![Netscape NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR Скачать руководство пользователя страница 251](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-1-administrator/netscape-directory-server-6-1-administrator_administrators-manual_1674675251.webp)
Access Control Usage Examples
Chapter
6
Managing Access Control
251
Setting a Target Using Filtering
If you want to set access controls that allow access to a number of entries that are
spread across the directory, you may want to use a filter to set the target. Keep in
mind that because search filters do not directly name the object for which you are
managing access, it is easy to unintentionally allow or deny access to the wrong
objects, especially as your directory becomes more complex. Additionally, filters
can make it difficult for you to troubleshoot access control problems within your
directory.
The following procedure shows you how to grant user
bjensen
write access to the
department number, home phone number, home postal address, JPEG photo, and
manager attributes for all members of the accounting organization.
Before you can set these permissions, you must create the accounting branch point
(
ou=accounting,dc=example,dc=com
). You can create organizational unit branch
points using the directory tab on the Directory Server Console.
Allowing Users to Add or Remove Themselves From a Group
Many directories set ACIs that allow users to add or remove themselves from
groups. This is useful, for example, for allowing users to add and remove
themselves from mailing lists.
At
example.com
, employees can add themselves to any group entry under the
ou=social committee
subtree. This is illustrated in the ACI “Group Members”
example.
ACI “Group Members”
In LDIF, to grant
example.com
employees the right to add or delete themselves
from a group, you would write the following statement:
aci: (targettattr="member")(version 3.0; acl "Group Members";
allow (selfwrite)
(userdn= "ldap:///uid=*,ou=example-people,dc=example,dc=com") ;)
This example assumes that the ACI is added to the
ou=social committee,
dc=example,dc=com
entry.
From the Console, you can set this permission by doing the following:
1.
On the Directory tab, right click the
example-people
entry under the
example.com
node in the left navigation tree, and choose Set Access
Permissions from the pop-up menu to display the Access Control Manager.
2.
Click New to display the Access Control Editor.
Содержание NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR
Страница 1: ...Administrator s Guide Netscape Directory Server Version6 1 August 2002...
Страница 20: ...20 Netscape Directory Server Administrator s Guide August 2002...
Страница 24: ...24 Netscape Directory Server Administrator s Guide August 2002...
Страница 44: ...Starting the Server in Referral Mode 44 Netscape Directory Server Administrator s Guide August 2002...
Страница 78: ...Maintaining Referential Integrity 78 Netscape Directory Server Administrator s Guide August 2002...
Страница 142: ...Using Referrals 142 Netscape Directory Server Administrator s Guide August 2002...
Страница 162: ...Enabling and Disabling Read Only Mode 162 Netscape Directory Server Administrator s Guide August 2002...
Страница 278: ...Setting Resource Limits Based on the Bind DN 278 Netscape Directory Server Administrator s Guide August 2002...
Страница 336: ...Troubleshooting Replication Related Problems 336 Netscape Directory Server Administrator s Guide August 2002...
Страница 396: ...Configuring LDAP Clients to Use SSL 396 Netscape Directory Server Administrator s Guide August 2002...
Страница 418: ...Monitoring Database Link Activity 418 Netscape Directory Server Administrator s Guide August 2002...
Страница 440: ...Miscellaneous Tuning Tips 440 Netscape Directory Server Administrator s Guide August 2002...
Страница 442: ...442 Netscape Directory Server Administrator s Guide August 2002...
Страница 478: ...PTA Plug In Syntax Examples 478 Netscape Directory Server Administrator s Guide August 2002...
Страница 498: ...498 Netscape Directory Server Administrator s Guide August 2002...
Страница 512: ...Storing Information in Multiple Languages 512 Netscape Directory Server Administrator s Guide August 2002...
Страница 532: ...Searching an Internationalized Directory 532 Netscape Directory Server Administrator s Guide August 2002...
Страница 538: ...Examples of LDAP URLs 538 Netscape Directory Server Administrator s Guide August 2002...