![Netscape NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR Скачать руководство пользователя страница 242](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-1-administrator/netscape-directory-server-6-1-administrator_administrators-manual_1674675242.webp)
Access Control Usage Examples
242
Netscape Directory Server Administrator’s Guide • August 2002
c.
Click the Add button to list Self in the list of users who are granted access
permission.
d.
Click OK to dismiss the Add Users and Groups dialog box.
4.
On the Rights tab, tick the checkbox for write. Make sure the other checkboxes
are clear.
5.
On the Hosts tab, click Add to display the Add Host Filter dialog box. In the
DNS host filter field, type
*.example.com
. Click OK to dismiss the dialog box.
6.
To create the value-based filter for roles, switch to manual editing by clicking
the Edit Manually button. Add the following to the beginning of the LDIF
statement:
(targattrfilters="add=nsRoleDN:(nsRoleDN != "cn=superAdmin,
dc=example,dc=com")")
The LDIF statement should read as follows:
(targattrfilters="add=nsRoleDN:(nsRoleDN != "cn=superAdmin,
dc=example,dc=com")") (targetattr = “*”) (target =
"ldap:///dc=example,dc=com") (version 3.0; acl "Roles"; allow
(write) (userdn = "ldap:///self") and (dns="*.example.com");)
7.
Click OK.
The new ACI is added to the ones listed in the Access Control Manager
window.
Granting a Group Full Access to a Suffix
Most directories have a group that is used to identify certain corporate functions.
These groups can be given full access to all or part of the directory. By applying the
access rights to the group, you can avoid setting the access rights for each member
individually. Instead, you grant users these access rights simply by adding them to
the group.
For example, when you install the Directory Server using the Typical Install
process, an Administrators group with full access to the directory is created by
default.
At
example.com
, the Human Resources group is allowed full access to the
ou=example-people
branch of the directory so that they can update the employee
database. This is illustrated in the ACI “HR” example.
ACI “HR”
In LDIF, to grant the HR group all rights on the employee branch of the directory,
you would use the following statement:
Содержание NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR
Страница 1: ...Administrator s Guide Netscape Directory Server Version6 1 August 2002...
Страница 20: ...20 Netscape Directory Server Administrator s Guide August 2002...
Страница 24: ...24 Netscape Directory Server Administrator s Guide August 2002...
Страница 44: ...Starting the Server in Referral Mode 44 Netscape Directory Server Administrator s Guide August 2002...
Страница 78: ...Maintaining Referential Integrity 78 Netscape Directory Server Administrator s Guide August 2002...
Страница 142: ...Using Referrals 142 Netscape Directory Server Administrator s Guide August 2002...
Страница 162: ...Enabling and Disabling Read Only Mode 162 Netscape Directory Server Administrator s Guide August 2002...
Страница 278: ...Setting Resource Limits Based on the Bind DN 278 Netscape Directory Server Administrator s Guide August 2002...
Страница 336: ...Troubleshooting Replication Related Problems 336 Netscape Directory Server Administrator s Guide August 2002...
Страница 396: ...Configuring LDAP Clients to Use SSL 396 Netscape Directory Server Administrator s Guide August 2002...
Страница 418: ...Monitoring Database Link Activity 418 Netscape Directory Server Administrator s Guide August 2002...
Страница 440: ...Miscellaneous Tuning Tips 440 Netscape Directory Server Administrator s Guide August 2002...
Страница 442: ...442 Netscape Directory Server Administrator s Guide August 2002...
Страница 478: ...PTA Plug In Syntax Examples 478 Netscape Directory Server Administrator s Guide August 2002...
Страница 498: ...498 Netscape Directory Server Administrator s Guide August 2002...
Страница 512: ...Storing Information in Multiple Languages 512 Netscape Directory Server Administrator s Guide August 2002...
Страница 532: ...Searching an Internationalized Directory 532 Netscape Directory Server Administrator s Guide August 2002...
Страница 538: ...Examples of LDAP URLs 538 Netscape Directory Server Administrator s Guide August 2002...