![Netscape NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR Скачать руководство пользователя страница 197](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-1-administrator/netscape-directory-server-6-1-administrator_administrators-manual_1674675197.webp)
Default ACIs
Chapter
6
Managing Access Control
197
•
Access control rules are always evaluated on the local server. Therefore, it is
not necessary to specify the hostname or port number of the server in LDAP
URLs used in ACI keywords. If you do, the LDAP URL will not be taken into
account at all. For more information on LDAP URLs, see Appendix C, “LDAP
URLs.”
Default ACIs
When you install the Directory Server, the following default ACIs apply to your
directory information stored in the
userRoot
database:
•
Users can modify their own entry in the directory, but not delete it. They
cannot modify the
aci
and
nsroledn
attributes.
•
Users have anonymous access to the directory for search, compare, and read
operations.
•
The administrator (by default
uid=admin,ou=Administrators,
ou=TopologyManagement,o=NetscapeRoot
) has all rights except proxy rights.
•
All members of the Configuration Administrators group have all rights except
proxy rights.
•
All members of the Directory Administrators group have all rights except
proxy rights.
•
SIE group.
Whenever you create a new database in the directory, the top entry has the default
ACIs listed above.
The
NetscapeRoot
subtree has its own set of default ACIs:
•
All members of the Configuration Administrators group have all rights on the
NetscapeRoot
subtree except proxy rights.
•
Users have anonymous access to the
NetscapeRoot
subtree for search and read
operations.
•
Group expansion.
•
All authenticated users have search, compare, and read rights to configuration
attributes that identify the Administration Server.
The following sections explain how to modify these default settings to suit the
needs of your organization.
Содержание NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR
Страница 1: ...Administrator s Guide Netscape Directory Server Version6 1 August 2002...
Страница 20: ...20 Netscape Directory Server Administrator s Guide August 2002...
Страница 24: ...24 Netscape Directory Server Administrator s Guide August 2002...
Страница 44: ...Starting the Server in Referral Mode 44 Netscape Directory Server Administrator s Guide August 2002...
Страница 78: ...Maintaining Referential Integrity 78 Netscape Directory Server Administrator s Guide August 2002...
Страница 142: ...Using Referrals 142 Netscape Directory Server Administrator s Guide August 2002...
Страница 162: ...Enabling and Disabling Read Only Mode 162 Netscape Directory Server Administrator s Guide August 2002...
Страница 278: ...Setting Resource Limits Based on the Bind DN 278 Netscape Directory Server Administrator s Guide August 2002...
Страница 336: ...Troubleshooting Replication Related Problems 336 Netscape Directory Server Administrator s Guide August 2002...
Страница 396: ...Configuring LDAP Clients to Use SSL 396 Netscape Directory Server Administrator s Guide August 2002...
Страница 418: ...Monitoring Database Link Activity 418 Netscape Directory Server Administrator s Guide August 2002...
Страница 440: ...Miscellaneous Tuning Tips 440 Netscape Directory Server Administrator s Guide August 2002...
Страница 442: ...442 Netscape Directory Server Administrator s Guide August 2002...
Страница 478: ...PTA Plug In Syntax Examples 478 Netscape Directory Server Administrator s Guide August 2002...
Страница 498: ...498 Netscape Directory Server Administrator s Guide August 2002...
Страница 512: ...Storing Information in Multiple Languages 512 Netscape Directory Server Administrator s Guide August 2002...
Страница 532: ...Searching an Internationalized Directory 532 Netscape Directory Server Administrator s Guide August 2002...
Страница 538: ...Examples of LDAP URLs 538 Netscape Directory Server Administrator s Guide August 2002...