Granting Anonymous Access - Netscape DIRECTORY SERVER 6.01 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Access Control Usage Examples
Grant all
Social Committee branch of the directory, and to delete group entries that they
own (see "Granting Rights to Add and Delete Group Entries," on page 236).
Grant all
under the Social Committee branch of the directory (see "Allowing Users to
Add or Remove Themselves From a Group," on page 244).
Grant access to the directory administrator (role) of HostedCompany1 and
HostedCompany2 on their respective branches of the directory tree, with
certain conditions such as SSL authentication, time and date restrictions, and
specified location (see "Granting Conditional Access to a Group or Role," on
page 239).
Grant individual subscribers access to their own entries (see "Granting Write
Access to Personal Entries," on page 230).
Deny individual subscribers access to the billing information in their own
entries (see "Denying Access," on page 241).
Grant anonymous access to the world to the individual subscribers subtree,
except for subscribers who have specifically requested to be unlisted. (This part
of the directory could be a slave server outside of the firewall and updated
once a day.) See "Granting Anonymous Access," on page 228 and "Setting a
Target Using Filtering," on page 244.

Granting Anonymous Access

Most directories are run such that you can anonymously access at least one suffix
for read, search, or compare. For example, you might want to set these permissions
if you are running a corporate personnel directory that you want employees to be
able to search, such as a phonebook. This is the case at
is illustrated in the ACI "Anonymous example.com" example.
As an ISP,
subscribers by creating a public phonebook accessible to the world. This is
illustrated in the ACI "Anonymous World" example.
ACI "Anonymous example.com"
In LDIF, to grant read, search, and compare permissions to the entire
tree to
aci: (targetattr !="userPassword")(version 3.0; acl "Anonymous
Example"; allow (read, search, compare) userdn= "ldap:///anyone" and
dns="*.example.com";)
228
Netscape Directory Server Administrator's Guide • January 2002
example.com
employees the right to add themselves to group entries
example.com
also wants to advertise the contact information of all of its
example.com
employees, you would write the following statement:
example.com
employees the right to create group entries under the
internally, and
example.com
example.com

Advertisement

Table of Contents
loading

This manual is also suitable for:

Directory server 6.01

Table of Contents