![Netscape NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR Скачать руководство пользователя страница 196](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-1-administrator/netscape-directory-server-6-1-administrator_administrators-manual_1674675196.webp)
Access Control Principles
196
Netscape Directory Server Administrator’s Guide • August 2002
For example, if you deny write permission at the directory’s root level, then none of
the users can write to the directory regardless of the specific permissions you grant
them. To grant a specific user write permissions to the directory, you have to
restrict the scope of the original denial for write permission so that it does not
include the user.
ACI Limitations
When creating an access control policy for your directory service, you need to be
aware of the following restrictions:
•
If your directory tree is distributed over several servers using the chaining
feature, some restrictions apply to the keywords you can use in access control
statements:
❍
ACIs that depend on group entries (
groupdn
keyword) must be located on
the same server as the group entry. If the group is dynamic, then all
members of the group must have an entry on the server too. If the group is
static, the members’s entries can be located on remote servers.
❍
ACIs that depend on role definitions (
roledn
keyword) must be located on
the same server as the role definition entry. Every entry that is intended to
have the role must also be located on the same server.
However, you can do value matching of values stored in the target entry with
values stored in the entry of the bind user (for example, using the userattr
keyword). Access will be evaluated normally even if the bind user does not
have an entry on server that holds the ACI.
For more information on how to chain access control evaluation, see “Database
Links and Access Control Evaluation,” on page 115.
•
Attributes generated by a CoS cannot be used in all ACI keywords.Specifically,
you should not use attributes generated by CoS with the following keywords:
❍
targetfilter
(see “Targeting Entries or Attributes Using LDAP Filters,”
on page 204)
❍
targattrfilters
(see “Targeting Attribute Values Using LDAP Filters,”
on page 205)
❍
userattr
(see “Using the userattr Keyword,” on page 218)
If you create target filters or bind rules that depend on the value of attributes
generated by CoS, the access control rule will not work. For more information
on CoS, see Chapter 5, “Advanced Entry Management.”
Содержание NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR
Страница 1: ...Administrator s Guide Netscape Directory Server Version6 1 August 2002...
Страница 20: ...20 Netscape Directory Server Administrator s Guide August 2002...
Страница 24: ...24 Netscape Directory Server Administrator s Guide August 2002...
Страница 44: ...Starting the Server in Referral Mode 44 Netscape Directory Server Administrator s Guide August 2002...
Страница 78: ...Maintaining Referential Integrity 78 Netscape Directory Server Administrator s Guide August 2002...
Страница 142: ...Using Referrals 142 Netscape Directory Server Administrator s Guide August 2002...
Страница 162: ...Enabling and Disabling Read Only Mode 162 Netscape Directory Server Administrator s Guide August 2002...
Страница 278: ...Setting Resource Limits Based on the Bind DN 278 Netscape Directory Server Administrator s Guide August 2002...
Страница 336: ...Troubleshooting Replication Related Problems 336 Netscape Directory Server Administrator s Guide August 2002...
Страница 396: ...Configuring LDAP Clients to Use SSL 396 Netscape Directory Server Administrator s Guide August 2002...
Страница 418: ...Monitoring Database Link Activity 418 Netscape Directory Server Administrator s Guide August 2002...
Страница 440: ...Miscellaneous Tuning Tips 440 Netscape Directory Server Administrator s Guide August 2002...
Страница 442: ...442 Netscape Directory Server Administrator s Guide August 2002...
Страница 478: ...PTA Plug In Syntax Examples 478 Netscape Directory Server Administrator s Guide August 2002...
Страница 498: ...498 Netscape Directory Server Administrator s Guide August 2002...
Страница 512: ...Storing Information in Multiple Languages 512 Netscape Directory Server Administrator s Guide August 2002...
Страница 532: ...Searching an Internationalized Directory 532 Netscape Directory Server Administrator s Guide August 2002...
Страница 538: ...Examples of LDAP URLs 538 Netscape Directory Server Administrator s Guide August 2002...