Authorization for CMS Users
Chapter
8
Authorization
347
Authorization for CMS Users
Authorization is the mechanism that checks whether or not a user is allowed to
perform a certain operation. Authorization points are defined in certain groups of
operations that requiring an authorization check of the user.
Access Control Lists (ACLs)
Access Control Lists (ACLs) are the mechanism that specifies the authorization to
each of the sets of operations that require authorization. An ACL exists for each set
of operations where an authorization check occurs. You can define additional
operations to a ACL, or additional sets of operations by adding this checking to
that resource using the CMS SDK.
Access Control Instructions (ACIs)
The ACL contains Access Control Instructions (ACIs) which specifically allow or
deny operations such as read or modify for this set of operations. The ACI also
contains an evaluator expression. The default implementation of ACLs specifies
only users, groups, and IP addresses as possible evaluator types, although you
could create others using the CMS SDK. Each ACI in an ACL specifies that access is
allowed or denied, what the specific operator is being allowed or denied, and
which user(s), group(s), or IP address(es) is being allowed or denied to perform the
operation.
Changing Privileges
You can change the privileges of CMS users by changing the Access Control Lists
(ACL) that are associated with the group in which the user is a member, for the
users themselves, or for the IP address of the user. You can also create groups and
assign access control to each group by adding that group to the access control lists.
For example, you can create a group for administrators who are only authorized to
view logs. You could name the group
LogAdmins
and modify the ACLs relevant to
logs to allow read or modify access to this group. If you did not add this group to
any other ACLs, members of this group would only have access to the logs.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...