background image

no

vd

ocx 

(e

n)

  

13

 Ma
y 20

09

Legal Notices

Novell, Inc., makes no representations or warranties with respect to the contents or use of this documentation, and 
specifically disclaims any express or implied warranties of merchantability or fitness for any particular purpose. 
Further, Novell, Inc., reserves the right to revise this publication and to make changes to its content, at any time, 
without obligation to notify any person or entity of such revisions or changes.

Further, Novell, Inc., makes no representations or warranties with respect to any software, and specifically disclaims 
any express or implied warranties of merchantability or fitness for any particular purpose. Further, Novell, Inc., 
reserves the right to make changes to any and all parts of Novell software, at any time, without any obligation to 
notify any person or entity of such changes.

Any products or technical information provided under this Agreement may be subject to U.S. export controls and the 
trade laws of other countries. You agree to comply with all export control regulations and to obtain any required 
licenses or classification to export, re-export or import deliverables. You agree not to export or re-export to entities 
on the current U.S. export exclusion lists or to any embargoed or terrorist countries as specified in the U.S. export 
laws. You agree to not use deliverables for prohibited nuclear, missile, or chemical biological weaponry end uses. 
See the 

Novell International Trade Services Web page (http://www.novell.com/info/exports/)

 for more information 

on exporting Novell software. Novell assumes no responsibility for your failure to obtain any necessary export 
approvals.

Copyright © 2008-2009 Novell, Inc. All rights reserved. No part of this publication may be reproduced, photocopied, 
stored on a retrieval system, or transmitted without the express written consent of the publisher.

Novell, Inc., has intellectual property rights relating to technology embodied in the product that is described in this 
document. In particular, and without limitation, these intellectual property rights may include one or more of the U.S. 
patents listed on the 

Novell Legal Patents Web page (http://www.novell.com/company/legal/patents/)

 and one or 

more additional patents or pending patent applications in the U.S. and in other countries.

Novell, Inc.
404 Wyman Street, Suite 500
Waltham, MA 02451
U.S.A.
www.novell.com

Online Documentation:

 To access the latest online documentation for this and other Novell products, see 

the 

Novell Documentation Web page (http://www.novell.com/documentation)

.

Содержание IDENTITY MANAGER 3.6.1 - ENTITLEMENTS

Страница 1: ...Novell www novell com novdocx en 13 May 2009 AUTHORIZED DOCUMENTATION Identity Manager 3 6 1 Entitlements Guide Identity Manager 3 6 1 June 05 2009 Entitlements Guide...

Страница 2: ...r re export to entities on the current U S export exclusion lists or to any embargoed or terrorist countries as specified in the U S export laws You agree to not use deliverables for prohibited nuclea...

Страница 3: ...Trademarks For Novell trademarks see the Novell Trademark and Service Mark list http www novell com company legal trademarks tmlist html Third Party Materials All third party trademarks are the proper...

Страница 4: ...4 Identity Manager 3 6 1 Entitlements Guide novdocx en 13 May 2009...

Страница 5: ...20 4 2 3 Valued Entitlement that Queries an External Application 21 4 3 Creating Entitlements in iManager 24 5 Creating Policies to Support Entitlements 27 6 Editing Entitlements 29 6 1 Editing Entit...

Страница 6: ...6 Identity Manager 3 6 1 Entitlements Guide novdocx en 13 May 2009...

Страница 7: ...online documentation or go to www novell com documentation feedback html and enter your comments there Documentation Updates For the most recent version of the Entitlements Guide visit the Identity Ma...

Страница 8: ...8 Identity Manager 3 6 1 Entitlements Guide novdocx en 13 May 2009...

Страница 9: ...figured Entitlements on page 11 1 1 How Entitlements Work The following diagram shows the basic entitlement process Figure 1 1 Overview of Entitlements 1 An entitlement agent grants an entitlement to...

Страница 10: ...itlements Both roles based provisioning and workflow based provisioning require the use of entitlements If you use either of these User Application provisioning methods you must use entitlements If yo...

Страница 11: ...y Grant and revoke accounts group membership Exchange Mailbox GroupWise Grant and revoke accounts grant and revoke members of distribution lists LDAP Grant and revoke user accounts and group membershi...

Страница 12: ...12 Identity Manager 3 6 1 Entitlements Guide novdocx en 13 May 2009...

Страница 13: ...ttribute to the User class The following drivers are already enabled for entitlements You do not need to complete this task for these drivers Active Directory GroupWise LDAP Linux and UNIX Lotus Notes...

Страница 14: ...r Role Based Entitlements Implementation Guide http www novell com documentation idm36drivers entitlements data bktitle html User Application Roles Based Provisioning Manages entitlements based on rol...

Страница 15: ...d Unix Lotus Notes RACF 3 1 Using Designer to Enable Entitlements Designer is the recommended tool for creating entitlements see Section 4 2 Creating Entitlements in Designer on page 17 During the ent...

