Setting A Target Using Filtering; Allowing Users To Add Or Remove Themselves From A Group - Netscape DIRECTORY SERVER 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Setting a Target Using Filtering

If you want to set access controls that allow access to a number of entries that are
spread across the directory, you may want to use a filter to set the target. Keep in
mind that because search filters do not directly name the object for which you are
managing access, it is easy to unintentionally allow or deny access to the wrong
objects, especially as your directory becomes more complex. Additionally, filters
can make it difficult for you to troubleshoot access control problems within your
directory.
The following procedure shows you how to grant user
department number, home phone number, home postal address, JPEG photo, and
manager attributes for all members of the accounting organization.
Before you can set these permissions, you must create the accounting branch point
(
ou=accounting,dc=example,dc=com
points using the directory tab on the Directory Server Console.

Allowing Users to Add or Remove Themselves From a Group

Many directories set ACIs that allow users to add or remove themselves from
groups. This is useful, for example, for allowing users to add and remove
themselves from mailing lists.
At
, employees can add themselves to any group entry under the
example.com
ou=social committee
example.
ACI "Group Members"
In LDIF, to grant
example.com
from a group, you would write the following statement:
aci: (targettattr="member")(version 3.0; acl "Group Members";
allow (selfwrite)
(userdn= "ldap:///uid=*,ou=example-people,dc=example,dc=com") ;)
This example assumes that the ACI is added to the
dc=example,dc=com
From the Console, you can set this permission by doing the following:
On the Directory tab, right click the
1.
node in the left navigation tree, and choose Set Access
example.com
Permissions from the pop-up menu to display the Access Control Manager.
Click New to display the Access Control Editor.
2.
). You can create organizational unit branch
subtree. This is illustrated in the ACI "Group Members"
employees the right to add or delete themselves
entry.
example-people
Access Control Usage Examples
write access to the
bjensen
ou=social committee,
entry under the
Chapter 6
Managing Access Control
251

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR and is the answer not in the manual?

Questions and answers

This manual is also suitable for:

Directory server 6.1

Table of Contents