![Netscape NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR Скачать руководство пользователя страница 194](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-1-administrator/netscape-directory-server-6-1-administrator_administrators-manual_1674675194.webp)
Access Control Principles
194
Netscape Directory Server Administrator’s Guide • August 2002
Access Control Principles
The mechanism by which you define access is called access control. When the server
receives a request, it uses the authentication information provided by the user in
the bind operation, and the access control instructions (ACIs) defined in the server
to allow or deny access to directory information. The server can allow or deny
permissions such as read, write, search, and compare. The permission level granted
to a user may be dependent on the authentication information provided.
Using access control, you can control access to the entire directory, a subtree of the
directory, specific entries in the directory (including entries defining configuration
tasks), or a specific set of entry attributes. You can set permissions for a specific
user, all users belonging to a specific group or role, or all users of the directory.
Finally, you can define access for a specific location such as an IP address or a DNS
name.
ACI Structure
Access control instructions are stored in the directory, as attributes of entries. The
aci
attribute is an operational attribute; it is available for use on every entry in the
directory, regardless of whether it is defined for the object class of the entry. It is
used by the Directory Server to evaluate what rights are granted or denied when it
receives an LDAP request from a client. The
aci
attribute is returned in an
ldapsearch
operation if specifically requested.
The three main parts of an ACI statement are:
•
Target
•
Permission
•
Bind Rule
The permission and bind rule portions of the ACI are set as a pair, also called an
Access Control Rule (ACR). The specified permission is granted or denied
depending on whether the accompanying rule is evaluated to be true.
Содержание NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR
Страница 1: ...Administrator s Guide Netscape Directory Server Version6 1 August 2002...
Страница 20: ...20 Netscape Directory Server Administrator s Guide August 2002...
Страница 24: ...24 Netscape Directory Server Administrator s Guide August 2002...
Страница 44: ...Starting the Server in Referral Mode 44 Netscape Directory Server Administrator s Guide August 2002...
Страница 78: ...Maintaining Referential Integrity 78 Netscape Directory Server Administrator s Guide August 2002...
Страница 142: ...Using Referrals 142 Netscape Directory Server Administrator s Guide August 2002...
Страница 162: ...Enabling and Disabling Read Only Mode 162 Netscape Directory Server Administrator s Guide August 2002...
Страница 278: ...Setting Resource Limits Based on the Bind DN 278 Netscape Directory Server Administrator s Guide August 2002...
Страница 336: ...Troubleshooting Replication Related Problems 336 Netscape Directory Server Administrator s Guide August 2002...
Страница 396: ...Configuring LDAP Clients to Use SSL 396 Netscape Directory Server Administrator s Guide August 2002...
Страница 418: ...Monitoring Database Link Activity 418 Netscape Directory Server Administrator s Guide August 2002...
Страница 440: ...Miscellaneous Tuning Tips 440 Netscape Directory Server Administrator s Guide August 2002...
Страница 442: ...442 Netscape Directory Server Administrator s Guide August 2002...
Страница 478: ...PTA Plug In Syntax Examples 478 Netscape Directory Server Administrator s Guide August 2002...
Страница 498: ...498 Netscape Directory Server Administrator s Guide August 2002...
Страница 512: ...Storing Information in Multiple Languages 512 Netscape Directory Server Administrator s Guide August 2002...
Страница 532: ...Searching an Internationalized Directory 532 Netscape Directory Server Administrator s Guide August 2002...
Страница 538: ...Examples of LDAP URLs 538 Netscape Directory Server Administrator s Guide August 2002...