Targeting A Single Directory Entry - Netscape DIRECTORY SERVER 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Creating ACIs Manually
When creating an entry, if a filter applies to an attribute in the new entry, then each
instance of that attribute must satisfy the filter. When deleting an entry, if a filter
applies to an attribute in the entry, then each instance of that attribute must also
satisfy the filter.
When modifying an entry, if the operation adds an attribute, then the add filter that
applies to that attribute must be satisfied; if the operation deletes an attribute, then
the delete filter that applies to that attribute must be satisfied. If individual values
of an attribute already present in the entry are replaced, then both the add and
delete filters must be satisfied.
For example consider the following attribute filter:
(targattrfilters="add=nsroleDN:(!(nsRoleDN=cn=superAdmin)) &&
telephoneNumber:(telephoneNumber=123*))
This filter can be used to allow users to add any role (
own entry, except the
number with a 123 prefix.
NOTE

Targeting a Single Directory Entry

Targeting a single directory entry is not straightforward because it goes against the
design philosophy of the access control mechanism. However, it can be done:
By creating a bind rule that matches user input in the bind request with an
attribute value stored in the targeted entry. For more details, see "Defining
Access Based on Value Matching," on page 218.
By using the
You can use the
the entry you want to target, and not in any of the entries below your target. For
example, if you want to target
any organizational units (
that contains:
targetattr=ou
A safer method is to use the
attribute value that appears in the entry alone. For example, during the installation
of the Directory Server, the following ACI is created:
206
Netscape Directory Server Administrator's Guide • August 2002
superAdmin
You cannot create value-based ACIs from the Server Console.
and
targetattr
targetfilter
keyword to specify an attribute that is only present in
targetattr
ou=people,dc=example,dc=com
) defined below that node you could specify an ACI
ou
targetfilter
nsRoleDN
role. It also allows users to add a telephone
keywords
keyword and to explicitly specify an
attribute) to their
, and there aren't

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR and is the answer not in the manual?

Questions and answers

Subscribe to Our Youtube Channel

This manual is also suitable for:

Directory server 6.1

Table of Contents