![Netscape NETSCAPE DIRECTORY SERVER 6.02 Скачать руководство пользователя страница 202](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-02/netscape-directory-server-6-02_administrators-manual_1674673202.webp)
Creating ACIs Manually
202
Netscape Directory Server Administrator’s Guide • May 2002
Targeting a Single Directory Entry
Targeting a single directory entry is not straightforward because it goes against the
design philosophy of the access control mechanism. However, it can be done:
•
By creating a bind rule that matches user input in the bind request with an
attribute value stored in the targeted entry. For more details, see “Defining
Access Based on Value Matching,” on page 213.
•
By using the
targetattr
and
targetfilter
keywords
You can use the
targetattr
keyword to specify an attribute that is only present in
the entry you want to target, and not in any of the entries below your target. For
example, if you want to target
ou=people,dc=example,dc=com
, and there aren’t
any organizational units (
ou
) defined below that node you could specify an ACI
that contains:
targetattr=ou
A safer method is to use the
targetfilter
keyword and to explicitly specify an
attribute value that appears in the entry alone. For example, during the installation
of the Directory Server, the following ACI is created:
aci: (targetattr="*")(targetfilter=(o=NetscapeRoot))(version 3.0;
acl "Default anonymous access"; allow (read, search)
userdn="ldap:///anyone";)
This ACI can apply only to the
o=NetscapeRoot
entry.
The risk associated with these methods is that your directory tree might change in
the future, and you would have to remember to modify this ACI.
Defining Permissions
Permissions specify the type of access you are allowing or denying. You can either
allow or deny permission to perform specific operations in the directory. The
various operations that can be assigned are known as rights.
There are two parts to setting permissions:
•
Allowing or denying access
•
Assigning rights
Содержание NETSCAPE DIRECTORY SERVER 6.02
Страница 1: ...Administrator s Guide Netscape Directory Server Version6 02 May 2002 ...
Страница 16: ...16 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 20: ...20 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 40: ...Starting the Server in Referral Mode 40 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 74: ...Maintaining Referential Integrity 74 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 138: ...Using Referrals 138 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 258: ...Compatibility with Earlier Releases 258 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 274: ...Setting Resource Limits Based on the Bind DN 274 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 330: ...Solving Common Replication Conflicts 330 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 374: ...Attribute Name Quick Reference Table 374 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 390: ...Configuring LDAP Clients to Use SSL 390 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 412: ...Monitoring Database Link Activity 412 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 432: ...Miscellaneous Tuning Tips 432 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 434: ...434 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 468: ...PTA Plug In Syntax Examples 468 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 488: ...488 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 502: ...Storing Information in Multiple Languages 502 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 522: ...Searching an Internationalized Directory 522 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 528: ...Examples of LDAP URLs 528 Netscape Directory Server Administrator s Guide May 2002 ...