Страница 16: ...hlighted 7 Click User and select Add Attribute then scroll to the bottom and select Show all attributes 8 Select the DirXML EntitlementRef attribute then click OK 9 Select DirXML EntitlementRef in the...

Страница 17: ...to create for other drivers User Account Entitlement Grants or revokes an account in Active Directory for the user When the account is granted the user is given an enabled logon account When the acco...

Страница 18: ...is displayed select Yes then click OK to enable the entitlement for the driver Skip the remaining steps in this section or Select Yes if the entitlement needs to include values click Next then continu...

Страница 19: ...n this example the values are corporate buildings Building A through Building D Through an entitlement client such as an iManager Role Based Entitlement task or through the user application users or d...

Страница 20: ...lows the driver filter to listen for entitlement activities which is necessary in order to use the entitlements you are creating or If you don t want to see the Add To Filter window on entitlements yo...

Страница 21: ...rity Merging the values merges the entitlements of all involved Role Based Entitlement policies so if one policy revokes an entitlement but another policy grants an entitlement the entitlement is even...

Страница 22: ...e Schema Browser The list includes both the Attributes and the Inherited Attributes for the selected class Description Defines the attribute that displays as a description for that value For the descr...

Страница 23: ...policy grants an entitlement the entitlement is eventually granted Solving conflicts by priority works if you need to ensure that only one policy is applied to this entitlement at any time This examp...

Страница 24: ...w again 4 3 Creating Entitlements in iManager We strongly recommend that you use the Entitlement Wizard in Designer to create entitlements The Entitlement Wizard creates the entitlement XML from the i...

Страница 25: ...es in the policies that are implementing the entitlement The entitlement name is stored on the Ref and Result attributes within the policy The context for the entitlement is already populated because...

Страница 26: ...26 Identity Manager 3 6 1 Entitlements Guide novdocx en 13 May 2009...

Страница 27: ...Vault When you use the User Account Entitlement managed user accounts are controlled by the entitlement in the Identity Vault A delete in Active Directory does not delete the controlling object in th...

Страница 28: ...ased Entitlements accounts are created only for users that are specifically granted the account entitlement This rule vetoes user account creation when the entitlement is not granted Identity Vault Ac...

Страница 29: ...entitlements You can also edit the XML source directly Section 6 1 1 Using the Entitlement Editor on page 29 Section 6 1 2 Using the XML Source and XML Tree Views on page 31 6 1 1 Using the Entitlemen...

Страница 30: ...priority button is the default Values Allows you to define how values are defined no values administrator defined values or values from an application The information that appears in the Entitlement E...

Страница 31: ...he XML code in a formatted state The upper right corner of the XML Source view has the following selections Name Description Expand All Allows you to see all items under the item that you have selecte...

Страница 32: ...a tree control view of the XML source code You can perform the same edits in this view as you can in the Entitlement Editor view or the XML Source view To view the entitlement in XML Tree view select...

Страница 33: ...d Before a Comment a Processing Instruction a PCDATA a CDATA Section a new Element Add After a Comment a Processing Instruction a PCDATA a CDATA Section a new Element Name Description Expand All Allow...

Страница 34: ...river Sets tab use the Search In field to search for and display the driver set 4 Click the driver set to open the Driver Set Overview page 5 Click the driver to display the Driver Overview page 6 On...

Страница 35: ...s provide information to help you create XML entitlement documents Section A 1 Novell Entitlement Document Type Definition DTD on page 35 Section A 2 Examples to Help You Write Your Own Entitlements o...

Страница 36: ...c id param state status msg timestamp ELEMENT dn PCDATA ELEMENT state PCDATA ELEMENT status PCDATA ELEMENT msg ANY ELEMENT timestamp PCDATA Cached query results stored in the DirXML SPCachedQuery attr...

Страница 37: ...Policy has a higher priority If an entitlement is single valued conflicts must be resolved by priority because a union of values results in more than one value being applied Role Based Entitlements p...

Страница 38: ...esult set element to help you interpret the result of an external application query There are three pieces of data that are of interest the display name of the value the display name child element the...

Страница 39: ...EntitlementRef portion is actually not part of the Entitlement definition You don t need to do anything with the elements and attributes under this heading A 2 Examples to Help You Write Your Own Enti...

Страница 40: ...perform future modifications to the entitlement The actual name of the entitlement is UserAccount while the display name displays in a managing agent as User Account Entitlement A 2 2 Example 2 Applic...

Страница 41: ...top of the tree and continues through its subtrees These values come from the connected Active Directory server and the application query starts at the nds tag Under the query xml tag this query recei...

Страница 42: ...states that the entitlement grants or revokes an Exchange mailbox for the user in Microsoft Exchange which is enough detail for what the entitlement does The display name is Exchange Mailbox Entitleme...

Страница 43: ...orporate building letters Building A through Building F Then through an entitlement client such as an iManager Roles Based Entitlement task or through the User Application users or defined task manage...

Страница 44: ...44 Identity Manager 3 6 1 Entitlements Guide novdocx en 13 May 2009...

Отзывы: