54
Novell iManager 2.7.3 Administration Guide
n
ov
do
cx (e
n)
22
Ju
n
e 20
09
Each Novell iManager task defines its applicable object types and necessary ACLs. However, these
ACLs allow the user to perform those operations with other object types through eDirectory APIs or
other tools such as Novell ConsoleOne or NWAdmin.
Use RBS to create specific roles within your organization; the roles contain tasks that an assigned
user can perform within iManager, such as creating a new user or changing a password. Tasks are
preassigned to roles but can be replaced, reassigned, or removed altogether.
Furthermore, users are associated with roles in a specified scope, which is a container in the tree in
which the user has the requisite permissions to perform a task. A role requires this threefold
association of role, members, and scope to be complete.
An RBS Role object creates an association between users and tasks. An administrator grants a user
access to a task by making the user a member of the role to which the task is assigned.
A user can be assigned to a role in the following ways:
Directly as a user
Through group and dynamic group assignments
If a user is a member of a group or a dynamic group that is assigned to a role, then the user has
access to the role.
Through organizational role assignments
If a user is an occupant of a organizational role that is assigned a role, then the user has access
to the role.
Through container assignment
A User object has access to all of the roles that its parent container is assigned. This could also
include other containers up to the root of the tree.
A user can be associated with a role multiple times, each with a different scope.
6.1.1 RBS Objects in eDirectory
The following table lists the RBS objects. iManager extends the eDirectory schema to include these
objects when you install RBS. For more information, see
“Installing RBS” on page 56
.
Object
Description
rbsCollection
A container object that holds all RBS Role and Module objects.
rbsCollection objects are the uppermost containers for all RBS objects. A tree
can have any number of rbsCollection objects. These objects have owners,
which are users who have management rights over the collection.
rbsCollection objects can be created in any of the following containers:
Country
Domain
Locality
Organization
Organizational Unit
Содержание IMANAGER 2.7.3
Страница 4: ...4 Novell iManager 2 7 3 Administration Guide novdocx en 22 June 2009...
Страница 22: ...22 Novell iManager 2 7 3 Administration Guide novdocx en 22 June 2009...
Страница 32: ...32 Novell iManager 2 7 3 Administration Guide novdocx en 22 June 2009...
Страница 52: ...52 Novell iManager 2 7 3 Administration Guide novdocx en 22 June 2009...
Страница 84: ...84 Novell iManager 2 7 3 Administration Guide novdocx en 22 June 2009...
Страница 102: ...102 Novell iManager 2 7 3 Administration Guide novdocx en 22 June 2009...
Страница 108: ...108 Novell iManager 2 7 3 Administration Guide novdocx en 22 June 2009...
Страница 114: ...114 Novell iManager 2 7 3 Administration Guide novdocx en 22 June 2009...