Granting Anonymous Access; Aci "Anonymous Example.com - Red Hat DIRECTORY SERVER 7.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Access Control Usage Examples

Granting Anonymous Access

Most directories are run such that you can anonymously access at least one suffix
for read, search, or compare. For example, you might want to set these
permissions if you are running a corporate personnel directory that you want
employees to be able to search, such as a phonebook. This is the case at
example.com
example.
As an ISP,
its subscribers by creating a public phonebook accessible to the world. This is
illustrated in the ACI "Anonymous World" example.

ACI "Anonymous example.com"

In LDIF, to grant read, search, and compare permissions to the entire
example.com
statement:
aci: (targetattr !="userPassword")(version 3.0; acl "Anonymous
Example"; allow (read, search, compare) userdn= "ldap:///anyone"
and dns="*.example.com";)
This example assumes that the
userPassword
From the Console, you can set this permission by doing the following:
In the Directory tab, right click the
1.
tree, and choose Set Access Permissions from the pop-up menu to display the
Access Control Manager.
Click New to display the Access Control Editor.
2.
In the Users/Groups tab in the ACI name field, type
3.
example.com
access permission.
In the Rights tab, tick the checkboxes for
4.
Make sure the other checkboxes are clear.
In the Targets tab, click This Entry to display the
5.
in the target directory entry field. In the attribute table, locate the
userPassword
All other checkboxes should be ticked. This task is made easier if you click the
Name header to organize the list of attributes alphabetically.
244
Red Hat Directory Server Administrator's Guide • May 2005
internally and is illustrated in the ACI "Anonymous example.com"
also wants to advertise the contact information of all of
example.com
tree to
example.com
aci
attribute is excluded from the scope of the ACI.
. Check that All Users is displayed in the list of users granted
attribute, and clear the corresponding checkbox.
employees, you would write the following
is added to the
dc=example,dc=com
node in the left navigation
example.com
,
read
compare
dc=example,dc=com
entry. The
Anonymous
, and
rights.
search
suffix

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the DIRECTORY SERVER 7.1 - ADMINISTRATOR and is the answer not in the manual?

Questions and answers

Subscribe to Our Youtube Channel

This manual is also suitable for:

Directory server 7.1

Table of Contents