About Roles - Netscape DIRECTORY SERVER 6.02 - DEPLOYMENT Deployment Manual

Table of Contents

Advertisement

About Roles

Roles are a new entry grouping mechanism. Your directory tree organizes
information hierarchically. This hierarchy is a grouping mechanism, though it is
not suited for short-lived, changing organizations. Roles provide another grouping
mechanism for more temporary organizational structures.
Roles unify static and dynamic groups. You use static groups to create a group
entry that contains a list of members. Dynamic groups allow you to filter entries
that contain a particular attribute and include them in a single group.
Each entry assigned to a role contains the
that specifies all of the roles an entry belongs to. A client application can check role
membership by searching the
and therefore always up-to-date.
Roles are designed to be more efficient and easier to use for applications. For
example, applications can locate the roles of an entry, rather than select a group
and browse the members list.
You can use roles to do the following:
Enumerate the members of the role.
Having an enumerated list of role members can be useful for resolving queries
for group members quickly.
Determine whether a given entry possesses a particular role.
Knowing the roles possessed by an entry can help you determine whether the
entry possesses the target role.
Enumerate all the roles possessed by a given entry.
Assign a particular role to a given entry.
Remove a particular role from a given entry.
Each role has members, entries that possess the role. You can specify members
either explicitly (meaning each entry contains an attribute associating it with a role)
or dynamically (by creating a filter that assigns entries to roles depending upon an
attribute contained by the entry). How you specify role membership depends upon
the type of role you are using. There are three types of roles:
Managed roles—A managed role allows you to create an explicit enumerated
list of members. Managed roles are added to entries using the
attribute.
attribute, a computed attribute
nsRole
attribute, which is computed by the directory
nsRole
Chapter 4
Grouping Directory Entries
nsRoleDN
Designing the Directory Tree
71

Advertisement

Table of Contents
loading

This manual is also suitable for:

Directory server 6.02

Table of Contents