Granting Write Access to Personal Entries
187
6. In the
Filter for subentries
field, type the following filter:
(!(unlistedSubscriber=yes))
7. In the attribute table, select the checkboxes for the
homePhone
,
homePostalAddress
, and
attributes.
All other checkboxes should be clear; if it is easier, click the
Check None
button to clear
the checkboxes for all attributes in the table, then click the
Name
header to organize them
alphabetically, and select the appropriate ones.
8. Click
OK
.
The new ACI is added to the ones listed in the
Access Control Manager
window.
6.9.2. Granting Write Access to Personal Entries
Many directory administrators want to allow internal users to change some but not all of the attributes
in their own entry. The directory administrators at
example.com
want to allow users to change their
own password, home telephone number, and home address, but nothing else. This is illustrated in
Section 6.9.2.1, “ACI "Write example.com"”
.
It is also
example.com
's policy to let their subscribers update their own personal information in the
example.com
tree, provided that they establish an SSL connection to the directory. This is illustrated
in
Section 6.9.2.2, “ACI "Write Subscribers"”
.
6.9.2.1. ACI "Write example.com"
NOTE
By setting this permission, you are also granting users the right to delete attribute values.
Granting
example.com
employees the right to update their password, home telephone number, and
home address has the following statement in LDIF:
aci: (targetattr="userPassword || homePhone ||
homePostalAddress") (version 3.0; acl "Write example.com"; allow
(write) userdn= "ldap:///self" and dns="*.example.com";)
This example assumes that the ACI is added to the
ou=example-people,dc=example,dc=com
entry.
From the Console, set this permission by doing the following:
1. In the
Directory
tab, right-click the
example-people
entry under the
example.com
node in the
left navigation tree, and choose
Set Access Permissions
from the pop-up menu to display the
Access Control Manager
.
2. Click
New
to display the
Access Control Editor
.
3. In the
Users/Groups
tab, in the
ACI name
field, type
Write example.com
. In the list of users
granted access permission, do the following:
Содержание DIRECTORY SERVER 8.0
Страница 18: ...xviii ...
Страница 29: ...Configuring the Directory Manager 11 6 Enter the new password and confirm it 7 Click Save ...
Страница 30: ...12 ...
Страница 112: ...94 ...
Страница 128: ...110 ...
Страница 190: ...Chapter 6 Managing Access Control 172 4 Click New to open the Access Control Editor ...
Страница 224: ...206 ...
Страница 324: ...306 ...
Страница 334: ...316 ...
Страница 358: ...340 ...
Страница 410: ...392 ...
Страница 420: ...402 ...
Страница 444: ...426 ...
Страница 454: ...436 ...
Страница 464: ...446 ...
Страница 484: ...466 ...
Страница 512: ...494 ...
Страница 522: ...504 ...