![Netscape NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR Скачать руководство пользователя страница 198](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-1-administrator/netscape-directory-server-6-1-administrator_administrators-manual_1674675198.webp)
Creating ACIs Manually
198
Netscape Directory Server Administrator’s Guide • August 2002
Creating ACIs Manually
You can create access control instructions manually using LDIF statements, and
add them to your directory tree using the
ldapmodify
utility. The following
sections explain in detail how to create the LDIF statements.
The ACI Syntax
The
aci
attribute uses the following syntax:
aci: (
target
)(version 3.0;acl "
name
";
permission bind_rules
;)
where
•
target
specifies the entry, attributes, or set of entries and attributes for which
you want to control access. The target can be a distinguished name, one or
more attributes, or a single LDAP filter. The target is an optional part of the
ACI.
•
version 3.0
is a required string that identifies the ACI version.
•
"
name
"
is a name for the ACI. The name can be any string that identifies the
ACI. The ACI name is required.
•
permission
specifically outlines what rights you are either allowing or denying
(for example, read or search rights).
•
bind_rules
specify the credentials and bind parameters that a user has to provide
to be granted access. Bind rules can also specifically deny access to certain
users or groups of users.
TIP
LDIF ACI statements can be very complex. However, if you are
setting access control for a large number of directory entries, using
LDIF is the preferred method over using the console because of the
time it can save.
To familiarize yourself with LDIF ACI statements, however, you
may want to use the Directory Server Console to set the ACI and
then click the Edit Manually button on the Access Control Editor.
This shows you the correct LDIF syntax. If your operating system
allows it, you can even copy the LDIF from the Access Control
Editor and paste it into your LDIF file.
Содержание NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR
Страница 1: ...Administrator s Guide Netscape Directory Server Version6 1 August 2002...
Страница 20: ...20 Netscape Directory Server Administrator s Guide August 2002...
Страница 24: ...24 Netscape Directory Server Administrator s Guide August 2002...
Страница 44: ...Starting the Server in Referral Mode 44 Netscape Directory Server Administrator s Guide August 2002...
Страница 78: ...Maintaining Referential Integrity 78 Netscape Directory Server Administrator s Guide August 2002...
Страница 142: ...Using Referrals 142 Netscape Directory Server Administrator s Guide August 2002...
Страница 162: ...Enabling and Disabling Read Only Mode 162 Netscape Directory Server Administrator s Guide August 2002...
Страница 278: ...Setting Resource Limits Based on the Bind DN 278 Netscape Directory Server Administrator s Guide August 2002...
Страница 336: ...Troubleshooting Replication Related Problems 336 Netscape Directory Server Administrator s Guide August 2002...
Страница 396: ...Configuring LDAP Clients to Use SSL 396 Netscape Directory Server Administrator s Guide August 2002...
Страница 418: ...Monitoring Database Link Activity 418 Netscape Directory Server Administrator s Guide August 2002...
Страница 440: ...Miscellaneous Tuning Tips 440 Netscape Directory Server Administrator s Guide August 2002...
Страница 442: ...442 Netscape Directory Server Administrator s Guide August 2002...
Страница 478: ...PTA Plug In Syntax Examples 478 Netscape Directory Server Administrator s Guide August 2002...
Страница 498: ...498 Netscape Directory Server Administrator s Guide August 2002...
Страница 512: ...Storing Information in Multiple Languages 512 Netscape Directory Server Administrator s Guide August 2002...
Страница 532: ...Searching an Internationalized Directory 532 Netscape Directory Server Administrator s Guide August 2002...
Страница 538: ...Examples of LDAP URLs 538 Netscape Directory Server Administrator s Guide August 2002...