•
Grant all
example.com
Social Committee branch of the directory, and to delete group entries that they
own (see "Granting Rights to Add and Delete Group Entries," on page 243).
•
Grant all
example.com
under the Social Committee branch of the directory (see "Allowing Users to
Add or Remove Themselves From a Group," on page 251).
•
Grant access to the directory administrator (role) of HostedCompany1 and
HostedCompany2 on their respective branches of the directory tree, with
certain conditions such as SSL authentication, time and date restrictions, and
specified location (see "Granting Conditional Access to a Group or Role," on
page 246).
•
Grant individual subscribers access to their own entries (see "Granting Write
Access to Personal Entries," on page 237).
•
Deny individual subscribers access to the billing information in their own
entries (see "Denying Access," on page 248).
•
Grant anonymous access to the world to the individual subscribers subtree,
except for subscribers who have specifically requested to be unlisted. (This part
of the directory could be a slave server outside of the firewall and updated
once a day.) See "Granting Anonymous Access," on page 235 and "Setting a
Target Using Filtering," on page 251.
Granting Anonymous Access
Most directories are run such that you can anonymously access at least one suffix
for read, search, or compare. For example, you might want to set these permissions
if you are running a corporate personnel directory that you want employees to be
able to search, such as a phonebook. This is the case at
is illustrated in the ACI "Anonymous example.com" example.
As an ISP,
example.com
subscribers by creating a public phonebook accessible to the world. This is
illustrated in the ACI "Anonymous World" example.
ACI "Anonymous example.com"
In LDIF, to grant read, search, and compare permissions to the entire
tree to
example.com
aci: (targetattr !="userPassword")(version 3.0; acl "Anonymous
Example"; allow (read, search, compare) userdn= "ldap:///anyone" and
dns="*.example.com";)
employees the right to create group entries under the
employees the right to add themselves to group entries
also wants to advertise the contact information of all of its
employees, you would write the following statement:
Access Control Usage Examples
internally, and
example.com
example.com
Chapter 6
Managing Access Control
235
Need help?
Do you have a question about the NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR and is the answer not in the manual?
Questions and answers