's business is to offer a web hosting service and Internet access. Part
example.com
of
's web hosting service is to host the directories of client companies.
example.com
actually hosts and partially manages the directories of two
example.com
medium-sized companies,
Internet access to a number of individual subscribers.
These are the access control rules that
•
Grant anonymous access for read, search, and compare to the entire
tree for
example.com
Access," on page 244).
•
Grant write access to
as
homeTelephoneNumber
Personal Entries," on page 246).
•
Grant
example.com
certain critical roles (see "Restricting Access to Key Roles," on page 249).
•
Grant the
example.com
People branch (see "Granting a Group Full Access to a Suffix," on page 251).
•
Grant all
example.com
Social Committee branch of the directory and to delete group entries that they
own (see "Granting Rights to Add and Delete Group Entries," on page 252).
•
Grant all
example.com
under the Social Committee branch of the directory (see "Allowing Users to
Add or Remove Themselves from a Group," on page 260).
•
Grant access to the directory administrator (role) of
HostedCompany2
conditions such as SSL authentication, time and date restrictions, and specified
location (see "Granting Conditional Access to a Group or Role," on page 255).
•
Grant individual subscribers access to their own entries (see "Granting Write
Access to Personal Entries," on page 246).
•
Deny individual subscribers access to the billing information in their own
entries (see "Denying Access," on page 257).
•
Grant anonymous access to the world to the individual subscribers subtree,
except for subscribers who have specifically requested to be unlisted. (This part
of the directory could be a consumer server outside of the firewall and be
updated once a day.) See "Granting Anonymous Access," on page 244, and
"Setting a Target Using Filtering," on page 260.
HostedCompany1
example.com
employees (see "Granting Anonymous
example.com
employees for personal information, such
example.com
and
homeAddress
employees the right to add any role to their entry, except
Human Resources group all rights on the entries in the
employees the right to create group entries under the
employees the right to add themselves to group entries
on their respective branches of the directory tree, with certain
Access Control Usage Examples
and
HostedCompany2
wants to put in place:
(see "Granting Write Access to
HostedCompany1
Chapter 6
Managing Access Control
. It also provides
and
243
Need help?
Do you have a question about the DIRECTORY SERVER 7.1 - ADMINISTRATOR and is the answer not in the manual?
Questions and answers