Allowing Or Denying Access; Assigning Rights - Netscape DIRECTORY SERVER 6.02 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Allowing or Denying Access

You can either explicitly allow or deny access permissions to your directory tree.
For more guidelines on when to allow and when to deny access, refer to the
Netscape Directory Server Deployment Guide.
NOTE
From the Server Console, you cannot explicitly deny access, but
only grant permissions.

Assigning Rights

Rights detail the specific operations a user can perform on directory data. You can
allow or deny all rights, or you can assign one or more of the following rights:
Read. Indicates whether users can read directory data. This permission applies
only to the search operation.
Write. Indicates whether users can modify an entry by adding, modifying, or
deleting attributes. This permission applies to the modify and modrdn operations.
Add. Indicates whether users can create entries. This permission applies only to the
add operation.
Delete. Indicates whether users can delete entries. This permission applies only to
the delete operation.
Search. Indicates whether users can search for the directory data. Users must have
Search and Read rights in order to view the data returned as part of a search result.
This permission applies only to the search operation.
Compare. Indicates whether the users can compare data they supply with data
stored in the directory. With compare rights, the directory returns a success or
failure message in response to an inquiry, but the user cannot see the value of the
entry or attribute. This permission applies only to the compare operation.
Selfwrite. Indicates whether users can add or delete their own DN from a group.
This right is used only for group management.
Proxy. Indicates whether the specified DN can access the target with the rights of
another entry. For an overview of proxy access, refer to Netscape Directory Server
Deployment Guide.
All. Indicates that the specified DN has all rights (read, write, search, delete,
compare, and selfwrite) to the targeted entry, excluding proxy rights.
Creating ACIs Manually
Chapter 6
Managing Access Control
203

Advertisement

Table of Contents
loading

This manual is also suitable for:

Directory server 6.02

Table of Contents