![Netscape NETSCAPE DIRECTORY SERVER 6.02 Скачать руководство пользователя страница 236](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-02/netscape-directory-server-6-02_administrators-manual_1674673236.webp)
Access Control Usage Examples
236
Netscape Directory Server Administrator’s Guide • May 2002
b.
In the attribute table, tick the checkboxes for the
homePhone
,
homePostalAddress
, and
attributes.
All other checkboxes should be clear. This task is made easier if you click
the Check None button to clear the checkoxes for all attributes in the table,
then click the Name header to organize them alphabetically, and select the
appropriate ones.
6.
If you want users to authenticate using SSL, switch to manual editing by
clicking the Edit Manually button and add
authmethod=ssl
to the LDIF
statement so that it reads as follows:
(targetattr="homePostalAddress || homePhone || mail") (version
3.0; acl "Write Subscribers"; allow (write) (userdn=
"ldap:///self") and authmethod="ssl";)
7.
Click OK.
The new ACI is added to the ones listed in the Access Control Manager
window.
Restricting Access to Key Roles
You can use role definitions in the directory to identify functions that are critical to
your business, the administration of your network and directory, or another
purpose.
For example, you might create a
superAdmin
role by identifying a subset of your
system administrators that are available at a particular time of day and day of the
week at corporate sites worldwide. Or you might want to create a
First Aid
role
that includes all members of staff on a particular site that have done first aid
training. For information on creating role definitions, refer to “Using Roles,” on
page 162.
When a role gives any sort of privileged user rights over critical corporate or
business functions, you should consider restricting access to that role. For example,
at
example.com
, employees can add any role to their own entry, except the
superAdmin
role. This is illustrated in the ACI “Roles” example.
ACI “Roles”
In LDIF, to grant
example.com
employees the right to add any role to their own
entry, except the
superAdmin
role, you would write the following statement:
aci: (targetattr = "nsRoleDn")
(targattrfilters="add=nsRoleDN:(nsRoleDN !=
"cn=superAdmin,dc=example,dc=com")") (version 3.0; acl "Roles";
allow (write) userdn= "ldap:///self" and dns="*.example.com";)
Содержание NETSCAPE DIRECTORY SERVER 6.02
Страница 1: ...Administrator s Guide Netscape Directory Server Version6 02 May 2002 ...
Страница 16: ...16 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 20: ...20 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 40: ...Starting the Server in Referral Mode 40 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 74: ...Maintaining Referential Integrity 74 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 138: ...Using Referrals 138 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 258: ...Compatibility with Earlier Releases 258 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 274: ...Setting Resource Limits Based on the Bind DN 274 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 330: ...Solving Common Replication Conflicts 330 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 374: ...Attribute Name Quick Reference Table 374 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 390: ...Configuring LDAP Clients to Use SSL 390 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 412: ...Monitoring Database Link Activity 412 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 432: ...Miscellaneous Tuning Tips 432 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 434: ...434 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 468: ...PTA Plug In Syntax Examples 468 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 488: ...488 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 502: ...Storing Information in Multiple Languages 502 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 522: ...Searching an Internationalized Directory 522 Netscape Directory Server Administrator s Guide May 2002 ...
Страница 528: ...Examples of LDAP URLs 528 Netscape Directory Server Administrator s Guide May 2002 ...