Advanced Access Control: Using Macro ACIs
Chapter 6
Managing Access Control
273
• ($dn)
• [$dn]
• ($attr.
attrName
), where
attrName
represents an attribute contained in the target
entry
To simplify the discussion in this section, the ACI keywords used to provide bind
credentials, such as
userdn
,
roledn
,
groupdn
, and
userattr
, are collectively called
the
subject
, as opposed to the
target
, of the ACI. Macro ACIs can be used in the
target part or the subject part of an ACI.
Table 6-6 shows in what parts of the ACI you can use DN macros:
The following restrictions apply:
• If you use
($dn)
in
targetfilter
,
userdn
,
roledn
,
groupdn
,
userattr
, you
must
define a target that contains
($dn)
.
• If you use
[$dn]
in
targetfilter
,
userdn
,
roledn
,
groupdn
,
userattr
, you
must
define a target that contains
($dn)
.
In short, you when using any macro, you
always
need a target definition that
contains the
($dn)
macro.
You can combine the
($dn)
macro and the
($attr.
attrName
)
macro.
Macro Matching for ($dn)
The
($dn)
macro is replaced by the matching part of the resource targeted in an
LDAP request. For example, you have an LDAP request targeted at the
cn=all,
ou=groups,dc=subdomain1,dc=hostedCompany1,dc=example,dc=com
entry and
an ACI that defines the target as follows:
(target="ldap:///ou=Groups,($dn),dc=example,dc=com")
The
($dn)
macro matches with
dc=subdomain1, dc=hostedCompany1
.
Table 6-6
Macros in ACI Keywords
Macro
ACI Keyword
($dn)
target
,
targetfilter
,
userdn
,
roledn
,
groupdn
,
userattr
[$dn]
targetfilter
,
userdn
,
roledn
,
groupdn
,
userattr
($attr
.
attrName
)
userdn
,
roledn
,
groupdn
,
userattr
Содержание DIRECTORY SERVER 7.1
Страница 1: ...Administrator s Guide Red Hat Directory Server Version7 1 May 2005 Updated February 2009 ...
Страница 20: ...20 Red Hat Directory Server Administrator s Guide May 2005 Glossary 619 Index 635 ...
Страница 22: ...22 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 26: ...26 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 78: ...Maintaining Referential Integrity 78 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 200: ...Assigning Class of Service 200 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 278: ...Compatibility with Earlier Releases 278 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 374: ...Troubleshooting Replication Related Problems 374 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 478: ...Using the Management Information Base 478 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 488: ...488 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 528: ...PTA Plug in Syntax Examples 528 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 545: ...About Windows Sync Chapter 18 Windows Sync 545 Figure 18 1 Active Directory Directory Server Synchronization Process ...
Страница 572: ...572 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 586: ...Storing Information in Multiple Languages 586 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 606: ...Searching an Internationalized Directory 606 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 612: ...Examples of LDAP URLs 612 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 634: ...634 Red Hat Directory Server Administrator s Guide May 2005 ...