership of the user
by associating that user ID with the user ID contained in the group.
3.
When the user tries to perform an operation, the authorization mechanism
checks that the user ID of the user, the group in which the user belongs, or the
IP address of the user is allowed to perform that operation by checking the
ACLs for this process to determine if an ACI exists that allows this operation to
be performed by this user, group, or IP address.
Default Groups
A user’s privileges are determined by the group membership of the user. When
you install the subsystem you are given the choice of whether to allow membership
of users in more than one group. The default setting allows users to belong to more
than one group. If you changed this setting in the install wizard, users are not
allowed to belong to more than one group.
The following groups are created by default:
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...