
Granting a Group Full Access to a Suffix
191
dc=example,dc=com")") (targetattr = "*") (target = "ldap:///
ou=example-people,dc=example,dc=com") (version 3.0; acl "Roles";
allow (write) (userdn = "ldap:///self") and (dns="*.example.com");)
8. Click
OK
.
The new ACI is added to the ones listed in the
Access Control Manager
window.
6.9.4. Granting a Group Full Access to a Suffix
Most directories have a group that is used to identify certain corporate functions. These groups can
be given full access to all or part of the directory. By applying the access rights to the group, you can
avoid setting the access rights for each member individually. Instead, you grant users these access
rights simply by adding them to the group.
For example, when the Directory Server is set up with a typical process, an administrators group with
full access to the directory is created by default.
At
example.com
, the
Human Resources
group is allowed full access to the
ou=example-
people
branch of the directory so that they can update the employee database. This is illustrated in
Section 6.9.4.1, “ACI "HR"”
.
6.9.4.1. ACI "HR"
In LDIF, to grant the HR group all rights on the employee branch of the directory, use the following
statement:
aci: (version 3.0; acl "HR"; allow (all) userdn=
"ldap:///cn=HRgroup,ou=example-people,dc=example,dc=com";)
This example assumes that the ACI is added to the
ou=example-people,dc=example,dc=com
entry.
From the Console, set this permission by doing the following:
1. In the
Directory
tab, right-click the
example-people
entry under the
example.com
node in the
left navigation tree, and choose
Set Access Permissions
from the pop-up menu to display the
Access Control Manager
.
2. Click
New
to display the
Access Control Editor
.
3. In the
Users/Groups
tab, in the
ACI name
field, type
HR
. In the list of users granted access
permission, do the following:
a. Select and remove
All Users
, then click
Add
.
The
Add Users and Groups
dialog box opens.
b. Set the
Search
area to
Users and Groups
, and type
HRgroup
in the
Search for
field.
This example assumes that you have created an HR group or role. For more information on
groups and roles, see
Chapter 5, Managing Entries with Roles, Classes of Service, and Views
.
c. Click the
Add
button to list the HR group in the list of users who are granted access
permission.
Содержание DIRECTORY SERVER 8.0
Страница 18: ...xviii ...
Страница 29: ...Configuring the Directory Manager 11 6 Enter the new password and confirm it 7 Click Save ...
Страница 30: ...12 ...
Страница 112: ...94 ...
Страница 128: ...110 ...
Страница 190: ...Chapter 6 Managing Access Control 172 4 Click New to open the Access Control Editor ...
Страница 224: ...206 ...
Страница 324: ...306 ...
Страница 334: ...316 ...
Страница 358: ...340 ...
Страница 410: ...392 ...
Страница 420: ...402 ...
Страница 444: ...426 ...
Страница 454: ...436 ...
Страница 464: ...446 ...
Страница 484: ...466 ...
Страница 512: ...494 ...
Страница 522: ...504 ...