Granting Conditional Access To A Group Or Role - Netscape DIRECTORY SERVER 6.02 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

ACI "Delete Group"
In LDIF, to grant
example.com
entry which they own under the
the following statement:
aci: (target="ou=social committee,dc=example,dc=com)
(targattrfilters="del=objectClass:(objectClass=groupOfNames)")
(version 3.0; acl "Delete Group"; allow (delete) userattr=
"owner#GROUPDN";)
This example assumes that the
dc=example,dc=com
Using the Console is not an effective way of creating this ACI because you would
have to use manual editing mode to create the target filter, and to check group
ownership.

Granting Conditional Access to a Group or Role

In many cases, when you grant a group or role privileged access to the directory,
you want to ensure that those privileges are protected from intruders trying to
impersonate your privileged users. Therefore, in many cases, access control rules
that grant critical access to a group or role are often associated with a number of
conditions.
, for example, has created a Directory Administrator role for each of
example.com
its hosted companies, HostedCompany1 and HostedCompany2. It wants these
companies to be able to manage their own data and implement their own access
control rules while securing it against intruders. For this reason, HostedCompany1
and HostedCompany2 have full rights on their respective branches of the directory
tree, provided the following conditions are fulfilled:
Connection authenticated using SSL,
Access requested between 8 am and 6 pm, Monday through Thursday, and
Access requested from a specified IP address for each company.
These conditions are illustrated in a single ACI for each company, ACI
"HostedCompany1" and ACI "HostedCompany2". Because the content of these
ACIs is the same, the examples below illustrate the "HostedCompany1 " ACI only.
ACI "HostedCompany1"
In LDIF, to grant HostedCompany1 full access to their own branch of the directory
under the conditions stated above, you would write the following statement:
employees the right to modify or delete a group
ou=Social Comittee branch
is added to the
aci
entry.
Access Control Usage Examples
, you would write
ou=social committee,
Chapter 6
Managing Access Control
241

Advertisement

Table of Contents
loading

This manual is also suitable for:

Directory server 6.02

Table of Contents