
Access Control and Authentication
167
n
ov
do
cx (e
n)
22
Ju
n
e 20
09
Table 16-2
Access Rights Explanation
NSS Access Control on OES
Table 16-3
provides links to documentation that discusses the various NSS-specific access control
features.
eDirectory
Objects
File System Trustee
Rights
Directory and File
Attributes
Directories and Files
eDirectory
objects (in
most cases
users and
groups) gain
access to
the file
system
through
eDirectory.
File system trustee
rights govern access
and usage by the
eDirectory object
specified for the
directory or file to
which the rights are
granted.
Trustee rights are
overridden by
directory and file
attributes.
For example, even
though Nancy has the
Supervisor (all)
trustee right at the
directory (and,
therefore, to the files it
contains), she cannot
delete File2 because it
has the Read Only
attribute set.
Of course, Nancy
could modify the file
attributes so that File2
could then be deleted.
Each directory and
file has attributes
associated with it.
These attributes
apply universally to
all trustees
regardless of the
trustee rights an
object might have.
For example, a file
that has the Read
Only attribute is
Read Only for all
users.
Attributes can be set
by any trustee that
has the Modify
trustee right to the
directory or file.
The possible actions by the eDirectory
users and group shown in this example
are as follows:
Nancy has the Supervisor trustee
right at the directory level, meaning
that she can perform any action not
blocked by a directory or file
attribute.
The Di (Delete Inhibit) and Ri
(Rename Inhibit) Attributes on
Directory A prevent Nancy from
deleting or renaming the directory
unless she modifies the attributes
first. The same principle applies to
her ability to modify File2.
Because Joe is a member of the
Reporters group, he can view file and
directory names inside DirectoryA
and also see the directory structure
up to the root directory.
Joe also has rights to open and read
any files in DirectoryA and to execute
any applications in DirectoryA.
Because Bert is a member of the
Reporters group, he can view file and
directory names inside DirectoryA
and also see the directory structure
up to the root directory.
Bert also has rights to open and read
File1 and to execute it if it's an
application.
And Bert has rights to grant any
eDirectory user access to File1.
Because all three users are
members of the Reporters group,
they can grant any eDirectory user
access to File2.
Of course, for Nancy this is
redundant because she has the
Supervisor right at the directory level.
Содержание OPEN ENTERPRISE SERVER 2 SP2 - ADMINISTRATION
Страница 4: ...4 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 14: ...14 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 24: ...24 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 26: ...26 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 76: ...76 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 80: ...80 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 82: ...82 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 98: ...98 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 122: ...122 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 148: ...148 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 178: ...178 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 208: ...208 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 216: ...216 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 224: ...224 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 232: ...232 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 234: ...234 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 242: ...242 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 244: ...244 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 248: ...248 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 252: ...252 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 256: ...256 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 276: ...276 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 278: ...278 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 288: ...288 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...