Viewing The Acis For An Entry; Advanced Access Control: Using Macro Acis; Macro Aci Example - Netscape DIRECTORY SERVER 6.2 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Viewing the ACIs for an Entry

Viewing the ACIs for an Entry
You can view all the ACIs under a single suffix in the directory by running the
following
ldapsearch -h host -p port -b baseDN -D rootDN -w rootPassword (aci=*) aci
See Netscape Directory Server Configuration, Command, and File Reference for
information on using the
From the Console, you can view all of the ACIs that apply to a particular entry
through the Access Control Manager.
In the Directory Console, on the Directory tab, right-click the entry in the
1.
navigation tree, and select Set Access Permissions.
The Access Control Manager is displayed. It contains a list of the ACIs
belonging to the selected entry.
Check the Show Inherited ACIs checkbox to display all ACIs created on entries
2.
above the selected entry that also apply.

Advanced Access Control: Using Macro ACIs

In organizations that use repeating directory tree structures, it is possible to
optimize the number of ACIs used in the directory by using macros. Reducing the
number of ACIs in your directory tree makes it easier to manage your access
control policy, and improves the efficiency of ACI memory usage.
Macros are placeholders that are used to represent a DN, or a portion of a DN, in
an ACI. You can use a macro to represent a DN in the target portion of the ACI, or
in the bind rule portion, or both. In practice, when Directory Server gets an
incoming LDAP operation, the ACI macros are matched against the resource
targeted by the LDAP operation. If there is a match, the macro is replaced by the
value of the DN of the targeted resource. Directory Server then evaluates the
ACI normally.

Macro ACI Example

The benefits of macro ACIs and how they work are best explained using an
example. Figure 6-4 on page 258 shows a directory tree in which using macro ACIs
is an effective way of reducing the overall number of ACIs.
256
Netscape Directory Server Administrator's Guide • December 2003
command:
ldapsearch
ldapsearch
utility.

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the NETSCAPE DIRECTORY SERVER 6.2 - ADMINISTRATOR and is the answer not in the manual?

Questions and answers

This manual is also suitable for:

Directory server 6.2

Table of Contents