Netscape DIRECTORY SERVER 6.02 - ADMINISTRATOR Administrator's Manual page 240

Table of Contents

Advertisement

Access Control Usage Examples
From the Console, you can set this permission by doing the following:
On the Directory tab, right click the Social Committee entry under the
1.
example.com
Permissions from the pop-up menu to display the Access Control Manager.
Click New to display the Access Control Editor.
2.
On the Users/Groups tab, in the ACI name field, type "Create Group". In the
3.
list of users granted access permission, do the following:
a.
b.
c.
d.
On the Rights tab, tick the checkbox for add. Make sure the other checkboxes
4.
are clear.
On the Targets tab, click This Entry to display the
5.
dc=example,dc=com
On the Hosts tab, click Add to display the Add Host Filter dialog box. In the
6.
DNS host filter field, type
To create the value-based filter that will allow employees to add only group
7.
entries to this subtree, switch to manual editing by clicking the Edit Manually
button. Add the following to the beginning of the LDIF statement:
(targattrfilters="add=objectClass:(objectClass=groupOfNames)")
The LDIF statement should read as follows:
(targattrfilters="add=objectClass:(objectClass=groupOfNames)")
(targetattr = "*") (target="ldap:///ou=social
committee,dc=example,dc=com) (version 3.0; acl "Create Group";
allow (read,search,add) (userdn= "ldap:///all") and
(dns="*.example.com"); )
Click OK.
8.
The new ACI is added to the ones listed in the Access Control Manager
window.
240
Netscape Directory Server Administrator's Guide • May 2002
node in the left navigation tree, and choose Set Access
Select and remove All Users, then click Add.
The Add Users and Groups dialog box is displayed.
Set the Search area to Special Rights, and select All Authenticated Users
from the Search results list.
Click the Add button to list All Authenticated Users in the list of users who
are granted access permission.
Click OK to dismiss the Add Users and Groups dialog box.
suffix in the target directory entry field.
. Click OK to dismiss the dialog box.
*.example.com
ou=social committee,

Advertisement

Table of Contents
loading

This manual is also suitable for:

Directory server 6.02

Table of Contents