![Netscape NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR Скачать руководство пользователя страница 218](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-1-administrator/netscape-directory-server-6-1-administrator_administrators-manual_1674675218.webp)
Bind Rules
218
Netscape Directory Server Administrator’s Guide • August 2002
roledn = "ldap:///
dn
[|| ldap:///
dn
]... [|| ldap:///
dn
]"
The bind rule is evaluated to be true if the bind DN belongs to the specified role.
The
roledn
keyword has the same syntax and is used in the same way as the
groupdn
keyword.
Defining Access Based on Value Matching
You can set bind rules to specify that an attribute value of the entry used to bind to
the directory must match an attribute value of the targeted entry.
For example, you can specify that the bind DN must match the DN in the
manager
attribute of a user entry in order for the ACI to apply. In this case, only the user’s
manager would have access to the entry.
This example is based on DN matching. However, you can match any attribute of
the entry used in the bind with the targeted entry. For example, you could create an
ACI that allowed any user whose
favoriteDrink
attribute is “beer” to read all the
entries of other users that have the same value for
favoriteDrink
.
Using the userattr Keyword
The
userattr
keyword can be used to specify which attribute values must match
between the entry used to bind and the targeted entry. You can specify:
•
A user DN
•
A group DN
•
A role DN
•
An LDAP filter, in an LDAP URL
•
Any attribute type
The LDIF syntax of the
userattr
keyword is as follows:
userattr = "
attrName
#
bindType
"
or, if you are using an attribute type that requires a value other than a user DN,
group DN, role DN, or an LDAP filter:
NOTE
If a DN contains a comma, the comma must be escaped by a
backslash (\).
Содержание NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR
Страница 1: ...Administrator s Guide Netscape Directory Server Version6 1 August 2002...
Страница 20: ...20 Netscape Directory Server Administrator s Guide August 2002...
Страница 24: ...24 Netscape Directory Server Administrator s Guide August 2002...
Страница 44: ...Starting the Server in Referral Mode 44 Netscape Directory Server Administrator s Guide August 2002...
Страница 78: ...Maintaining Referential Integrity 78 Netscape Directory Server Administrator s Guide August 2002...
Страница 142: ...Using Referrals 142 Netscape Directory Server Administrator s Guide August 2002...
Страница 162: ...Enabling and Disabling Read Only Mode 162 Netscape Directory Server Administrator s Guide August 2002...
Страница 278: ...Setting Resource Limits Based on the Bind DN 278 Netscape Directory Server Administrator s Guide August 2002...
Страница 336: ...Troubleshooting Replication Related Problems 336 Netscape Directory Server Administrator s Guide August 2002...
Страница 396: ...Configuring LDAP Clients to Use SSL 396 Netscape Directory Server Administrator s Guide August 2002...
Страница 418: ...Monitoring Database Link Activity 418 Netscape Directory Server Administrator s Guide August 2002...
Страница 440: ...Miscellaneous Tuning Tips 440 Netscape Directory Server Administrator s Guide August 2002...
Страница 442: ...442 Netscape Directory Server Administrator s Guide August 2002...
Страница 478: ...PTA Plug In Syntax Examples 478 Netscape Directory Server Administrator s Guide August 2002...
Страница 498: ...498 Netscape Directory Server Administrator s Guide August 2002...
Страница 512: ...Storing Information in Multiple Languages 512 Netscape Directory Server Administrator s Guide August 2002...
Страница 532: ...Searching an Internationalized Directory 532 Netscape Directory Server Administrator s Guide August 2002...
Страница 538: ...Examples of LDAP URLs 538 Netscape Directory Server Administrator s Guide August 2002...