Access Control Usage Examples
260
Red Hat Directory Server Administrator’s Guide • May 2005
Setting a Target Using Filtering
If you want to set access controls that allow access to a number of entries that are
spread across the directory, you may want to use a filter to set the target. Keep in
mind that because search filters do not directly name the object for which you are
managing access, it is easy to allow or deny access to the wrong objects
unintentionally, especially as your directory becomes more complex.
Additionally, filters can make it difficult for you to troubleshoot access control
problems within your directory.
The following procedure shows you how to grant user
bjensen
write access to the
department number, home phone number, home postal address, JPEG photo, and
manager attributes for all members of the accounting organization.
Before you can set these permissions, you must create the accounting branch point
(
ou=accounting,dc=example,dc=com
). You can create organizational unit
branch points using the directory tab on the Directory Server Console.
Allowing Users to Add or Remove Themselves from
a Group
Many directories set ACIs that allow users to add or remove themselves from
groups. This is useful, for example, for allowing users to add and remove
themselves from mailing lists.
At
example.com
, employees can add themselves to any group entry under the
ou=social committee
subtree. This is illustrated in the ACI “Group Members”
example.
ACI “Group Members”
In LDIF, to grant
example.com
employees the right to add or delete themselves
from a group, you would write the following statement:
aci: (targettattr="member")(version 3.0; acl "Group Members";
allow (selfwrite)
(userdn= "ldap:///uid=*,ou=example-people,dc=example,dc=com")
;)
This example assumes that the ACI is added to the
ou=social committee,
dc=example,dc=com
entry.
From the Console, you can set this permission by doing the following:
Содержание DIRECTORY SERVER 7.1
Страница 1: ...Administrator s Guide Red Hat Directory Server Version7 1 May 2005 Updated February 2009 ...
Страница 20: ...20 Red Hat Directory Server Administrator s Guide May 2005 Glossary 619 Index 635 ...
Страница 22: ...22 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 26: ...26 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 78: ...Maintaining Referential Integrity 78 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 200: ...Assigning Class of Service 200 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 278: ...Compatibility with Earlier Releases 278 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 374: ...Troubleshooting Replication Related Problems 374 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 478: ...Using the Management Information Base 478 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 488: ...488 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 528: ...PTA Plug in Syntax Examples 528 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 545: ...About Windows Sync Chapter 18 Windows Sync 545 Figure 18 1 Active Directory Directory Server Synchronization Process ...
Страница 572: ...572 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 586: ...Storing Information in Multiple Languages 586 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 606: ...Searching an Internationalized Directory 606 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 612: ...Examples of LDAP URLs 612 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 634: ...634 Red Hat Directory Server Administrator s Guide May 2005 ...