Creating ACIs Manually
206
Red Hat Directory Server Administrator’s Guide • May 2005
• All authenticated users have search, compare, and read rights to
configuration attributes that identify the Administration Server.
The following sections explain how to modify these default settings to suit the
needs of your organization.
Creating ACIs Manually
You can create access control instructions manually using LDIF statements and
add them to your directory tree using the
ldapmodify
utility. The following
sections explain in detail how to create the LDIF statements.
The ACI Syntax
The
aci
attribute uses the following syntax:
aci: (
target
)(version 3.0;acl "
name
";
permission
bind_rules
;)
where
•
target
specifies the entry, attributes, or set of entries and attributes for which
you want to control access. The target can be a distinguished name, one or
more attributes, or a single LDAP filter. The target is an optional part of the
ACI.
•
version 3.0
is a required string that identifies the ACI version.
•
"
name
"
is a name for the ACI. The name can be any string that identifies the
ACI. The ACI name is required.
TIP
LDIF ACI statements can be very complex. However, if you are
setting access control for a large number of directory entries, using
LDIF is the preferred method over using the Console because of the
time it can save.
To familiarize yourself with LDIF ACI statements, however, you
may want to use the Directory Server Console to set the ACI and
then click the Edit Manually button on the Access Control Editor.
This shows you the correct LDIF syntax. If your operating system
allows it, you can even copy the LDIF from the Access Control
Editor and paste it into your LDIF file.
Содержание DIRECTORY SERVER 7.1
Страница 1: ...Administrator s Guide Red Hat Directory Server Version7 1 May 2005 Updated February 2009 ...
Страница 20: ...20 Red Hat Directory Server Administrator s Guide May 2005 Glossary 619 Index 635 ...
Страница 22: ...22 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 26: ...26 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 78: ...Maintaining Referential Integrity 78 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 200: ...Assigning Class of Service 200 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 278: ...Compatibility with Earlier Releases 278 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 374: ...Troubleshooting Replication Related Problems 374 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 478: ...Using the Management Information Base 478 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 488: ...488 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 528: ...PTA Plug in Syntax Examples 528 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 545: ...About Windows Sync Chapter 18 Windows Sync 545 Figure 18 1 Active Directory Directory Server Synchronization Process ...
Страница 572: ...572 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 586: ...Storing Information in Multiple Languages 586 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 606: ...Searching an Internationalized Directory 606 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 612: ...Examples of LDAP URLs 612 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 634: ...634 Red Hat Directory Server Administrator s Guide May 2005 ...